Live data from Hacker News

Deploying Tor Relays

blog.mozilla.org

51–60 of 91 posts

Re: Deploying Tor Relays

#51
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Silicon Valley problems

Re: Deploying Tor Relays

#52

Earlier quoted context omitted.

What would be great is if a foundation came along that offered people a way to sponsor a Tor node without having to own or operate it themselves.

IANAL, but would this just require someone incorporating or starting an LLC and then paying for the exit nodes in the name of that entity? Would that be sufficient protection?

"sole proprietor" LLCs don't have as limited liability as one may hope. you need more people to shift the blame around.

Re: Deploying Tor Relays

#53
post #20
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

It is plenty safe to run exit nodes. If your host complains, there is even form letters to send. The government knows that seizing an exit node will not help them in anyway (one can go online immediately.) Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.

>Do you think Amazon gets raided?

Did you hear of Lavabit?

Do you know they can force Amazon to handle access to all your running instances and you simple will never be informed?

Re: Deploying Tor Relays

#54
post #44
post #6

Earlier quoted context omitted.

> facebook > privacy

There is a diffrence between mostly voluntaryly pushing your own data into facebook and wanting to not be detected when organising political rally.

A great deal of the data Facebook has must be derived outside of things you have posted yourself. They build and hold a lot of data you do not explicitly consent to share.

Facebook really wants your activity to be based on your real identity, and making associations between you and other people.

Facebook shouldn't be used as a tool for organizing political rallies if there is concern for privacy. Connecting to FB via Tor does not isolate you from much.

Re: Deploying Tor Relays

#55
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

Part of the problem of running an exit node is that it's unclear how "safe" it actually is, and as a result there is a lot of rumor and paranoia. Every country has different laws that affect the legal status of an exit node operator. For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultim…

tor exit is effectively a proxy. nobody should run an open proxy. that's just common sense.

on the other hand it may be a good feature if implemented correctly. for example, sites explicitly saying they allow tor exit connections would be a good start.

Re: Deploying Tor Relays

#56
post #20

Earlier quoted context omitted.

It is plenty safe to run exit nodes. If your host complains, there is even form letters to send. The government knows that seizing an exit node will not help them in anyway (one can go online immediately.) Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.

> It is plenty safe to run exit nodes ... in someone else's data center. Never, ever in your own home. If you are raided ALL your computers and ancillaries will be seized.

you can be raided just the same.

fbi will probably send one agent to pick up the server in the data center, and 20 others will be picking you up at your credit card billing address.

Re: Deploying Tor Relays

#57
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

i think in most countries the pipe is always more expensive than the server

Re: Deploying Tor Relays

#59

Earlier quoted context omitted.

No way. In the US, at least, you're liable for the illegal traffic you route onto the internet as an individual.

Has that ever been proven? I suspect it's as unproven as the theory that Tor operators are "common carriers" and as liable for the traffic that passes over their connection as an ISP is for the traffic that passes over its connections.

At the very least, you can get your computer and networking equipment seized. Tor's own FAQ says you shouldn't run exit nodes at home:

"Should I run an exit relay from my home?

No. If law enforcement becomes interested in traffic from your exit relay, it's possible that officers will seize your computer. For that reason, it's best not to run your exit relay in your home or using your home Internet connection."

Re: Deploying Tor Relays

#60

This is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is. To anyone who is thinking of running a relay, here are the basic st…

I see also that there are some tor relay Docker containers out there, e.g. https://github.com/vpetersson/docker-torrelay

I also quite like Tor Arm if you are running a relay, for an nice eye-candy dashboard: https://www.torproject.org/projects/arm.html.en

Post reply on HN