Live data from Hacker News

Deploying Tor Relays

blog.mozilla.org

61–70 of 91 posts

Re: Deploying Tor Relays

#61

Im not sure if mozilla should get into such a political field.

The Mozilla Foundation regularly leads or joins in political action relevant to its mission. For example we campaigned against SOPA/PIPA and CISPA [1], submitted a Net Neutrality proposal to the U.S. FCC [2], and have testified multiple times to the Librarian of Congress and elsewhere in favor of DMCA exemptions and DMCA reform [3].

[1]: https://blog.mozilla.org/blog/2012/01/17/mozilla-to-join-tom...

[2]: http://arstechnica.com/tech-policy/2014/05/mozilla-offers-fc...

[3]: http://www.cnet.com/news/growing-pressure-in-congress-to-fix...

Re: Deploying Tor Relays

#62
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Well, if they were in any way savvy (which I believe they are), they would sell a machine like that or donate it to another project. In this instance, I imagine, instead of selling/donating they repurposed.

Re: Deploying Tor Relays

#63

This is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is. To anyone who is thinking of running a relay, here are the basic st…

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk.

Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

Re: Deploying Tor Relays

#64
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Well, if they were in any way savvy (which I believe they are), they would sell a machine like that or donate it to another project. In this instance, I imagine, instead of selling/donating they repurposed.

For instance a while back Mozilla was giving away old Mac minis: http://armenzg.blogspot.de/2014/05/do-you-need-used-mac-mini...

Re: Deploying Tor Relays

#65
post #43

Earlier quoted context omitted.

I've ran an exit node in my home for several years and the worst I've seen as a result of it is several DMCA notices and one polite call from the police in another state.

Even if so far everyone has that exact worst case experience, that doesn't mean tomorrow you won't be arrested for somebody viewing illegal material through your exit host. I know people who've sold drugs and never had any problem, it doesn't mean I'm going to start doing it presuming its safe based off their anecdotes.

That is very much like saying you shouldn't express your political views because you don't know if tomorrow they'll be made retroactively illegal.

And the criticism of anecdotal evidence is that it may not be a representative sample. So what is the actual percentage of Tor exit node operators who have been incarcerated for it in the US then? Is it not 0%?

Re: Deploying Tor Relays

#66
post #42
post #37

This is, of course, great news. However, it's my impression that there is a surplus of entry and middle nodes, and a serious shortage of exit nodes, especially fast ones. Also, I've read that the geographic diversity of exit nodes is inadequate. I base these comments on discussions on the tor-talk and tor-relays lists, and from posts on the Tor Project blog.

Would it help if an ISP ran a couple of exit nodes plugged into core routers?

It's actually better if 1000 different people each run a 40Mbps exit node than if one ISP runs a single 40Gbps one. You don't want to centralize control over the exit nodes because it increases the chance that party could control every node in a circuit.

Re: Deploying Tor Relays

#67

They better tell their employees not to buy any drugs or use TOR for illegal stuff, because now they'll be representing the whole TOR project and The Free Web. So it's like, they don't just represent themselves anymore, and an arrest will be a political tool to smash everything into corporate/government control.

Any government agency that wants to trash-talk Tor is already doing so, and already has plenty of ammo for the propaganda machine. They're not going to wait for some Mozilla employee to download a movie torrent, especially since that wouldn't actually change anything.

Re: Deploying Tor Relays

#68
post #63

Earlier quoted context omitted.

> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is. To anyone who is thinking of running a relay, here are the basic st…

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists

Have you got an example of that? I know a few relays intimately and I've never seen this.

Re: Deploying Tor Relays

#69
post #68
post #63

Earlier quoted context omitted.

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists Have you got an example of that? I know a few relays intimately and I've never seen this.

Numerous sites pull down lists of exits daily/hourly/$xly and retroactively block them, although I've never heard of a subnet being blocked.

Re: Deploying Tor Relays

#70
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

Part of the problem of running an exit node is that it's unclear how "safe" it actually is, and as a result there is a lot of rumor and paranoia. Every country has different laws that affect the legal status of an exit node operator. For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultim…

Actually, as for the case in Austria, he was found guilty as an accomplice for distributing child porn (which was carried out on his exit node.)
Post reply on HN