Live data from Hacker News

Tor Exit Nodes in Libraries – Pilot

blog.torproject.org

41–50 of 60 posts

Re: Tor Exit Nodes in Libraries – Pilot

#41
post #17

Earlier quoted context omitted.

https://www.torproject.org/about/sponsors.html.en The NSA fully-funded and wrote SELinux, too. So what?

I am naive on this topic. Sincere question: don't these facts call the utility of SELinux and Tor into question? If the answer is "because math", well... I don't speak math. Being illerate in this manner, I must depend on the reputations of the parties involved (and the reputations of the parties that report who was involved!). So... Can a person who does not trust the NSA trust products they paid for?

Slightly off-topic here, but flipping through this[1] Abstract Algebra textbook(2009), I found it amusing that the author thanks NSA for support among others :D.

[1] http://www.amazon.com/Algebra-Chapter-Graduate-Studies-Mathe...

Re: Tor Exit Nodes in Libraries – Pilot

#42
post #4

If you think the Tor project is working on an important problem, consider running a relay. It's inexpensive, easy to administer, no hassle (if not an exit) and I think the scale is such that a couple thousand additional relays would make a noticeable difference to the network. You can even have it AWS where it will get automatic updates with almost no effort: https://cloud.torproject.org/ If you want to run it on OS…

If you want to run a tor exit node, you can improve the security by subscribing to a rigorous hygiene process that provides accountability of your security upkeep.

* System Hardening

* Log Monitoring

* Intrusion Prevention

* Write proceses

* Perimeter Control

A compromised tor exit node is no good because all it takes is switching on NetFlow and all those sensitive packets are captured.

http://motherboard.vice.com/read/how-the-nsa-or-anyone-else-...

Re: Tor Exit Nodes in Libraries – Pilot

#43

Earlier quoted context omitted.

I am naive on this topic. Sincere question: don't these facts call the utility of SELinux and Tor into question? If the answer is "because math", well... I don't speak math. Being illerate in this manner, I must depend on the reputations of the parties involved (and the reputations of the parties that report who was involved!). So... Can a person who does not trust the NSA trust products they paid for?

You can definitely trust the sensational value in finding out that any project advocating freedom and data security would be exploited by a government. That's what I do, it's not perfect but I love reading source code and figuring out how things work so I know others, much smarter than me, love that too. The public cases of the US government going after Tor, for example, have all read like external attacks on the pro…

I don't think they're state-owned, but they depend on community and county (and maybe state and Federal) sources for funding. Depending on the community politics, libraries could face funding cuts for running exit nodes.

If the library staff are at all bureaucrat-savvy, they can probably obfuscate the activity. I hope so. I think this is a very good idea.

Re: Tor Exit Nodes in Libraries – Pilot

#44
post #24

Earlier quoted context omitted.

Since the global passive adversary is now a reality (NSA) it seems like Tor is broken by design.

Not everyone is hiding from the NSA.

So ToR is like a shitty free VPN? Who can one be hiding from that a cheap VPN to a jurisdiction of your choice won't solve much better?

Re: Tor Exit Nodes in Libraries – Pilot

#45

Earlier quoted context omitted.

You can definitely trust the sensational value in finding out that any project advocating freedom and data security would be exploited by a government. That's what I do, it's not perfect but I love reading source code and figuring out how things work so I know others, much smarter than me, love that too. The public cases of the US government going after Tor, for example, have all read like external attacks on the pro…

I don't think they're state-owned, but they depend on community and county (and maybe state and Federal) sources for funding. Depending on the community politics, libraries could face funding cuts for running exit nodes. If the library staff are at all bureaucrat-savvy, they can probably obfuscate the activity. I hope so. I think this is a very good idea.

I think he means state-owned in the sense that the IC can easily watch the traffic going to and leaving the exit node, and with many exit nodes leveraging this into a passive attack on the network.

If this is true, if ToR is to stick to a goal of establishing truly anonymous browsing, ToR needs to establish links through a diverse number of jurisdictions.

Re: Tor Exit Nodes in Libraries – Pilot

#46
post #24
post #16

Earlier quoted context omitted.

From https://svn.torproject.org/svn/projects/design-paper/tor-des... : A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary.

Since the global passive adversary is now a reality (NSA) it seems like Tor is broken by design.

The NSA isn't really global, though. For example, if enough ToR traffic were routed via Asia or South America, I imagine they would not be able to perform much traffic analysis on it.

Re: Tor Exit Nodes in Libraries – Pilot

#47

Earlier quoted context omitted.

You can definitely trust the sensational value in finding out that any project advocating freedom and data security would be exploited by a government. That's what I do, it's not perfect but I love reading source code and figuring out how things work so I know others, much smarter than me, love that too. The public cases of the US government going after Tor, for example, have all read like external attacks on the pro…

> I would be more suspicious over placing exit nodes in libraries... Librarians are more often rabidly pro-privacy and pro-anonymity than not. They're often very well read, well educated, and know their history. > I just think it's sort of ironic because the attacks that have been performed all required possession of exit nodes. Unless you have information that I do not (if you do, please link to it) control of a sin…

>Librarians are more often rabidly pro-privacy and pro-anonymity than not. They're often very well read, well educated, and know their history.

Few librarians are involved in network operations at the library though. I'm just speaking from my experience here in Sweden but that stuff is usually handled by a local IT department or out sourced to a company.

So the danger would be in having a federal oversight on network operations of libraries. I do not believe we have that in Sweden at least. Probably the US government allow libraries to manage themselves on that front too.

>Unless you have information that I do not (if you do, please link to it) control of a single exit node gives you no more power than your ISP already has over you. What attacks were you thinking of? Keep in mind that Tor explicitly does not protect against:

Exit nodes, as in plural.

So hypothetically if the federal government did manage network operations for libraries in the US, and the Tor network was successful in onboarding many libraries in this project, that could mean massive control of Tor exit nodes.

Re: Tor Exit Nodes in Libraries – Pilot

#48
post #46
post #24

Earlier quoted context omitted.

Since the global passive adversary is now a reality (NSA) it seems like Tor is broken by design.

The NSA isn't really global, though. For example, if enough ToR traffic were routed via Asia or South America, I imagine they would not be able to perform much traffic analysis on it.

The NSA is very much global and according to the Snowden leaks tapped into a large number of major internet exchanges and sea cables, including the largest internet exchange of the world (Germany, DECIX[1]) as well as the largest exchange in Asia (Hong Kong, HKIX[3]) and South America (Brazil, BRIX[4]) respectively.

From what we know the NSA has global coverage with google-style indexing[1] since at least 2012, possibly earlier.

[1] https://firstlook.org/theintercept/2014/08/25/icreach-nsa-ci...

[2] http://www.ip-watch.org/2015/04/24/largest-internet-exchange...

[3] http://www.scmp.com/news/hong-kong/article/1269773/hong-kong...

[4] http://www.newyorker.com/news/news-desk/what-the-n-s-a-wants...

[5] http://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret...

[6] https://docs.google.com/spreadsheets/d/1x6aYnGmbQKzZGLUkWC4m...

Re: Tor Exit Nodes in Libraries – Pilot

#49
post #44

Earlier quoted context omitted.

Not everyone is hiding from the NSA.

So ToR is like a shitty free VPN? Who can one be hiding from that a cheap VPN to a jurisdiction of your choice won't solve much better?

No, it's not. It's also not written ToR. I recommend you venture over to their website and start reading the documentation.

Re: Tor Exit Nodes in Libraries – Pilot

#50
post #29
post #4

If you think the Tor project is working on an important problem, consider running a relay. It's inexpensive, easy to administer, no hassle (if not an exit) and I think the scale is such that a couple thousand additional relays would make a noticeable difference to the network. You can even have it AWS where it will get automatic updates with almost no effort: https://cloud.torproject.org/ If you want to run it on OS…

> no hassle (if not an exit) Not 100% true, your server's IP will be banned along side the IPs of exit nodes. It seems a lot of blacklists don't bother to make the distinction. https://www.reddit.com/r/TOR/comments/2abne1/hulu_blocked_af... https://trac.torproject.org/projects/tor/wiki/org/doc/ListOf...

I've been running a relay at home for most of this year. The only site I've had issues accessing is Apple's shitty support forums. No big loss.
Post reply on HN