Live data from Hacker News

Tor Wars: The Signal Awakens

techcrunch.com

11–20 of 43 posts

Re: Tor Wars: The Signal Awakens

#11
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

> nobody is going to DDOS you via Tor Uhh, yes they will... and that is pretty much the exact reason for the captcha.

It's rather hard and inefficient to do that over Tor.

It's actually way easier to just use your regular botnet or pretty much every other approach.[1]

And then it's rather simple to prevent this with your ordinary approach. There are currently around 1000 exit nodes[2]. Compared to most DDOS attacks that is really small number of nodes. For various reasons (measures that are mostly there to make sure Tor can be used for regular browsing in a usable manner, even when there is people that want to download lots of large files) you will run into limitations rather quickly.

[1] https://www.torproject.org/docs/faq-abuse.html.en#DDoS

[2] https://metrics.torproject.org/relayflags.html?graph=relayfl...

Re: Tor Wars: The Signal Awakens

#12

An important point the article makes is how important it is for a large number of people to use Tor, even if only occasionally. I try to use Tor at least once or twice a week for general web browsing. I also donated money to them. It is really important for people to also support groups like the EFF and ACLU financially: a good investment in future freedom. History shows that large empires tend to get tough on their…

My Tomato router has Tor built in. I can enable it and route some traffic through sometimes, but does anyone know if it will consume bandwidth if I leave it open but not use it? Is every Tor node a potential relay node?

Re: Tor Wars: The Signal Awakens

#13

An important point the article makes is how important it is for a large number of people to use Tor, even if only occasionally. I try to use Tor at least once or twice a week for general web browsing. I also donated money to them. It is really important for people to also support groups like the EFF and ACLU financially: a good investment in future freedom. History shows that large empires tend to get tough on their…

My Tomato router has Tor built in. I can enable it and route some traffic through sometimes, but does anyone know if it will consume bandwidth if I leave it open but not use it? Is every Tor node a potential relay node?

You are only a relay router in Tor if you elect to be a relay router.

Re: Tor Wars: The Signal Awakens

#14
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

> nobody is going to DDOS you via Tor Uhh, yes they will... and that is pretty much the exact reason for the captcha.

More likely they will try to perform a Denial Of Service while appearing to be Distributed, so "DDOS" is technically accurate.

Re: Tor Wars: The Signal Awakens

#15
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

Some of these points are partly why I chose to go with a commercial VPN regularly rather than Tor. There is also no change at all in my bandwidth with the VPN, and I can seamlessly use high bandwidth tools like Netflix, streaming audio/video, etc. Maybe Tor has improved lately to allow this kind of behavior easily also?

For certain kinds of streaming it might be nicer to use a VPN, even though, like others already pointed out it might still be used invade your privacy.

Not just that your provider might just log your actions, but VPNs are usually not trying to avoid various passive attacks, simply because VPNs are there to provide an encrypted connection, nothing more.

For ISPs (of the VPN) and others it's rather simple to look at where and how you enter and therefor an attack where people look at the (amount of) traffic that goes there, what the server on the VPN side requests. It's not impossible with Tor, but way, way harder.

In addition to VPNs usually being centralized and therefor easier to attack in such a manner your VPN also is likely to have fewer users than Tor, so it's way easier to look at it and draw conclusions.

Also VPNs tend to be better suited for (semi)targeted attacks.

Re: Tor Wars: The Signal Awakens

#16
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

Some of these points are partly why I chose to go with a commercial VPN regularly rather than Tor. There is also no change at all in my bandwidth with the VPN, and I can seamlessly use high bandwidth tools like Netflix, streaming audio/video, etc. Maybe Tor has improved lately to allow this kind of behavior easily also?

Watching HTML5 video on Tor is fine, though I haven't tried a 2 hour movie in high resolution. The main challenge is that if you want to preserve many security benefits of Tor then you can't use Flash.

Tor's performance generally works well enough that I think most users could use it most of the time and make non-Tor usage a special case.

Re: Tor Wars: The Signal Awakens

#17
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

> nobody is going to DDOS you via Tor Uhh, yes they will... and that is pretty much the exact reason for the captcha.

As tete says, it'd be rather inefficient to do a DDoS via Tor. I think that the reason for the captcha is more related with security, to avoid spammers or bots to getting through via Tor. Cloudflare explains the issue here: https://support.cloudflare.com/hc/en-us/articles/203306930-D...

Re: Tor Wars: The Signal Awakens

#18

An important point the article makes is how important it is for a large number of people to use Tor, even if only occasionally. I try to use Tor at least once or twice a week for general web browsing. I also donated money to them. It is really important for people to also support groups like the EFF and ACLU financially: a good investment in future freedom. History shows that large empires tend to get tough on their…

About donations. Other than EFF and the Tor Project this is also a good way to help:

https://oniontip.com/

There is also organizations that host Tor servers and while I think they can be trusted and a donation certainly is worthwhile it also leads to a form of centralization.

Oniontip is likely far from covering any costs, but I guess it helps the operators a bit.

Re: Tor Wars: The Signal Awakens

#19
post #3

Earlier quoted context omitted.

I actually switched to using Tor whenever I go on wild hunts about stuff that I find interesting. Basically that means whenever I visit Wikipedia, because I can waste hours there, going over the weirdest topics. Usually I get drawn in by stuff like history and end up on things like Soviet Union, Nazi Germany, Japan in WW2, etc. or stuff like Ku Klux Klan, the "Islamic State". If there is some surveillance system it w…

Some of these points are partly why I chose to go with a commercial VPN regularly rather than Tor. There is also no change at all in my bandwidth with the VPN, and I can seamlessly use high bandwidth tools like Netflix, streaming audio/video, etc. Maybe Tor has improved lately to allow this kind of behavior easily also?

Nope. Still an annoying process to stream YouTube, and it still chops. The general vibe of the Tor community is to not use up excess bandwidth unless you have to, because it chokes endpoints and gateways and leaves less room for others. I think a lot of gateways probably run some form of bandwidth limiter, but that's just speculation. It's considered extremely bad taste to do things such as high-volume P2P

Re: Tor Wars: The Signal Awakens

#20
I don't agree with this statement from the article:

This, and Tor’s history of US government sponsorship, has led to series of really embarrassing conspiracy theories from the likes of PandoDaily. This is why non-technical journalists should not write about technical subjects. If you’re going to suggest that open-source software has dark ulterior vulnerabilities, you need to point at exactly where they are in the code (or deployment process), or you will quite rightly be laughed out of the room. Funding and relationships are not unimportant — and I’m sure Pando will now write me off as part of the shadowy conspiracy, as Tor developer Jacob Appelbaum is an old friend — but it’s the running code that actually matters. Sadly, non-engineers don’t seem to understand this, or how laughably ridiculous they look as a result.

The author, Jon Evans, seems to imply this is a widely accepted standard, which is not my experience. It also doesn't seem realistic: While it's great that open source software's source code is available, it's not possible to review it all much less to catch subtle exploits that might have been introduced by security agencies - we can't even catch many unintentional exploits. Also, we know from leaks that security agencies have tried and have succeeded at times. Realistically it comes down to trust.

Think of it this way: How many HN readers, a sophisticated population, have reviewed Tor's code? How many feel they have no choice but to choose either to trust them or not? Also, how many open source projects have had security audits performed by anyone?

Post reply on HN