Live data from Hacker News

Snowflake

snowflake.torproject.org

11–20 of 61 posts

Re: Snowflake

#11

Earlier quoted context omitted.

It not an exit. But by default someone has to knowingly run the Snowflake applet but webmasters could modify the code to automatically essentially start a Tor guard in someones browser. Though, that would be very evil to abuse someones resources like that. That example has the users consent before starting.

That's already how many shady VPN software work. Remember if a VPN is "free", you are the product. Web scraping companies pay $$$$ for residential and mobile IPs.

Friendly reminder that it's not just free VPNs that sell your data; many of the paid VPNs do also.

Re: Snowflake

#12

> If you switch on the Snowflake below and leave the browser tab open, a user can connect through your new proxy! I am not even sure, if I am getting this right. If I embed an iframe in my website, traffic from Tor users will get tunneled through my user visitor's IP? How does consent works with relay.love? Does my website vistor's IP show up as TOR exit node?

It not an exit. But by default someone has to knowingly run the Snowflake applet but webmasters could modify the code to automatically essentially start a Tor guard in someones browser. Though, that would be very evil to abuse someones resources like that. That example has the users consent before starting.

[deleted]

Re: Snowflake

#13
post #7

If Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.

They could block Snowflakes with IPs from networks in unsafe countries, but that is trivially bypassed by the attacker just buying VPSs (or botnet nodes) in a freer country.

Skimming the Technical Overview[0], I don't see anything about mitigating the risks you mention.

The purpose of Snowflake seems to be to circumvent blocking of Tor, not to prevent detection of using Tor. It takes advantage of "Domain Fronting" and WebRTC to accomplish this.

[0] https://gitlab.torproject.org/tpo/anti-censorship/pluggable-...

Re: Snowflake

#14
There is also a standalone (go) version [0] that can be deployed on a server. "one of the main advantages of standalone Snowflake proxies is that they can be installed on servers and offer a higher bandwidth and more reliable option for users behind restrictive NATs and firewalls."

[0] https://community.torproject.org/relay/setup/snowflake/stand...

Re: Snowflake

#15

> If you switch on the Snowflake below and leave the browser tab open, a user can connect through your new proxy! I am not even sure, if I am getting this right. If I embed an iframe in my website, traffic from Tor users will get tunneled through my user visitor's IP? How does consent works with relay.love? Does my website vistor's IP show up as TOR exit node?

What a strange thing not to require browser consent for.

Re: Snowflake

#17
post #2

So, I'm reminded of the old 'store your files on youtube' thing[0] and I wonder how much bandwidth one could get using the same concept on one of the widely used voice conferencing solutions (like zoom) to further blend in. Bonus if you can do some kind of video steganography to transfer the data and have a 'real' call. [0] https://github.com/DvorakDwarf/Infinite-Storage-Glitch

> Bonus if you can do some kind of video steganography to transfer the data and have a 'real' call.

What you are suggesting would bring the proposed UK Online Safety Bill (OSB) into operation, and by virtue of the encoding/stenography means that GCHQ govt code crackers will be involved in what would be classed Police matters, not govt regulator aka OfCom matters, despite the UK govt suggesting its just a function of the regulator. The OSB also reads like it will extend beyond borders, simply on the grounds that it could be used in the UK.

Re: Snowflake

#18
Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend.

The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear that countries like Iran and China would just block all of AWS.

1. https://en.wikipedia.org/wiki/Domain_fronting 2. https://azure.microsoft.com/en-us/updates/generally-availabl... 3. https://signal.org/blog/looking-back-on-the-front/

Re: Snowflake

#19
post #7

If Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.

"Just" don't connect from an IP that can be tied back to you, use black market sim in a separate phone, connect from places you don't go, turn it off when not in use... It gets expensive fast...

Re: Snowflake

#20
post #7

If Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.

"Just" don't connect from an IP that can be tied back to you, use black market sim in a separate phone, connect from places you don't go, turn it off when not in use... It gets expensive fast...

> use black market sim in a separate phone

In most countries this takes you from “may have committed a crime” to “have actually committed a crime”

Post reply on HN