Live data from Hacker News

Tor best practices

digital-era.net

11–20 of 59 posts

Re: Tor best practices

#11
post #7
post #3

I don't think the article mentions it, but in addition to the tips in the article, stay away from wireless or bluetooth connections, remove the card(s) if possible... While it might seem tin foil hat, any over-the-air communication is fairly trackable (not saying wired isn't). And while your computer or device tries to connect to a network, The control packets sent out to channel 0 will even send a list of preferred…

FBI also once had a carrier OTA update somebody's internet usb stick to broadcast their location

[citation needed]

Re: Tor best practices

#12

Earlier quoted context omitted.

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

> People can still compare when you're using your internet on Tor and when you doing activities online (on Tor) Ok, so what is the threat model in this case? (really want to understand)

Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012.

Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day.

Not enough to prove anything, but there's definitely some circumstantial evidence there.

Re: Tor best practices

#13
post #3

I don't think the article mentions it, but in addition to the tips in the article, stay away from wireless or bluetooth connections, remove the card(s) if possible... While it might seem tin foil hat, any over-the-air communication is fairly trackable (not saying wired isn't). And while your computer or device tries to connect to a network, The control packets sent out to channel 0 will even send a list of preferred…

[deleted]

Re: Tor best practices

#14
post #10

Earlier quoted context omitted.

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

"using your internet on Tor" and "doing online activities (on Tor)" sound like the same thing to me. But this whole article sounds to me like the author's expecting people to only ever use Tor when they want to hide something. What we should be doing is encouraging everyone to use Tor all the time for everything, delays be damned. That totally obliterates any correlative analysis.

[deleted]

Re: Tor best practices

#15
post #10

Earlier quoted context omitted.

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

"using your internet on Tor" and "doing online activities (on Tor)" sound like the same thing to me. But this whole article sounds to me like the author's expecting people to only ever use Tor when they want to hide something. What we should be doing is encouraging everyone to use Tor all the time for everything, delays be damned. That totally obliterates any correlative analysis.

This only stops the simple correlative analysis. You could probably still do correlative packet timing attacks(correlating the sent/recieve time of packets from you and from the server) , and active attacks(by adding some data to your/server packet at the ISP and watching this packet flow across the network).

Re: Tor best practices

#16

I really don't understand any of the points in "Your Environment". > Never use Tor from home, or near home. Never work on anything sensitive enough to require Tor from home, even if you remain offline. Computers have a funny habit of liking to be connected… How exactly? The entire point of Tor is that such stuff should not matter since the first node doesn't know what you have requested. > And while the jackboots are…

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

OTOH, you can also run a Tor node and your ISP wouldn't be able to see anything (other than you running a Tor node). For added security, run a Tor Exit Node and your ISP wouldn't be able to determine when you stop using the regular internet, either.

Re: Tor best practices

#17
"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick.

If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made a serious mistake.

Using a JSON or XML based API would be much safer since you aren't having to trust any level of javascript, css, or html...fetching executable code over the internet from a third party is the ROOT of the problem.

It all comes down to what you are trying to do...why are you using tor? who is your adversary?

Just using tails or whonix and being super paranoid...because security...is kind of a shit lifestyle decision. It can also lead to a false sense of security.

Re: Tor best practices

#18
There are too many third party requests/tracking scripts (Google Adsense, Analytics, webfonts; icon font from bootstrapcdn.com; Twitter avatars) in this blog.

The blog itself is hosted in Wordpress.com. I don't if this is good or bad for visitors' privacy, but it feels bad.

(I know this kind of comment — X advocates Y but does Z, where Z != Y — is often annoying and shortsighted. That said, hypocrisy, even when it's unintended, reduces your authoritativeness.)

Re: Tor best practices

#20
post #3

I don't think the article mentions it, but in addition to the tips in the article, stay away from wireless or bluetooth connections, remove the card(s) if possible... While it might seem tin foil hat, any over-the-air communication is fairly trackable (not saying wired isn't). And while your computer or device tries to connect to a network, The control packets sent out to channel 0 will even send a list of preferred…

That is an issue but how do you combine this with not connecting from your home? I would hope that as long as you keep care with your preferred networks and only connect over Tor the idea of using lots of cafe wifi spots is better than just using your own wired internet?

Use macchanger in init startup scripts to hand out something random, use a live o/s or don't keep any preferred wireless AP history
Post reply on HN