Live data from Hacker News

Zed Shaw: Why I Don't Use Tor

sheddingbikes.com

111–120 of 170 posts

Re: Zed Shaw: Why I Don't Use Tor

#111
post #107

Earlier quoted context omitted.

I'm envisioning a piece of software that lets you IM folks, but with the messages steganographically embedded in emoticons and the cleartext messages autogenerated.

The more different types of traffic that messages could be hidden in, the better. But, personally, I think the best place to hide them right now is video streams. The thing about steganography is that the smaller your hidden message is and the larger the data it's hiding in is, the less of a chance there is of it being detected, and also the greater the cost of such detection will be. Think of it this way: How effect…

This is silly. You can programatically detect e.g. anomalous keyframes from traffic today. Anything you do to try and embed messages in any rich media format (audio, lossy images, video, &c) can be reversed and turned into a filter. The filters won't even need to be accurate; they'll baseline, wait for you to trip a threshold, and then send people to your door to collect your machine.

I'm particularly amused by the comment about using complicated images of ocean waves and trees, as if computers were just mechanical humans trying to make sense of the shapes in the picture.

Re: Zed Shaw: Why I Don't Use Tor

#113
post #100
post #44

It's shit like this Zed... Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox . God damn Zed, this Hitler sandwich shit is pretty weak. Zed also has a problem with Tor because he thinks ther…

Thing is, you don't have to believe Firefox is trustworthy to believe it's your best bet for surfing the web. The whole point of Tor is to be trustworthy; hence, there's no point in it if you don't trust it. Plus, like you said, using Tor may be worse than nothing, so you have to have a pretty strong motivation and pretty strong trust. Using Firefox or OSX requires no such trust.

A comprised web browser or operating system gives the attacker your email credentials, which by proxy gives them the rest of your life. You're trying to argue that an untrustworthy browser/OS is not as significant as an untrustworthy Tor. There isn't such an argument to be made. Browsers and operating systems require trust.

Re: Zed Shaw: Why I Don't Use Tor

#114

It's an interesting question. If Project Vigilant had compromised Tor, I'd expect there to be quite a few pedophiles who had used it to share cp getting busted. I'm not aware of any such incidents, let alone many. I imagine that the government wouldn't want to give away that they had it compromised, and so would simply use the information to compose a list of people to watch for slip ups, but one would expect to see…

  > so would simply use the information to compose a list of
  > people to watch for slip ups
How would they 'watch for slip ups' though? One would think that they would have to justify to a judge why the person was under surveillance in the first place.

Re: Zed Shaw: Why I Don't Use Tor

#115
post #24

Ad Hominems are a-ok now are they? Well here's Zed's thought process: a) Read Greenwald Salon article accusing Wired of having shady connections. b) Roll that basic premise into a set of wild accusations and things we already know about Tor. c) Sit back and enjoy the whole chaos of the troll. When someone attacks bring out the usual sockpuppets and sycophants to say "but Zed does all this great coding", "Zed is not l…

What he is talking about is not Ad Hominem but Conflict of Interest. For example, a judge is required to recuse him or herself from a case in which he or she has a personal interest, such as a business relationship with the plaintiff or defendant. This is probably why Zed has the words "Conflict Of Interest" as a section heading in a very large font.

That section is rambling and contradictory.

For example: "I will go on record right now saying Wikileaks rocks. ... if anyone from Wikileaks tries to work with me or on any project I'm on you bet your ass I'm not trusting them one bit. Never trust a traitor, no matter how noble their intentions."

So Wikileaks "rocks", yet anyone involved in Wikileaks is a traitor and shouldn't be trusted? That seems contradictory. Taking this logic further, are journalists who cite Wikileaks' work also traitors that shouldn't be trusted?

As a fan of Zed's and someone that isn't completely sold on Tor, I'd love to see a sober critique of the project's vulnerbilities from Zed, but this post isn't it.

Re: Zed Shaw: Why I Don't Use Tor

#116
post #99

Earlier quoted context omitted.

From Thomas' post: "Get circumvention at all wrong and you achieve the opposite of what the tool is intended for: you put a big red flag on people breaking their local laws. ... Don't build circumvention tools." That attitude is so wrongheaded I hardly know where to begin. First of all, anyone who uses something like TOR in China has already put a huge (and very very obvious) red flag on their communications stream.…

If you're going to put a big blinking red light on all your packets so that the largest, best-armed surveillance state in the world can collect and analyze them, I guess there's very little harm in waving rubber chickens over them too. Go ahead with the stego. You might want to read Neils Provos' stegdetect stuff, first. The world needs more fun grad student projects, and you wouldn't want people to have to rehash th…

Sure, steganography and steganalysis are in an arms race, just like encryption and cryptanalysis.

But if the existence of such an arms race doesn't stop someone from using encryption it shouldn't stop them from using steganography.

Of course, you need to be prudent about it. Use the most secure techniques available, and don't use methods you know have been broken.

Finally, know that you are taking a risk, that nothing is 100% foolproof, and the more powerful and determined your adversary the more of a risk you're taking.

Re: Zed Shaw: Why I Don't Use Tor

#117
post #29

(I rather suspect that Mr Shaw is trolling, but anyway.) It's certainly true that humans have all manner of interesting behaviors owing to the fact that we're smart apes with huge numbers of survival heuristics. I would pause before taking a sandwich from Hitler, because I'm human, but it's not pertinent to the question of whether the sandwich is any good. (Except in as far as you think it more or less likely that th…

>So I find the whole first half of the text to be a flabby way of saying that the arguments of dishonest people need to be evaluated more critically than those of honest people. But I find that the arguments of honest people need to be critically evaluated too. You over-simplified the argument here, I think. I read it more as a person's motivations need to be considered, not particularly honesty. And nearly everybody…

a person's motivations need to be considered

But how can we know a person's actual motivations? Those are internal to the individual, we can't see them. Heck, in many ways the individual himself doesn't really understand his own motivations.

Trying to consider motivations is thus completely fruitless. We only have the history of a person's actions, and to a lesser extent, the history of his statements, to guide us.

Re: Zed Shaw: Why I Don't Use Tor

#118
post #113
post #100

Earlier quoted context omitted.

Thing is, you don't have to believe Firefox is trustworthy to believe it's your best bet for surfing the web. The whole point of Tor is to be trustworthy; hence, there's no point in it if you don't trust it. Plus, like you said, using Tor may be worse than nothing, so you have to have a pretty strong motivation and pretty strong trust. Using Firefox or OSX requires no such trust.

A comprised web browser or operating system gives the attacker your email credentials, which by proxy gives them the rest of your life. You're trying to argue that an untrustworthy browser/OS is not as significant as an untrustworthy Tor. There isn't such an argument to be made. Browsers and operating systems require trust.

No, all they require is being just as trustworthy as the other browsers and operating systems, even if that level is zero. Tor is an extra inconvenience and calls extra attention to you and therefore requires a credible claim of providing extra security to make up for the downside.

Re: Zed Shaw: Why I Don't Use Tor

#119
post #116

Earlier quoted context omitted.

If you're going to put a big blinking red light on all your packets so that the largest, best-armed surveillance state in the world can collect and analyze them, I guess there's very little harm in waving rubber chickens over them too. Go ahead with the stego. You might want to read Neils Provos' stegdetect stuff, first. The world needs more fun grad student projects, and you wouldn't want people to have to rehash th…

Sure, steganography and steganalysis are in an arms race, just like encryption and cryptanalysis. But if the existence of such an arms race doesn't stop someone from using encryption it shouldn't stop them from using steganography. Of course, you need to be prudent about it. Use the most secure techniques available, and don't use methods you know have been broken. Finally, know that you are taking a risk, that nothin…

We're talking about individuals versus nation states. You're handwaving.

Re: Zed Shaw: Why I Don't Use Tor

#120
post #44

It's shit like this Zed... Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox . God damn Zed, this Hitler sandwich shit is pretty weak. Zed also has a problem with Tor because he thinks ther…

hide a stone among stones and a man among men
Post reply on HN