Live data from Hacker News

Zed Shaw: Why I Don't Use Tor

sheddingbikes.com

21–30 of 170 posts

Re: Zed Shaw: Why I Don't Use Tor

#22
post #18

It's an interesting question. If Project Vigilant had compromised Tor, I'd expect there to be quite a few pedophiles who had used it to share cp getting busted. I'm not aware of any such incidents, let alone many. I imagine that the government wouldn't want to give away that they had it compromised, and so would simply use the information to compose a list of people to watch for slip ups, but one would expect to see…

I find funny that I was re-reading a novel this morning during the commute, about a WWII cryptographer and arrived at the point were he sees that the warning in every secret document was "never take any action that could reveal the enemy that we can break their encryption".

I don't suppose MILINT has gotten any less competent in the last 60-odd years, but not disclosing that Tor is compromised would seriously hamper using it as a source for law enforcement, hence my thinking it would be more likely to be NSA. If so, I doubt we'd ever know, short of somebody leaking it.

Re: Zed Shaw: Why I Don't Use Tor

#23
OMG! The government created something useful therefore it can only, fundamentally, be a trojan horse. While I'm sure there could be some crackers out there trying to insert bad code. I also believe these things tend not to stick around for long. Especially when blame says "Hey, I've inserted code here, here and here. Try not to read me too closely."

I've tried Tor in the past and I stopped because:

* It's really slow.

* It's the chatroulette of really questionnable material. You stumble into some shit and think WTF?!

* The amount of traffic it generated caused my shitty router to slow down significantly or crash completely.

Re: Zed Shaw: Why I Don't Use Tor

#24
Ad Hominems are a-ok now are they? Well here's Zed's thought process:

a) Read Greenwald Salon article accusing Wired of having shady connections.

b) Roll that basic premise into a set of wild accusations and things we already know about Tor.

c) Sit back and enjoy the whole chaos of the troll. When someone attacks bring out the usual sockpuppets and sycophants to say "but Zed does all this great coding", "Zed is not like that in real life/conferences".

d) Profit/save on therapist fees by feeding own teenager-like angst and need for attention.

Re: Zed Shaw: Why I Don't Use Tor

#25
post #23

OMG! The government created something useful therefore it can only, fundamentally, be a trojan horse. While I'm sure there could be some crackers out there trying to insert bad code. I also believe these things tend not to stick around for long. Especially when blame says "Hey, I've inserted code here, here and here. Try not to read me too closely." I've tried Tor in the past and I stopped because: * It's really slow…

If wikileaks can snoop tor nodes to get its first data release than that is in fact a trojan horse..no imagination required..

Re: Zed Shaw: Why I Don't Use Tor

#26
This, to me, sounds like a classic case of not knowing what you're protecting against. TOR hides your IP address by preventing the destination server ever needing to do a TCP/IP handshake. There is no way to complete a TCP/IP handshake without you revealing your IP address. TOR then also stops the server you /do/ handshake with knowing the destination of your packet.

This is all TOR is supposed to do. This allows you to be anonymous to the receiving end, but it does not guarantee it. It is your responsibility to surf safely, to sanitise your traffic, to encrypt your traffic and do the rest. We know that most people can be uniquely differentiated by combining all the available information from their browsers (some of which doesn't need javascript) http://panopticlick.eff.org/ . Therefore we know, using TOR or not, that we need to be careful to do things well when we want to be anonymous.

There is little in this article which makes me worried about TOR. TOR isn't the problem, if any of this is true, then the problem is the government collecting data in various ways. Whether you agree with this is a matter for yourself to consider and not a reason to avoid using TOR.

Re: Zed Shaw: Why I Don't Use Tor

#27
post #14
post #4

> P.S. I have a long bet that SELinux is an NSA backdoor. Any takers? I don't know if it's an NSA backdoor, but there were several security alerts related to SELinux. I don't understand why all common distros use this. I don't, I compile my kernels from unpatched vanilla source.

> there were several security alerts related to SELinux. Can you elaborate?

There were several security advisories in the past years, of various privilege escalation or other security holes that were actually in SELinux and not present in the vanilla source. I didn't keep a log of the details but you probably can find them in the advisories archives.

Re: Zed Shaw: Why I Don't Use Tor

#28
post #24

Ad Hominems are a-ok now are they? Well here's Zed's thought process: a) Read Greenwald Salon article accusing Wired of having shady connections. b) Roll that basic premise into a set of wild accusations and things we already know about Tor. c) Sit back and enjoy the whole chaos of the troll. When someone attacks bring out the usual sockpuppets and sycophants to say "but Zed does all this great coding", "Zed is not l…

There's more to Ad Hominem arguments than unjustified personal insults.

Re: Zed Shaw: Why I Don't Use Tor

#29
(I rather suspect that Mr Shaw is trolling, but anyway.)

It's certainly true that humans have all manner of interesting behaviors owing to the fact that we're smart apes with huge numbers of survival heuristics. I would pause before taking a sandwich from Hitler, because I'm human, but it's not pertinent to the question of whether the sandwich is any good. (Except in as far as you think it more or less likely that the sandwich is poisoned etc.)

So I find the whole first half of the text to be a flabby way of saying that the arguments of dishonest people need to be evaluated more critically than those of honest people. But I find that the arguments of honest people need to be critically evaluated too. I think that the authors of Haystack were honest, but their assertions turned out to be dangerously wrong. (Which, by the way, we know thanks to Mr Appelbaum.) So, as a guide, the motives of the author don't seem to be very useful to me.

Then, in the second half, we find a mixture of arguments that I find valid, and many that I don't. A sense of vertigo at the amount of trust that we have to put into software is justified. It is possible to hide major bugs in code and we're standing on a stack of hardware, kernel, and userland which is incomprehensible to any one person these days.

It's also true that there are some fairly effective attacks against Tor for the capable opponent. It's a real-time mix-net, with all the tradeoffs implied and it generates a lot of research. I recommend reading some papers of the papers, I find them often to be very good.

But accusing the Tor people of being NSA agents because they once got funding from the navy doesn't hold water. The Internet was an ARPA funded project. Military spending has subsidised much of the modern world.

Many people have read through Tor's source and evaluated the protocol etc. Of course, all those people could be NSA agents too, publishing fake papers. You could, in fact, be in The Matrix. But you probably aren't.

Some, likely massively exaggerated, secret project might be monitoring every ISP on the planet and thus able to break any real-time mix net, but they probably aren't.

Likewise, all the Tor node operators that I have met might all be NSA plants, but they probably aren't.

And finally the author picks out Mr Appelbaum for special criticism because he connects him with Wikileaks. I think his assertion that the goals of Tor and Wikileaks are in conflict is wrong, but we could go around all day trying to pin down the goals of Wikileaks so that's probably not fruitful. But it does seem ironic that the author voices support for Wikileaks right after asserting that such supporters are not to be trusted.

So, while the stack of software is, indeed, large, Tor remains a reasonable tool to use. If the author is so concerned with the human aspect, the Tor authors are make regular appearances at conferences and are wonderful people to meet. So do, and are, node operators in my experience.

Also, on top of Tor, there's a fair chance that the author is using a browser who's network and SSL stack I've had a hand in. And who knows what kind of person he's taking a sandwich from now?

Re: Zed Shaw: Why I Don't Use Tor

#30
post #10

It's somewhat informative to compare Zed's response to personal criticisms vs those he targets with his own criticisms. Follow the chain of twitter replies and make up your own mind.

So much name calling and playground idiocy. Just looking at a sample of the tweets made my head hurt. Surely most of us don't use Tor because 1. It's slow as hell 2. We're not doing anything illegal or trying to get past censorship

Well I did try to use Tor to get past censorship(I'm in China) and it's not effective here unless you already know someone outside the Chinese network to connect to (that is not a public ip).

They (Tor) are losing their fight. IMO

Post reply on HN