Live data from Hacker News

Tor and HTTPS

eff.org

21–30 of 135 posts

Re: Tor and HTTPS

#21
post #2

When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?

well, it is serious, in that it's the most likely weak point in tor. however, exactly how serious is still an open question. remember - what the nsa wants is both your location and the site. your location alone only means that you were using the internet (and tor, which itself might be regarded a suspicious). the site alone only means someone was using the site. what the NSA have to do is connect those. so everything…

Would it be helpful to run a forwarding (at least non-exit, possibly entry) Tor node on one’s own computer to mask the Tor traffic actually originating from this machine?

Re: Tor and HTTPS

#22

Earlier quoted context omitted.

well, it is serious, in that it's the most likely weak point in tor. however, exactly how serious is still an open question. remember - what the nsa wants is both your location and the site. your location alone only means that you were using the internet (and tor, which itself might be regarded a suspicious). the site alone only means someone was using the site. what the NSA have to do is connect those. so everything…

Would it be helpful to run a forwarding (at least non-exit, possibly entry) Tor node on one’s own computer to mask the Tor traffic actually originating from this machine?

i think it might, but only at about the level of adding an extra tor hop (the NSA can compare requests in and out, and try to detect which ones out are extra).

Re: Tor and HTTPS

#25
How legal is operating a Tor node? I'm thinking of putting up a machine (and a VPS) to just run a node. I just don't want to get into legal trouble for running a(n exit) node.

Re: Tor and HTTPS

#26
Maybe I'm misinformed, but I thought the big problem has less to do with data in transit than it does with the destinations (Google, Facebook, Microsoft, etc) working hand-in-hand with the NSA? What am I missing?

Re: Tor and HTTPS

#27

How legal is operating a Tor node? I'm thinking of putting up a machine (and a VPS) to just run a node. I just don't want to get into legal trouble for running a(n exit) node.

That depends on your jurisdiction. In many countries it is perfectly legal. It is also very safe and low maintenance.

Re: Tor and HTTPS

#28
Assuming the NSA is tapping ISP cables, and siphoning all unencrypted data of the web, and that they need to ask the big companies in the slides for the encrypted data, would EFF's "HTTPS Everywhere" help with all the websites that are not encrypted, like say Reddit?

Re: Tor and HTTPS

#29

How legal is operating a Tor node? I'm thinking of putting up a machine (and a VPS) to just run a node. I just don't want to get into legal trouble for running a(n exit) node.

Running a regular node is fine as you're routing encrypted information for the Tor network - your unlikely to get any hassle although check your countries laws on crypto first.

Running an exit node may be a different story. You could get false DMCA takedown notices or get charged with someone else's crime. Think of it this way; you're running an open proxy. Uses of Tor can send any traffic through your connection. That being said, some ISPs are ok with it, others won't tolerate it.

I suggest you checkout https://blog.torproject.org/running-exit-node if your really serious about running an exit node.

Re: Tor and HTTPS

#30
post #28

Assuming the NSA is tapping ISP cables, and siphoning all unencrypted data of the web, and that they need to ask the big companies in the slides for the encrypted data, would EFF's "HTTPS Everywhere" help with all the websites that are not encrypted, like say Reddit?

I thought "HTTPS everywhere" is just switching your connection from HTTP to HTTPS when the site you are visiting is on the list of sites known to support their services over HTTPS.
Post reply on HN