Live data from Hacker News

Tor best practices

digital-era.net

21–30 of 59 posts

Re: Tor best practices

#21
It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".

Re: Tor best practices

#22
post #21

It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".

"doing some shady shit" Or he is a freedom fighter)

Re: Tor best practices

#23
post #22
post #21

It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".

"doing some shady shit" Or he is a freedom fighter)

Or Stallman:

"For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time."

Re: Tor best practices

#24
post #21

It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".

The only real reason people use Tor at all is for shady shit. They'll deny it all they want and bullshit on about "freedom", but not even Stallman is this autistic. Come on.

Re: Tor best practices

#25

"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…

> The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick.

It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't open to peer review. Moreover, the Tor Freedom Host attack only exploited Firefox on Windows.

> Just using tails or whonix and being super paranoid...because security...is kind of a shit lifestyle decision.

Don't you think this is a little rude? Or even just presumptive?

Re: Tor best practices

#26
post #12

Earlier quoted context omitted.

> People can still compare when you're using your internet on Tor and when you doing activities online (on Tor) Ok, so what is the threat model in this case? (really want to understand)

Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012. Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day. Not enough to prove anything, but there's definitely some circumstantial evidence there.

But if you use Tor for all of your day-to-day browsing, in strict contrast with the OP's recommendation, then there's not such a glaring correlation.

Re: Tor best practices

#27
post #10

Earlier quoted context omitted.

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

"using your internet on Tor" and "doing online activities (on Tor)" sound like the same thing to me. But this whole article sounds to me like the author's expecting people to only ever use Tor when they want to hide something. What we should be doing is encouraging everyone to use Tor all the time for everything, delays be damned. That totally obliterates any correlative analysis.

Ya the anonymity sometimes isn't because I'm doing anything illegal. I've been considering setting up Tor on my firewall/router and starting to funnel connections to google, bing, facebook and things like that through it. Probably eventually funnel all http and https through it.

Re: Tor best practices

#28
post #25

"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…

> The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't…

He is right though, FF 0day is probably not expensive regardless of O/S. A life on the run or using multiple safe houses is also a shitty lifestyle when you could just avoid all tracking cookies and executable 3rd party code with a terminal script and not have to wear a fake beard at a different starbucks everday

Re: Tor best practices

#29
post #26
post #12

Earlier quoted context omitted.

Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012. Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day. Not enough to prove anything, but there's definitely some circumstantial evidence there.

But if you use Tor for all of your day-to-day browsing, in strict contrast with the OP's recommendation, then there's not such a glaring correlation.

You've still got the spike in network activity, and if you're running a relay, you've still got the spike in outgoing activity minus incoming activity.

Re: Tor best practices

#30
post #25

"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…

> The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't…

I love that "Microsoft has backdoors"...no one credible has said that they have proof of that. They give the US Government early access to vulnerability data...they give those updates to several governments and large corporations early as the result of agreements they have made with big customers. They also let these same entities audit the source code for windows. Look it up. If you have the money and its important to you then, yes, you can audit the windows code base.

"security-conscious people prefer Linux"...That's kind of a sweeping statement. What does security conscious even mean?

To me it sounds like this..."People who talk about security a lot use Linux by and large"..."but some of them are really partial to OpenBSD"..."and lots of Windows security experts really use Windows a lot."

I say that its a shit lifestyle decision because what is it accomplishing? You use this really restricted platform to make sure that people can't track you doing ??? What exactly? Communicating with your team of spy's??? Downloading midget porn??? Why do you think that you can have a single workstation that's good for every security corner case? What in the history of computer security makes you think that is a good idea or even desirable?

Let's take the example of the Iranian dissident trying to avoid the oppressive badies in their weird ass government...what does tails or Linux buy you? You are better off with the "throw away laptop" plan using good opsec and running tor from public places. Don't use it for anything but tor and tweeting your pics of black helmeted assholes. Get a new one as soon as possible. Rotate them with other people. The OS means next to nothing.

People keep conflating tor's uses with every possible InfoSec edge case. The dissident has different needs than a guy trying to make sure that the NSA doesn't catch him posting documents. The whistleblower has different needs than the guy buying drugs.

In all cases applying some critical thinking about what you are trying to do is a bigger exercise than "Winblows is the suxor at securitehz!"

Unix doesn't have a monopoly on security. I'm not saying windows does, but Unix people are kind of crazy about their pet platform.

Post reply on HN