Live data from Hacker News

BBC News launches 'dark web' Tor mirror

bbc.co.uk

221–230 of 306 posts

Re: BBC News launches 'dark web' Tor mirror

#222
post #170

Earlier quoted context omitted.

I'm normally the tinfoil-hat guy in any given discussion. I'll go out on a limb and predict that my HN internet points score is not a signal of interest to NSA selection criteria.

Wait, why not? Knowing who votes for what content, when, and in coordination with whom else seems like it would be extremely useful indeed! Aren't techniques like this already used by FBI etc on Twitter when investigating illegal content and coordination of its' dissemination? Bot networks are taken down on Twitter and other sites all the time using voting data. Social voting data is a rather sizable and useful datas…

> HN may have your email address privately (if you gave it to them) and they also have your IP/access logs. This is all stuff that they save but is not publicly available information.

I'm pretty certain there's nothing the NSA doesn't already have. See the Swowden gifts on MUSCULAR[1] the better-known PRISM[2], and XKEYSCORE[3]. There are other relevant programs, but I don't have my notes on that stuff with me at the moment.

Anyway, I won't argue about how much the NSA values internet scores. Let's just say I can imagine a targeted extortion campaign against a specific individual using such inputs, but I can't see how the Great Hoover would use them as any sort of actionable signal.

[1] http://apps.washingtonpost.com/g/page/world/how-the-nsas-mus...

[2] https://en.wikipedia.org/wiki/PRISM_%28surveillance_program%...

[3] https://en.wikipedia.org/wiki/XKeyscore

Re: BBC News launches 'dark web' Tor mirror

#223

Potentially I am misunderstanding how Tor's onion routing works, but according to https://metrics.torproject.org/networksize.html there are about 6000 tor relays right now. Surely if some well funded organisation (Eve) were to install a similar number of relays itself, then it is reasonably likely that for a given user a packet would eventually travel across relays solely owned by Eve, and at that point Eve could map…

You're not missing anything - Tor is not designed to defend against a global passive network observer.

> A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic […]

https://svn.torproject.org/svn/projects/design-paper/tor-des...

Re: BBC News launches 'dark web' Tor mirror

#224

Since no one posted that, yet: Tor relies on the size the of its network to counteract blocks, prevent take overs, and naturally ensure stability as well as performance. You can either donate to various groups running Tor servers, the developers, or take part on your own. https://www.noisebridge.net/wiki/Tor https://www.torservers.net/ https://www.dfri.se/donera/ https://nos-oignons.net/ https://donate.torproject.org…

How do I know that my computers won’t be used to traffic child porn, if I donate a server and some bandwidth?

You can't, you're in the same moral quandary an ISP finds itself in.

Re: BBC News launches 'dark web' Tor mirror

#225

Since no one posted that, yet: Tor relies on the size the of its network to counteract blocks, prevent take overs, and naturally ensure stability as well as performance. You can either donate to various groups running Tor servers, the developers, or take part on your own. https://www.noisebridge.net/wiki/Tor https://www.torservers.net/ https://www.dfri.se/donera/ https://nos-oignons.net/ https://donate.torproject.org…

The real question is the kind of liability you take on when running a tor node on a machine that "belongs" to you (for some definition of belong). Another is to find a place that will agree to power your machine and allow it to hook in to the ethernet if it runs a tor node. At any rate, running a tor node isn't as simple as running apt-get.

I run two relay nodes. It is exactly as simple as running apt-get and editing the config.

Re: BBC News launches 'dark web' Tor mirror

#226

Earlier quoted context omitted.

Both if possible. A Pi 3 can saturate its ethernet adapter (~50Mbps) running a Tor relay. It's reasonably straightforward to setup. You shouldn't run exit nodes from a home connection due to possible abuse. If a person uses it to do something illegal you may end up with law enforcement busting down your door. Relays are safe though.

I thought the consensus was that law enforcement can "crack" Tor these days (a la tracing the illegal traffic back to the source, not just the exit node) Is this not the case, or is it not a black/white answer?

People will hack the sites that are proxied behind Tor .onion domains. Hacking a site is also a crime, so you won't find too many documents revealing how a crime network was exposed. Instead, they gather data from the hacked servers and hand it over as anonymous tips.

Tor is just a proxy. A fancy proxy that uses onion routing, but a proxy nonetheless. Think of it as a CDN that does not have to hand over customer details because they have plausible deniability about who you are. Unlike commercial CDN's however, Tor does not try to prevent hacking. That exercise is left to the people running the servers that Tor is routing to. As it turns out, some criminals may be lazy or inept.

Re: BBC News launches 'dark web' Tor mirror

#227

Ethereum has contract call ENS (Ethereum Name Service). It's kind of like a decentralized DNS. People are starting to use that to create .eth domain names that point to .onion sites. https://medium.com/the-ethereum-name-service/list-of-ens-nam...

Why is this of interest?

.onion urls are difficult to remember. ENS provides human readable names that point to .onion urls.

Re: BBC News launches 'dark web' Tor mirror

#228

Earlier quoted context omitted.

Both if possible. A Pi 3 can saturate its ethernet adapter (~50Mbps) running a Tor relay. It's reasonably straightforward to setup. You shouldn't run exit nodes from a home connection due to possible abuse. If a person uses it to do something illegal you may end up with law enforcement busting down your door. Relays are safe though.

I thought the consensus was that law enforcement can "crack" Tor these days (a la tracing the illegal traffic back to the source, not just the exit node) Is this not the case, or is it not a black/white answer?

https://2019.www.torproject.org/docs/faq.html.en#AttacksOnOn... It's not 100%, but the more of the connection your attacker can see, the worse your odds. If you're in the USA and you're using nodes in the Five Eyes https://en.wikipedia.org/wiki/Five_Eyes and you're being tracked by the NSA, they might be able to see everything. Maybe. Also check point #4 on this answer https://2019.www.torproject.org/docs/faq.html.en#EverybodyAR...

Re: BBC News launches 'dark web' Tor mirror

#229

BTW NYtimes has been doing this for a while. https://open.nytimes.com/https-open-nytimes-com-the-new-york... https://www.nytimes3xbfgragh.onion/

Yet does not allow you to sign up anonymously. I'm still not sure why you need to host a tor site unless your server is in a censored country.

Re: BBC News launches 'dark web' Tor mirror

#230

Earlier quoted context omitted.

Is it worth it to donate, or to just pool a little cash and start your own? Like, how do I know any of those links aren't the NSA? I ask because I have 5-6 Raspberry Pis, a couple retired Supermicro boxes, and old Cisco gear that isn't doing much...

>Like, how do I know any of those links aren't the NSA? Well, I've only linked to communities listed by the Tor Project itself. Otherwise, the same way you would check whether HN or your local tea store is the NSA. You do your own research, run your own risk analysis, and if you want to stay sane, by default you give people the benefit of the doubt. Generally, it's best not to run Tor relays from home as services wil…

> Generally, it's best not to run Tor relays from home as services will start to blacklist your IP as a proxy.

Conversely, if you're engaging in illegal online behavior from your home IP, intermittently running a TOR exit node could be a useful mechanism for creating plausible deniability.

Post reply on HN