Earlier quoted context omitted.
I'm running exits since about 9 months. Have been running non exits for over a decade before. The exits are run by a non-profit (a Swiss Verein) and use the recommended setup like described in the blog post. The ISP knows it's an exit, it has a page on port 80 describing it and a PTR record that contains tor-exit. No contact with the police till now. If you would like to support the Tor network but don't want to run…
Thanks for doing this. Early 2010s, I provided free wifi when I lived across the street from a subsidized housing block. I tunneled all their traffic through Tor (including DNS via a hacky script). I was too much of a coward to take the risk of the police breaking down my door because of something done by some random person using the free wifi. Thanks to others like you who were braver than I was, a bunch of folks ha…
Tor Browser 12.0
221–230 of 230 posts
Re: Tor Browser 12.0
#222Earlier quoted context omitted.
For me old.reddit.com seems to work just as well with or without Tor (eg via Brave). The website served at the raw domain barely functions IME, so perhaps that's where the issue lie?
The problem is user account creation, usually. Read-only access works pretty well in most cases (unless it is behind Cloudflare, then you're @#$%@#^%).
Try again, this hasn't been the case for a long time.
Re: Tor Browser 12.0
#223Just FYI that HN is very anti-tor. I made this account via Tor just now to prove the point. It will be dead by default (unless someone "vouches" for it). It's a very user-hostile stance that HN takes (along with not letting you delete your account). It really makes you wonder what they're doing with all this data? Doxxing is almost a given.
Yup. Suspicious just like when reddit became hostile to Tor. It's also a violation of the spirit of the internet. Tim Berners-Lee wrote about this in the December 2010 issue of Scientific American that any walled off website that blocks you from accessing it is unacceptable because it's not the web anymore.
It is a personal point of pride that LokiList allows posting over Tor. Not many clearnet sites do, especially without registration.
Re: Tor Browser 12.0
#224Earlier quoted context omitted.
Thanks for doing this. Early 2010s, I provided free wifi when I lived across the street from a subsidized housing block. I tunneled all their traffic through Tor (including DNS via a hacky script). I was too much of a coward to take the risk of the police breaking down my door because of something done by some random person using the free wifi. Thanks to others like you who were braver than I was, a bunch of folks ha…
But then weren't you leaking all their HTTP traffic to a possibly malicious exit node?
Re: Tor Browser 12.0
#225Earlier quoted context omitted.
But then weren't you leaking all their HTTP traffic to a possibly malicious exit node?
These are people who connected to a random open wifi network. Tor exit nodes were probably the least of their worries.
Re: Tor Browser 12.0
#226Earlier quoted context omitted.
Thanks for doing this. Early 2010s, I provided free wifi when I lived across the street from a subsidized housing block. I tunneled all their traffic through Tor (including DNS via a hacky script). I was too much of a coward to take the risk of the police breaking down my door because of something done by some random person using the free wifi. Thanks to others like you who were braver than I was, a bunch of folks ha…
But then weren't you leaking all their HTTP traffic to a possibly malicious exit node?
There was a captive portal page (another hacky script running as a CGI) where the user had to agree to, "not be a dick" to continue. And, the user also had to agree that they were aware that others, who were dicks, could be accessing their data if it was not encrypted and gave the example of http vs. https in the address bar of the browser.
There was also a picture of an onion on the captive portal page, and a link to a FAQ which talked about open wifi and Tor. Exit nodes were not geo restricted, so if nothing else, the warnings and explanations allowed the users to understand why sites often seemed to think they were in a different country.
There is a limit to what people are able to digest about a subject that is not one they focus on. But, the warnings (right on the main captive portal page; without having to navigate to the FAQ) were sufficiently scary to encourage caution.
The most likely available alternative would have been public access terminals in the library, or other open wifi for those with portable devices. Public access terminals could be running keyloggers and worse. Even if the public terminal is free of malware, the non-technical user might just close a logged in browser tab/window, not realizing that is not sufficient to log them out.
Yes, even with users being careful about looking for https in the URL bar, some websites are broken and use https for their login page, but use http for their session cookies. But, trying to protect from these incompetent websites would require shutting down all public wifi everywhere (OWE [opportunistic wifi encryption without authentication] did not exist yet).
I think my open wifi (and open wifi generally, as well as Tor) were/are a net good. If, after this additional detail you still disagree, then we will just have to disagree.
Re: Tor Browser 12.0
#227Earlier quoted context omitted.
But then weren't you leaking all their HTTP traffic to a possibly malicious exit node?
Good point. I considered adding more details, but felt they were off-topic to the purpose of my post, and didn't want to have the "thank you, brave soul for running an exit node. Your actions might enable other good things that you might not have expected" message lost in noise. There was a captive portal page (another hacky script running as a CGI) where the user had to agree to, "not be a dick" to continue. And, th…
Re: Tor Browser 12.0
#228Earlier quoted context omitted.
May I ask: That wasn't enough for you to stop operating a Tor node? People were abusing others thanks to your specific personal efforts and you just said: "eh, it's still worth it". How do you determine that it's still worth it?
Some statistics from one of my servers regarding Tor abuse. From 1130 abuse IPs in my http access log 4 are Tor exit nodes and from the 1905 ssh bruteforce attacker IPs 3 are Tor exit nodes. Stop operating Tor nodes would therefore reduce the abuse by basically nothing but take Tor from the people that need it. >eh, it's still worth it Yes it's totally worth it.
Re: Tor Browser 12.0
#229I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…
It's surprising to me that those people haven't been arrested yet. People get raided for far lesser offenses compared to running Tor exit nodes. Exit nodes are a mistake. The web is a lost cause by now. Most sites already consider access through Tor to be abuse. Exit nodes are also the focus of the deanonymization attacks that I've seen. The Tor hidden service network should be strengthened instead. We should launch…
Re: Tor Browser 12.0
#230Earlier quoted context omitted.
Yea, there is only about 1000 (actually 1300, I just checked) exits - out of only ~6000 nodes total, the Tor network is actually kinda small.
So I guess the question is, how would one scale the number of nodes? Isn't that really what's needed then?