Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

31–40 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#31
post #2

Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Does anyone know what is state of the art in vocab fingerprinting?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#32
post #8

Earlier quoted context omitted.

>Too bad onions was compromised by the NSA. that makes speaking up against the Bad Guys a bit more dangerous. Any references you would want to provide for this claim?

If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.

> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you.

That's why Tor Browser comes with NoScript.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#33
post #22

It's refreshing to notice that in the typical italian political climate of general incompetence, there are still people who do a good job.

You are right in the first part (I'm italian). Regarding people doing a good job, I don't know if this is the case. I tried to use this service (just to see how it works), and:

  - "anonymous reports will be considered only in particular cases" (!)
  - you cannot report if you are a private person/company
  - you have no kind of legal counseling / protection
  - other limitations
I'm not sure if it was designed to get actual reports or not.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#34
post #2

Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Is that actually a controversy? I feel like everyone I talk to with any credible claim to security expertise recommends against it.

So much so that I’d like to see an expert recommend it.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#35

Earlier quoted context omitted.

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Is that actually a controversy? I feel like everyone I talk to with any credible claim to security expertise recommends against it. So much so that I’d like to see an expert recommend it.

> So much so that I’d like to see an expert recommend it.

Bruce Schneier?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#36
post #2

Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Even if you use it perfectly, between fingerprinting techniques which could be used to cross-reference your logged-in "normal" use and some of the communications Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched), I would be sure someone couldn't pierce the veil of anonymity.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#37

Earlier quoted context omitted.

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Is that actually a controversy? I feel like everyone I talk to with any credible claim to security expertise recommends against it. So much so that I’d like to see an expert recommend it.

Yeah, I've seen people go apoplectic at the idea.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#38

Earlier quoted context omitted.

Pretty bold claim about !%. Do you by any chance have any refs or links at hand explaining the topic more into depth. There are quite a lot on Tor www but covering more common use.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#39

Earlier quoted context omitted.

Pretty bold claim about !%. Do you by any chance have any refs or links at hand explaining the topic more into depth. There are quite a lot on Tor www but covering more common use.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

> Tor is far more fingerprintable than people think it is

You seem to have no idea about the existence of pluggable transports.[1][2]

> and its riddled with adversaries and malware.

Yes, and so is I2P... Freenet... the Internet?

> Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you.

Isn't that an argument for using Tor? As Mike Perry (who works now on the vanguard proposal implementation) puts it, "we want enough people to actually use Tor Browser such that it becomes less interesting that you're a Tor user. We have plenty of academic research and mathematical proofs that tell us quite clearly that the more people use Tor, the better the privacy, anonymity, and traffic analysis resistance properties will become."

> Just use a burner iPad and wipe it frequently. If you're truly paranoid light up a DigitalOcean droplet with a pre-paid credit card and a false name and install OpenVPN on it make an image and cycle your IP.

Your IP will be known since you connect directly using your IP to the droplet. Also doesn't protect you from browser fingerprinting which alone may have leaked enough information to identify you.

[1] : https://www.torproject.org/docs/pluggable-transports.html.en

[2] : https://www.pluggabletransports.info/ (really good folks work on them, and we should appreciate the amount of work that they put in obfs research)

Re: Italian Anti-Corruption Authority Adopts Onion Services

#40

Earlier quoted context omitted.

Pretty bold claim about !%. Do you by any chance have any refs or links at hand explaining the topic more into depth. There are quite a lot on Tor www but covering more common use.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

> Tor [... is] riddled with [...] malware.

what the ass does this even mean

Post reply on HN