Live data from Hacker News

Tor Browser 8.5

blog.torproject.org

31–40 of 99 posts

Re: Tor Browser 8.5

#31

Earlier quoted context omitted.

To be fair I mostly use it for not overly sensitive stuff. Let me give you an idea: I prefer to not have my ISP log my requests to reddit.com/r/LSD. Not because I do anything illegal (I don't even take acid), but in this dystopian world where every action on the internet is recorded, the last thing I want is to end up on lists purely because of my curiosity. If I would do anything I could get into trouble for (which…

Please correct me if I'm wrong, but can't your ISP only see that you're requesting reddit.com, as long as you're using https? Now sure, if you go to lsd.reddit.com, it can be logged as a subdomain, but anything beyond reddit.com shouldn't be viewable by your ISP. I'm not saying that you shouldn't use tor, just that as far as I understand, the whole request, including path and method, is encrypted over tls/ssl after y…

I do believe the url path is visible even over HTTPS. Off to do some research on this.

Edit: apparently the url is not visible, but the domain (more like IP, which can be easily resolved to domain).

Same thing still applies, perhaps not with reddit subreddits, but with specific domains/websites.

Re: Tor Browser 8.5

#32
post #16

Earlier quoted context omitted.

You have to be a little weary using tor. Anyone can run an exit node and it is trivial to rewrite and inject onto web pages. You can also on the fly intercept SSL requests and generate your own self signed certificate that fails proper verification but looks real enough if inspected that will always trick a percentage of users. If you've used tor with any frequency you've probably hit weird SSL cert errors that go aw…

To be fair I mostly use it for not overly sensitive stuff. Let me give you an idea: I prefer to not have my ISP log my requests to reddit.com/r/LSD. Not because I do anything illegal (I don't even take acid), but in this dystopian world where every action on the internet is recorded, the last thing I want is to end up on lists purely because of my curiosity. If I would do anything I could get into trouble for (which…

Your ISP won't log the request going to /r/LSD. It's over SSL, so the only thing your ISP sees is a request to reddit.com.

Re: Tor Browser 8.5

#33
post #20

Earlier quoted context omitted.

It is fair to say that using unauthenticated protocols like HTTP over Tor is a pretty bad idea (and there really should be more warning bells about this in the Tor Browser). However on the TLS comment -- almost all modern websites use HSTS, so sslstrip doesn't really work any more.

How about sslstrip2 ([1], check demo)? A weakness of HSTS is that is stored per domain and the exit node can also control your DNS traffic. I wonder how hard it is to pull this off as a Tor exit node, for local networks there are tools like bettercap [2]. [1] https://github.com/byt3bl33d3r/sslstrip2 [2] https://www.bettercap.org/legacy/

[deleted]

Re: Tor Browser 8.5

#34
post #25
post #22

Earlier quoted context omitted.

If using the definition for the dark/deep web that I think, then it includes traffic to and from any networked entity that does not have a URL (or otherwise public frontend). This could then include stored data, VPNs or other company/govt/organisational data that is not accessible via normal web traffic.

I believe thats just the definition for deep web.

Both terms are just stupid.

Deep web: stuff not indexed by search engines. Private forums, non-public social media accounts, Telegram rooms, Discord servers etc. are technically "deep web".

Dark web: a subset of deep web that requires specific software or configuration to access. Slightly more precise, but still includes every possible use case for IPFS, Dat, ".onion" etc. Note that this is nowhere close to what people usually mean when they use the term "dark web". They're referring to the subset of a subset of deep web that's used for criminal activities.

Re: Tor Browser 8.5

#35
post #11

I'm rooting for Mozilla and the Tor Project to uplift Tor into Firefox. Imagine a world where people need to opt in to get less privacy.

The reason to have a Tor browser is that regular browser features aren't well suited to secure anonymous browsing.

The reason to have a regular browser is that you want those features, and the low latency of a direct connection.

Re: Tor Browser 8.5

#36
Are there any casual users of Tor around? Someone who does it not for the sake of safety, but just privacy?

I'd happily use Tor, but the last time I used it (which was ~5 years ago), it was terribly slow for regular browsing (not streaming, or anything considered bandwidth heavy).

Re: Tor Browser 8.5

#37
post #11

I'm rooting for Mozilla and the Tor Project to uplift Tor into Firefox. Imagine a world where people need to opt in to get less privacy.

It's interesting, the only way that would work is if they also turn every browser into a through node, which would be both highly controversial while also a great boon to the Tor network as a whole

Re: Tor Browser 8.5

#38
post #17

I wish people used the deep web for something besides illegal buying and child pornography

I wish people would at least learn the difference between "deep web" and "dark web". ;) I bet you use the "deep web" multiple times each week. The "dark web" on the other hand, probably not.

Depends who you ask.

I transparently use the darknet continuously every day. Multiple home servers owned by me and my colleagues make up a VPN we share with friends and family.

Amongst the trusted recursive resolvers we use there's the DoT v3 onion from Cloudflare. A proxy redirects our traffic for Facebook and DuckDuckGo over the respective onions, same for Debian updates. A next generation firewall inspects our traffic and use Tor for some websites that are censored or geoblocked.

Re: Tor Browser 8.5

#39
post #20

Earlier quoted context omitted.

It is fair to say that using unauthenticated protocols like HTTP over Tor is a pretty bad idea (and there really should be more warning bells about this in the Tor Browser). However on the TLS comment -- almost all modern websites use HSTS, so sslstrip doesn't really work any more.

How about sslstrip2 ([1], check demo)? A weakness of HSTS is that is stored per domain and the exit node can also control your DNS traffic. I wonder how hard it is to pull this off as a Tor exit node, for local networks there are tools like bettercap [2]. [1] https://github.com/byt3bl33d3r/sslstrip2 [2] https://www.bettercap.org/legacy/

That is a pretty neat attack, but I disagree it would be useful against Tor.

DNS traffic is funneled through a different Tor circuit than the web traffic. You'd need to apply the bad DNS to all users, which would almost certainly in your exit node being dropped from the network.

I'm also not sure how this would be handled with HSTS preload lists -- HSTS preload applies to all subdomains so you'd need to come up with a completely different domain (and protections against homograph attacks mean that avenue is restricted). It'd probably be simpler to just set up an actual website with LetsEncrypt than to bother with stripping the TLS in this manner.

Re: Tor Browser 8.5

#40
post #36

Are there any casual users of Tor around? Someone who does it not for the sake of safety, but just privacy? I'd happily use Tor, but the last time I used it (which was ~5 years ago), it was terribly slow for regular browsing (not streaming, or anything considered bandwidth heavy).

What do you mean by casual? I use it relatively often, when I want to access a website privately (I don't trust any VPN service that much). I'm pretty sure I'm not the only person doing that.

But maybe you mean if someone using it as the main browsing tool for privacy reasons? This I doubt, since it's indeed slow. I also don't think that Tor is meant to be used as your main browser really.

Post reply on HN