Live data from Hacker News

Things You Should Know About Tor

eff.org

31–40 of 115 posts

Re: Things You Should Know About Tor

#32
post #29

Earlier quoted context omitted.

Sure, but this is why pretty much every resource on Tor stresses the importance of end-to-end encryption for sensitive or identifying info.

That's why I mention sslstrip (check out the presentation - it's scary) and overall lack of SSL on the internet. To provide some anecdata, my browser window currently has 8 tabs open right now. Those that support HTTPS: news.ycombinator.com; twitter.com; www.torproject.org Those that don't: cryptome.org (!); zzaper.co.uk (the Vim tips article from a few days ago); forbes.com; vimeo.com; nytimes.com End-to-end encrypt…

I will say safeguards against tampering are getting better for newer browsers. I'm working on a software stack for PirateBox type systems but focused on security, so I get a pretty good glimpse at how a lot of sites handle incorrect certs, since it's an internetless portal and redirects everything to its hosted SSL page. Both gmail and hackernews will refuse to load at all, as they properly support HSTS. Well gmail "cheats" and is hard coded in chrome.

Re: Things You Should Know About Tor

#33
>They have been able to compromise certain Tor users in specific situations. Historically this has been done by finding an exploit for the Tor Browser Bundle or by exploiting a user that has misconfigured Tor.

I'm not touching TOR until I figure out how they managed to capture Ross Ulbricht.

I highly doubt that he had his TOR misconfigured.

Re: Things You Should Know About Tor

#34

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

a) The NSA collects first and targets later b) The NSA may control the exit node your traffic is going through vs the NSA collects all network traffic from everywhere.

Using tor do add an additional anonymity layer.

Re: Things You Should Know About Tor

#35

Earlier quoted context omitted.

That's why I mention sslstrip (check out the presentation - it's scary) and overall lack of SSL on the internet. To provide some anecdata, my browser window currently has 8 tabs open right now. Those that support HTTPS: news.ycombinator.com; twitter.com; www.torproject.org Those that don't: cryptome.org (!); zzaper.co.uk (the Vim tips article from a few days ago); forbes.com; vimeo.com; nytimes.com End-to-end encrypt…

I will say safeguards against tampering are getting better for newer browsers. I'm working on a software stack for PirateBox type systems but focused on security, so I get a pretty good glimpse at how a lot of sites handle incorrect certs, since it's an internetless portal and redirects everything to its hosted SSL page. Both gmail and hackernews will refuse to load at all, as they properly support HSTS. Well gmail "…

So how does Gmail do it with other browsers?

Re: Things You Should Know About Tor

#37

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

I think the key is that Tor should only be used with HTTPS connections. Anyone that's like "zomg, my HTTP connections are being recorded by Tor exit nodes don't use Tor!" is kinda being a bit silly. I know personally people the have designed hardware for major ISPs to specifically record HTTP traffic for non-benign purposes.

I don't trust Tor for a completely different reason: you become a threat. Just by sending Tor traffic from your home, you're flagged as a potential active monitoring target, and I don't really need the additional heat.

Re: Things You Should Know About Tor

#38
post #16

"It is also important to remember that if you log into services like Google and Facebook over Tor, you will be sacrificing your anonymity to those services." It is important to note that both Google and FB can track you on 3rd party websites through things like "Like" button. Consider disabling 3rd party cookies completely or using plugins like Ghostery.

I have always wondered about that. What if I completely switch all my network traffic to Tor continue using all the services as I currently do? What are the implications involved here?

Re: Things You Should Know About Tor

#40

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

I hope you realize you just described the entire Internet. Which is the ultimate irony of complaining about the security of tor: you're trusting someone else to forward your packets. Yes, yes they can modify the traffic to and from your host, and yes, yes they can monitor everything you're doing. The difference with the non-tor Internet is that it's far far easier to do that.
Post reply on HN