Live data from Hacker News

Snowflake

snowflake.torproject.org

51–60 of 61 posts

Re: Snowflake

#51
post #44

Earlier quoted context omitted.

[flagged]

You are willfully misrepresenting the situation. The issue isn't that she wrote "men cannot be mothers", it's that she is telling a trans woman "you are a man". If people were running around and telling feminine-looking men "you are a woman" it would be the same situation and handled the same.

[flagged]

Re: Snowflake

#52
post #35

This is a relay for Tor users to be able to access Tor (when normal guard relays (first hop in a Tor circuit) are blocked), using domain fronting and webrtc. The text is written quite confusingly, at least the German translation it served me by default. I was wondering how this could circumvent censorship, as the target needs to also support webrtc so there's no way to access any http(s) website via this in-browser p…

I can't speak to the German translation, but the point the English version is making is you don't install Snowflake, you install software that uses Snowflake (most typically, Tor Browser). It's presumably trying to clarify things for confused users trying to figure out how to install Snowflake as a proxy or VPN application, when that's not how it works.

edit to add the direct quote (which seems pretty clear to me): "Unlike VPNs, you do not need to install a separate application to connect to a Snowflake proxy and bypass censorship. It is usually a circumvention feature embedded within existing apps."

Re: Snowflake

#53
post #7

If Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.

In most places where Snowflake is useful, connecting to Tor is either legal or the laws against it aren't enforced. It's usually the creators/contributors of anti-censorship tools that face repercussions. That said, Tor Project pretty consistently emphasizes that all plugable transports are for AC purposes, not steganographic purposes, and while they're difficult to block, they will not stop the network operator from being able to tell you're connecting to Tor, and that it ultimately falls on the user to decide whether that's acceptable.

Re: Snowflake

#54

Earlier quoted context omitted.

You're just lucky YOU aren't affected yet. Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Or to any of the people who made money on crypto who they want to use as security for an appartment loan. Or to someone trying to wire gains from legal online casinos abroad. Or to someone trying to access a web site that the norwegian authorities do…

My 2c on your scenarios. >Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Probably blocked due to terror laws. If you can't Western Union money, there is a REALLY good reason. Wait until you hear about how we are a cashless society and our bank app for money transfer. That you need mobile ID and bank account to use :) Max tracking. But its…

My point was regarding the "no censorship in Scandinavia" comment that I replied to. The rest of your arguments are just ramblings about you not caring about individual freedom. You even justify their actions using your own made up arguments (which I'm not even bother going to sensibly refute). It is your exact attitude that gets us into trouble with power greedy politicians. You're an easy mark.

Re: Snowflake

#55
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

When I last looked, the intent was that eventually ECH endpoints offer the same effective service that you got with Domain Fronting, but without messing with the backend in a way which is disruptive for the cloud providers so they support it. Encrypted Client Hello is the in-progress work to have even the client's initial contact to an HTTPS server be encrypted. https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ W…

ECH is a good idea on paper but will never work in the real world.

Oppressive regimes just drop any connection lacking a plain text SNI. The browser will either retry without ECH, or the user will retry with a browser that does not support ECH.

I think people in the Western world don't exactly understand how internet censorship works. They don't give a shit about blocking large legitimate sites or breaking connectivity for large swaths of users if it helps them avoid losing power.

Re: Snowflake

#56
post #21
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

> The technique is heavily used by bad actors Evidence?

https://attack.mitre.org/techniques/T1090/004/

Re: Snowflake

#58
post #55

Earlier quoted context omitted.

When I last looked, the intent was that eventually ECH endpoints offer the same effective service that you got with Domain Fronting, but without messing with the backend in a way which is disruptive for the cloud providers so they support it. Encrypted Client Hello is the in-progress work to have even the client's initial contact to an HTTPS server be encrypted. https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ W…

ECH is a good idea on paper but will never work in the real world. Oppressive regimes just drop any connection lacking a plain text SNI. The browser will either retry without ECH, or the user will retry with a browser that does not support ECH. I think people in the Western world don't exactly understand how internet censorship works. They don't give a shit about blocking large legitimate sites or breaking connectivi…

> ECH is a good idea on paper but will never work in the real world.

Uhuh.

> Oppressive regimes just drop any connection lacking a plain text SNI.

All of the connections will have a plain text SNI. Many of them will have ECH. In some of them, at least at first the ECH will just be GREASE, in others it's real. For the server it's apparent which is which, for a snoop it's impossible to know. Indeed that's sort of the point of GREASE.

> They don't give a shit about blocking large legitimate sites or breaking connectivity for large swaths of users if it helps them avoid losing power.

We heard basically the same thing for TLS 1.3. But of course we actually rolled out TLS 1.3 with no major problems, even the anti-downgrade provision which was the part I was most sceptical about delivering. Google's Chrome GREASEs a bunch of TLS 1.3 already.

Re: Snowflake

#59
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

> when they tried to roll it out on a wide basis for fear that countries like Iran and China would just block all of AWS

That is the whole point: make it so they have to block vast swatches of the useful internet in order to defeat it. Ideally, we should be able to make it so they have to block the entire internet to censor anything.

There must be some kind of limit to the amount of tyranny they're able to muster, right? Eventually the collateral damage will be too great and they'll give up on trying to censor anything. Alternatively, they will become such tyrannical societies that people won't accept it.

Re: Snowflake

#60

Earlier quoted context omitted.

It not an exit. But by default someone has to knowingly run the Snowflake applet but webmasters could modify the code to automatically essentially start a Tor guard in someones browser. Though, that would be very evil to abuse someones resources like that. That example has the users consent before starting.

That's already how many shady VPN software work. Remember if a VPN is "free", you are the product. Web scraping companies pay $$$$ for residential and mobile IPs.

Yeah, those proprietary VPN apps.

"If you don't control the routing, you're being routed."

To be fair, ProtonVPN allows you to export their config. It seems to be an exception to your rule.

Post reply on HN