Live data from Hacker News

Arti – An implementation of Tor in Rust

blog.torproject.org

61–70 of 143 posts

Re: Arti – An implementation of Tor in Rust

#61
post #45

Quoted post unavailable.

Using crypto is a good thing in my eyes, but you seem to be convinced that crypto is all evil and a scam. We've seen in recent years that fiat payment systems are ran by bad actors, that will on a whim revoke access to their systems to any entity they deem "problematic", even if no laws have been broken. Crypto allows entities to freely exchange money without having to worry about passing some arbitrary purity test o…

It simply is. Not just 'ZCash' but the entire space [0].

[0] https://lukeplant.me.uk/blog/posts/the-technological-case-ag...

Re: Arti – An implementation of Tor in Rust

#62

Earlier quoted context omitted.

Bad actors use effective technologies, just like good ones do. So what?

So this means that Tor taking money from Zcash is an explicit endorsement of the crypto token space and the scams and speculation and environmental destruction they harbour. Not to mention the ransomware enablement of a so called privacy token. I don't think Tor would want to be associated with all of that on top of all the other illicit activities they are already associated with.

So when did you stop using Amazon? Or Apple? Or Visa? Because of the gift card scams. Or the usd? Almost all crime is paid for in usd.

Your argument is less than merited because there is no moral contrast with alternatives. Guilt by association is fallacious. That leaves only "because you don't like it" and that's a valid opinion, which you're welcome to, but having privacy enabling technology allows real world freedom. Others of us have the opinion that despite bad people existing, supporting the freedom and anonymity of people, good or bad, is an improvement to the world.

Re: Arti – An implementation of Tor in Rust

#63
post #21

Earlier quoted context omitted.

I despise crypto, but telling an underfunded OSS project to abandon scarce funding for what is a relatively minor ideological reason definitely rubs me the wrong way. Rather than demanding them to change, why not find a way to help secure them a source of less objectionable funding.

I would want them to at least go to the Rust Foundation Grants Program [0] or perhaps the Mozilla Foundation grants program [1]. This isn't minor, Wikimedia [2] is also asking the same thing of their project and they shouldn't use or endorse these crypto tokens, same thing as Tor. [0] https://foundation.rust-lang.org/news/2021-12-09-news-rust-f... [1] https://foundation.mozilla.org/en/what-we-fund/ [2] https://meta.w…

> This isn't minor, Wikimedia [2] is also asking the same thing of their project and they shouldn't use or endorse these crypto tokens, same thing as Tor.

https://meta.wikimedia.org/wiki/Requests_for_comment/Stop_ac... is a proposal with what looks like extremely divided voting; I'm not seeing where it was ratified? So Wikimedia is not asking that, someone suggested that Wikimedia should ask that.

Re: Arti – An implementation of Tor in Rust

#64
post #33

Earlier quoted context omitted.

To many, yes.

Do those same people also use SELinux?

Is that likely? People who don't trust things backed by the US gov't are unlikely to be fond of SELinux, but even beyond that, AppArmor is used in preference to SELinux by the Debian and SUSE families, which probably gives it a greater share of the Desktop Linux market (vs SELinux, mostly used by the Red Hat family) even without ideological/trust issues in play.

Re: Arti – An implementation of Tor in Rust

#65
post #48

So at this point it is ready for passing traffic through a SOCKS proxy. Meaning we can `cargo run --release -- proxy` and redirect applications to use port `9150` for their network connections. Couple of related questions: - Does anyone know, in a Linux distro, how to pass all system traffic through a SOCKS proxy port? I'm not looking for intermediary proxy handlers but an official method to force all user and system…

I don't think you can generally expect all processes to transparently use a SOCKS proxy? You might be able to finagle a custom vpn around it, I suppose. But AFAIK SOCKS isn't 100% transparent at the IP layer allowing all protocols to transparently layer on top? I guess SOCKS5 handles tcp and udp - so you might get away with redsocks (which explicitly recommends against using with TOR): https://github.com/darkk/redsoc…

Does anyone know how TAILS accomplishes this, then? It doesn't rely on a relay like Whonix does, but I'm not a networking expert or a Linux expert, so I'm not altogether sure how it does work.

Re: Arti – An implementation of Tor in Rust

#66

Earlier quoted context omitted.

I mean I urge folks who have the ability to direct some of their company's money towards Tor. It's directly helping both Ukranian and Russian citizens right now.

Sure Tor helps Ukrainian and Russian citizens, but I urge the Tor foundation to question themselves and to stop accepting crypto token donations and grants. It acts as an endorsement and emboldens the cryptobros, enthusiasts and fans to pump the price of the token.

Why should they forgo an opportunity for funding that allows people to donate in countries where direct bank transfers to the Tor project would be logged and marked as suspicious, and which is resistant to payment processors deciding not to process the donations? Because you personally don't like cryptocurrency? That is ridiculously childish.

Re: Arti – An implementation of Tor in Rust

#67
post #35

Earlier quoted context omitted.

Do you ask that in the comments of every project on the off chance?

This question is relevant when 1: one of the most important (perceived) adversarial is the NSA; 2: as of 2012, 80% of The Tor Project's $2 million annual budget came from the United States government; 3: the Underhanded C Contest exists and we can assume that however secure Rust is, writing underhanded Rust code is possible. https://en.wikipedia.org/wiki/The_Tor_Project#Funding https://en.wikipedia.org/wiki/Underhand…

I'm not sure that follows. First, funding != code. And the Underhanded C Contest exists because C kind of sucks; since Rust largely exists specifically to solve the problems with C, I would like rather more compelling evidence that underhanded Rust is possible than pointing at C.

Re: Arti – An implementation of Tor in Rust

#68
post #33

Earlier quoted context omitted.

Do those same people also use SELinux?

Is that likely? People who don't trust things backed by the US gov't are unlikely to be fond of SELinux, but even beyond that, AppArmor is used in preference to SELinux by the Debian and SUSE families, which probably gives it a greater share of the Desktop Linux market (vs SELinux, mostly used by the Red Hat family) even without ideological/trust issues in play.

SELinux is turned on across all Android and ChromeOS devices.

Re: Arti – An implementation of Tor in Rust

#69
post #36

Earlier quoted context omitted.

You also might have heard about this saying which goes by: 'The road to hell is paved with good intentions' and it goes both ways. At least I happen to recognize that, unlike the grandparent comment. But where did I exactly say 'ban' it?

So you're saying a tor rewrite in rust is the road to hell then? Or that tor itself is the road to hell? Either way, your same argument can be made against the whole internet which should demonstrate how silly it is.

> Either way, your same argument can be made against the whole internet which should demonstrate how silly it is.

Not really.

I recognize that the same criminals can also use the wider internet too, however there are central authorities and regulators in different countries that have laws that regulate the internet in the countries that they are in and these criminals will be caught very quickly if they tried.

The difference is that Tor only makes it more harder to trace, hence the appeal to criminals, extremists and terrorists to use it for their illegal activities which that is its unintended use case after promising 'privacy' and 'anonymity' for 'everyone'.

So yes, that is it's 'decentralised' road to hell indeed.

Re: Arti – An implementation of Tor in Rust

#70
post #68

Earlier quoted context omitted.

Is that likely? People who don't trust things backed by the US gov't are unlikely to be fond of SELinux, but even beyond that, AppArmor is used in preference to SELinux by the Debian and SUSE families, which probably gives it a greater share of the Desktop Linux market (vs SELinux, mostly used by the Red Hat family) even without ideological/trust issues in play.

SELinux is turned on across all Android and ChromeOS devices.

I'm skeptical that there's much overlap between "people who seriously use TOR" and "people who use ChromeOS", but yeah Android is a fair point. (And I'll certainly grant that there are probably more Android devices out there than laptops/desktops running Debian derivatives.)
Post reply on HN