Live data from Hacker News

Tor Browser 8.5

blog.torproject.org

81–90 of 99 posts

Re: Tor Browser 8.5

#81
post #36

Are there any casual users of Tor around? Someone who does it not for the sake of safety, but just privacy? I'd happily use Tor, but the last time I used it (which was ~5 years ago), it was terribly slow for regular browsing (not streaming, or anything considered bandwidth heavy).

Sure. I'm even a casual host of TOR hidden services. Every time I make a clear text website I'll also host a tor hidden service for it. Things like amateur radio sites. In a lot of ways once you get passed the controversy tor is more like the 1990s web than any evil underground. And at least on TOR you own your domain rather than lease it from some entity on a whim.

Re: Tor Browser 8.5

#82

I wish people used the deep web for something besides illegal buying and child pornography

I host all kinds of completely normal websites (ie, amateur radio) as tor hidden services. TOR is great because you actually own your domain instead of just leasing it on the whim of some corporation.

Once you get past the controversy TOR hidden services are more like the 1990s web than what you describe.

Re: Tor Browser 8.5

#83
post #60

Tor Browser might be the least mainstream safe browser on the Internet: * It permanently tracks the lagging ESR Firefox. * It puts its users on Tor, which "anonymizes" them but also flags their traffic as interesting. * It collapses all those users down to a single set of browser releases, making it cost-effective to target exploits to. Use Firefox if you really like Firefox, but use the most recent version you can p…

> But use it explicitly, not as part of a browser bundle. I hope you're conflating two issues here. You surely aren't recommending users who "believe in Tor" install Tor directly and attempt to manually proxy their favorite browser traffic over it? Not to say I disagree with your points against using TBB.

I do this, using an up-to-date chromium browser proxied through Tor for regular browsing. I do this instead of the regular Tor browser on the theory that there's less potential for 0-day exploits.

Of course, this does compromise anonymity a bit in some respects, since there are probably few people who run chromium on Tor and because it's not as resistant to fingerprinting as the regular Tor browser. That's acceptable to me, as I only use that browser on Tor, and use another browser for things that could potentially leak my real identity.

Re: Tor Browser 8.5

#84
post #60

Tor Browser might be the least mainstream safe browser on the Internet: * It permanently tracks the lagging ESR Firefox. * It puts its users on Tor, which "anonymizes" them but also flags their traffic as interesting. * It collapses all those users down to a single set of browser releases, making it cost-effective to target exploits to. Use Firefox if you really like Firefox, but use the most recent version you can p…

If you are worried about the security provided by the tor browser then you should be using projects like whonix and tails. Both of them try to block (or redirect it via tor?) all non-tor traffic, which should make it significantly more difficult to mount an attack.

Re: Tor Browser 8.5

#86

Earlier quoted context omitted.

> the most popular onion service on the internet by a large margin is Facebook's How do you know? It shouldn't be possible to collect this sort of data.

Exit nodes can track which sites are hit to a degree. CDNs make this more difficult, but it's not too hard to figure out what percentage of your traffic is Facebook. It also won't work if you're going to the Facebook onion site of course.

[deleted]

Re: Tor Browser 8.5

#87
post #14

Earlier quoted context omitted.

Less than 3% of Tor traffic is to onion services of any kind (which means 97% is to websites already accessible on the public internet), and the most popular onion service on the internet by a large margin is Facebook's (facebookcorewwwi.onion). More than 2 million people use Tor every day -- are they all bad people? Heck, government agents use Tor when traveling abroad. Do bad people do bad things using Tor? Yes. Do…

> the most popular onion service on the internet by a large margin is Facebook's How do you know? It shouldn't be possible to collect this sort of data.

In 2016, Facebook published an article saying that 1 million people use Facebook (over their onion address) every month[1]. Comparing this with the privacy preserving statistics provided by the Tor project (based on extrapolating HSDir hits) leads you to believe that 1 million per month is the overwhelming majority of .onion site users.

Roger Dingledine mentions this in quite a few of his talks, I'm fairly sure it's an accurate statement.

[1]: https://www.facebook.com/notes/facebook-over-tor/1-million-p...

Re: Tor Browser 8.5

#88

Earlier quoted context omitted.

> the most popular onion service on the internet by a large margin is Facebook's How do you know? It shouldn't be possible to collect this sort of data.

Exit nodes can track which sites are hit to a degree. CDNs make this more difficult, but it's not too hard to figure out what percentage of your traffic is Facebook. It also won't work if you're going to the Facebook onion site of course.

Exit nodes aren't used like that for .onion sites, so they cannot track usage of .onion sites.

The way it works is that the client and server pick a "rendezvous node" (the server generates 6 HSDir entries, each with 3 random nodes every day, and the client picks a random HSDir entry and a random one of those node to use). Then, they communicate through the rendezvous node which doesn't know who the client or server are (because both are connected through Tor circuits and neither reveals the .onion URL that was looked up in the HSDir).

The way the statistics work is that some Tor relays opt-in to sharing statistics about how many HSDir lookups happened through them, and then those figures are extrapolated to figure out how many .onion service accesses happen. The relay doesn't know which service is being looked up, and the rendezvous node doesn't know which service is being talked to.

Re: Tor Browser 8.5

#89
post #36

Are there any casual users of Tor around? Someone who does it not for the sake of safety, but just privacy? I'd happily use Tor, but the last time I used it (which was ~5 years ago), it was terribly slow for regular browsing (not streaming, or anything considered bandwidth heavy).

I use it (Tor, not the browser as much) just to bust NAT to my local computer when sharing stuff. It's so easy to create an onion service that links to a local web server.

Is that just sharing stuff with yourself, or sharing with others, because the recipient would also need to be using Tor to access it?

Re: Tor Browser 8.5

#90

Earlier quoted context omitted.

> But use it explicitly, not as part of a browser bundle. I hope you're conflating two issues here. You surely aren't recommending users who "believe in Tor" install Tor directly and attempt to manually proxy their favorite browser traffic over it? Not to say I disagree with your points against using TBB.

I do this, using an up-to-date chromium browser proxied through Tor for regular browsing. I do this instead of the regular Tor browser on the theory that there's less potential for 0-day exploits. Of course, this does compromise anonymity a bit in some respects, since there are probably few people who run chromium on Tor and because it's not as resistant to fingerprinting as the regular Tor browser. That's acceptable…

It also opens you to many subtle mis-configuration bugs that would result in your anonymity being removed completely. Are you sure you're tunneling DNS over Tor? IPv6? Are you sure that Chromium isn't phoning home with your real IP?

Tor Browser (despite its many faults) has lots of patches that are applied in order to stop these sorts of leaks. If it takes the people who develop Tor to continually patch Firefox in order to make it actually anonymous, I would argue you have a worse chance of making it work properly.

Post reply on HN