Live data from Hacker News

Tor Browser 8.5

blog.torproject.org

91–99 of 99 posts

Re: Tor Browser 8.5

#91
post #23
post #12

Earlier quoted context omitted.

When I went to China I expected problems so I setup my laptop with an SSL tunnel on port 443 to a virtual server and then routed openvpn over that. It worked like a charm. My favorite feature of openvpn is it can maintain state, so even if the tunnel resets and openvpn has to reconnect all the tcp connections just pick up where they left off.

What is the difference between this and just having a normal SSH tunnel; for example, how does this differ from using sshuttle?

Openvpn allows you to connect to and have a routable IP on the network. SSH tunnels are great for some things but being logically on a network is another thing.

Re: Tor Browser 8.5

#92
post #60

Tor Browser might be the least mainstream safe browser on the Internet: * It permanently tracks the lagging ESR Firefox. * It puts its users on Tor, which "anonymizes" them but also flags their traffic as interesting. * It collapses all those users down to a single set of browser releases, making it cost-effective to target exploits to. Use Firefox if you really like Firefox, but use the most recent version you can p…

If you are worried about the security provided by the tor browser then you should be using projects like whonix and tails. Both of them try to block (or redirect it via tor?) all non-tor traffic, which should make it significantly more difficult to mount an attack.

I've been googling a bit and come up with Whonix, Tails and Qubes.

Can anyone advise their opinion on which one would be best to run in a VM? I'm prepared to accept the security compromise of running in a VM, but I do want the ability to store passwords in the browser and save small files in the VM.

Edit: Just signed up for this account over Tor for shits and giggles. Literally my first post and it's dead immediately.

I get that Tor has spammers but I did have to do the captcha to create an account so this seems heavy handed. Seems like there's no way to legitimately post to hn over Tor.

Re: Tor Browser 8.5

#93
post #88

Earlier quoted context omitted.

Exit nodes can track which sites are hit to a degree. CDNs make this more difficult, but it's not too hard to figure out what percentage of your traffic is Facebook. It also won't work if you're going to the Facebook onion site of course.

Exit nodes aren't used like that for .onion sites, so they cannot track usage of .onion sites. The way it works is that the client and server pick a "rendezvous node" (the server generates 6 HSDir entries, each with 3 random nodes every day, and the client picks a random HSDir entry and a random one of those node to use). Then, they communicate through the rendezvous node which doesn't know who the client or server a…

(Correction, 3 introduction points and the client picks the rendezvous point -- so even a compromised introduction point is useless because the node used for communication is different for all communications.)

Re: Tor Browser 8.5

#94

Earlier quoted context omitted.

If you are worried about the security provided by the tor browser then you should be using projects like whonix and tails. Both of them try to block (or redirect it via tor?) all non-tor traffic, which should make it significantly more difficult to mount an attack.

I've been googling a bit and come up with Whonix, Tails and Qubes. Can anyone advise their opinion on which one would be best to run in a VM? I'm prepared to accept the security compromise of running in a VM, but I do want the ability to store passwords in the browser and save small files in the VM. Edit: Just signed up for this account over Tor for shits and giggles. Literally my first post and it's dead immediately…

Some of those posts get autokilled by software, but moderators review them and unkill the legitimate ones. This is how I came across and unkilled yours.

Re: Tor Browser 8.5

#95

Earlier quoted context omitted.

If you are worried about the security provided by the tor browser then you should be using projects like whonix and tails. Both of them try to block (or redirect it via tor?) all non-tor traffic, which should make it significantly more difficult to mount an attack.

I've been googling a bit and come up with Whonix, Tails and Qubes. Can anyone advise their opinion on which one would be best to run in a VM? I'm prepared to accept the security compromise of running in a VM, but I do want the ability to store passwords in the browser and save small files in the VM. Edit: Just signed up for this account over Tor for shits and giggles. Literally my first post and it's dead immediately…

Qubes is a Xen-based virtualization thing, it has nothing to do with tor by itself, you can think of it as a replacement to qemu or virtualbox (but not exactly). Qubes has official support for both Whonix and Tails.

It looks like whonix is what you are looking for, from wikipedia:

> Unlike Tails, Whonix is not "amnesic"; both the Gateway and the Workstation retain their past state across reboots

Re: Tor Browser 8.5

#96
post #90

Earlier quoted context omitted.

I do this, using an up-to-date chromium browser proxied through Tor for regular browsing. I do this instead of the regular Tor browser on the theory that there's less potential for 0-day exploits. Of course, this does compromise anonymity a bit in some respects, since there are probably few people who run chromium on Tor and because it's not as resistant to fingerprinting as the regular Tor browser. That's acceptable…

It also opens you to many subtle mis-configuration bugs that would result in your anonymity being removed completely. Are you sure you're tunneling DNS over Tor? IPv6? Are you sure that Chromium isn't phoning home with your real IP? Tor Browser (despite its many faults) has lots of patches that are applied in order to stop these sorts of leaks. If it takes the people who develop Tor to continually patch Firefox in or…

> Are you sure that Chromium isn't phoning home with your real IP?

Especially given that Chromium does make startup queries to Google-owned servers. (Not sure about runtime.) Probably for perfectly reasonable usability and/or security reasons.

But I agree that Chromium manually proxied through Tor probably looks vastly superior to TBB when you do a benefit analysis. :)

Edit: added smiley to make what I'm saying slightly more obvious.

Re: Tor Browser 8.5

#97
post #94

Earlier quoted context omitted.

I've been googling a bit and come up with Whonix, Tails and Qubes. Can anyone advise their opinion on which one would be best to run in a VM? I'm prepared to accept the security compromise of running in a VM, but I do want the ability to store passwords in the browser and save small files in the VM. Edit: Just signed up for this account over Tor for shits and giggles. Literally my first post and it's dead immediately…

Some of those posts get autokilled by software, but moderators review them and unkill the legitimate ones. This is how I came across and unkilled yours.

Thanks a lot, dang. I was hoping a mod would see my edit.

Re: Tor Browser 8.5

#98

Earlier quoted context omitted.

I've been googling a bit and come up with Whonix, Tails and Qubes. Can anyone advise their opinion on which one would be best to run in a VM? I'm prepared to accept the security compromise of running in a VM, but I do want the ability to store passwords in the browser and save small files in the VM. Edit: Just signed up for this account over Tor for shits and giggles. Literally my first post and it's dead immediately…

Qubes is a Xen-based virtualization thing, it has nothing to do with tor by itself, you can think of it as a replacement to qemu or virtualbox (but not exactly). Qubes has official support for both Whonix and Tails. It looks like whonix is what you are looking for, from wikipedia: > Unlike Tails, Whonix is not "amnesic"; both the Gateway and the Workstation retain their past state across reboots

Cool, thanks for the info. I think I'll try out virtualbox with Whonix.

Re: Tor Browser 8.5

#99
post #58
post #36

Are there any casual users of Tor around? Someone who does it not for the sake of safety, but just privacy? I'd happily use Tor, but the last time I used it (which was ~5 years ago), it was terribly slow for regular browsing (not streaming, or anything considered bandwidth heavy).

As a sysadmin I use tor regularly as a easy and free third-party perspective. If there is a problem but it works when I test it, I then go and test in tor in order to eliminate any potential effect in my local network. Tor is also ipv4 so it is a convenient way to get a ipv4 web view inside a ipv6 enabled network, without having to deal with browser plugins or adjust the interface on the machine.

Tor has had ipv6 exit nodes for at least 2 years.
Post reply on HN