Live data from Hacker News

Zed Shaw: Why I Don't Use Tor

sheddingbikes.com

91–100 of 170 posts

Re: Zed Shaw: Why I Don't Use Tor

#91
post #10

It's somewhat informative to compare Zed's response to personal criticisms vs those he targets with his own criticisms. Follow the chain of twitter replies and make up your own mind.

So much name calling and playground idiocy. Just looking at a sample of the tweets made my head hurt. Surely most of us don't use Tor because 1. It's slow as hell 2. We're not doing anything illegal or trying to get past censorship

Strongly disagree with (2). I use Tor because anonymous communication is essential in a democratic society. This has been known since the Federalist Papers were published anonymously in 1787-1788 [1] and has been constantly reaffirmed by our courts since then. The most oft citied case is McIntyre v. Ohio Elections Comm'n. As Justice Thomas wrote in his concurrence: the Framers shared the belief that [anonymous publishing] was firmly part of the freedom of the press. It is only an innovation of modern times that has permitted the regulation of anonymous speech. [2]

[1] http://en.wikipedia.org/wiki/Federalist_Papers

[2] http://www.law.cornell.edu/supct/html/93-986.ZC1.html

Re: Zed Shaw: Why I Don't Use Tor

#92
post #8

Wikileaks is supposed to ensure anonymity to leakers, so I don't see how contributing to both projects is contradictory...

The softly stated allegation is that Wikileaks can use their knowledge of Tor weaknesses to SNOOP and extract traffic not directed at them. At least, that's what I understood.

Re: Zed Shaw: Why I Don't Use Tor

#93
post #90

As someone living on the other side of the Great Firewall of China it's become VERY clear that a government can effectively censor the internet(without VPN to get out it's terrible), provided that the government in question put enough effort into it. As I said in another comment, the Chinese government has beaten Tor. You can't download it or even read about it(almost everything Tor related is blocked). Even when you…

This is why more people need to learn about and use steganography: http://en.wikipedia.org/wiki/Steganography Properly used, good steganographic software will hide your use of encryption. Ideally, your communication stream will seem perfectly innocuous to all observers. Of course, in real life nothing is perfect. So there's always a chance your use of encryption will be detected. But using steganography properly shou…

Stealth circumvention tools are even harder to write than just plain old circumvention tools, which we already are struggling with. It's a disaster waiting to happen. See Haystack and this comment by Thomas: http://news.ycombinator.com/item?id=1690871.

Re: Zed Shaw: Why I Don't Use Tor

#94
post #70

Earlier quoted context omitted.

Using Tor does not mean that you are an exit node. You have to actually set that up and it is warning you about it. Using Tor as a client only is safe and secure. If people do bad things through your exit node, you are in danger regardless where you live. The law enforcement must be aware of what your server was doing. Its understanding varies from place to place.

OK, then I guess I made that decision to chicken out about running an exit node. It seems a bit parasitic to not run one and still participate, though?

The Tor nodes are not anonymous, so nobody expects users of a Tor node to run their own...they're trying to be anonymous.

Re: Zed Shaw: Why I Don't Use Tor

#95
post #27
post #14

Earlier quoted context omitted.

> there were several security alerts related to SELinux. Can you elaborate?

There were several security advisories in the past years, of various privilege escalation or other security holes that were actually in SELinux and not present in the vanilla source. I didn't keep a log of the details but you probably can find them in the advisories archives.

Holes SELinux created? Or holes where SELinux was circumvented in new or changed functionality?

I'm not aware of any time SELinux has actually introduced a new hole.

Re: Zed Shaw: Why I Don't Use Tor

#96
I, for one, would like to point out to Mr. Shaw (and others) that the Swastika is a religious symbol to a lot of people ; maybe even 20% of all humanity (the Hindus, for one).

Just because the Swastika was co-opted by Hitler and his cronies means nothing to most people outside the western world (which is in a minority).

Secondly (while I have this soapbox): whether you take the sandwich from Hitler or not depends on whether Hitler is your "Der Fuhrer" or not (remember, he's long dead, so time travel is involved in Mr. Shaw's hypotheticals). If Hitler is your Fuhrer, then you _better_ take that sammich and eat it if he offers it to you! :-D

Re: Zed Shaw: Why I Don't Use Tor

#97
post #73

Earlier quoted context omitted.

Suppose the FreedomBox catches on, and there's a Tor node on half of them. That could represents millions of Tor exit nodes within 5 years. That should turn the tide, don't you think?

If we're playing the suppose game, what if the chinese government collapses? That'd turn the tide too, and there's probably a better chance of that happening then there ever being millions of tor exits.

I'm playing the guessing game because I believe the FreedomBox will happen (more than 0.9 probability within 5 years). We have the hardware and most of the software. The final set-up should take a year or so, then we just have to sell that. And selling will be easy. Who wouldn't want a bit of personal cloud at home? We don't even need to overthrow Microsoft, or eradicate Windows. No coercion is required, except with some ISPs.

The Chinese government collapsing within 5 years? That takes a revolution. I assign less than 0.1 probability to that.

Re: Zed Shaw: Why I Don't Use Tor

#98
post #44

It's shit like this Zed... Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox . God damn Zed, this Hitler sandwich shit is pretty weak. Zed also has a problem with Tor because he thinks ther…

The tptacek comments you're probably referring to: http://news.ycombinator.com/item?id=1690871 http://news.ycombinator.com/item?id=1184236

Re: Zed Shaw: Why I Don't Use Tor

#99
post #93
post #90

Earlier quoted context omitted.

This is why more people need to learn about and use steganography: http://en.wikipedia.org/wiki/Steganography Properly used, good steganographic software will hide your use of encryption. Ideally, your communication stream will seem perfectly innocuous to all observers. Of course, in real life nothing is perfect. So there's always a chance your use of encryption will be detected. But using steganography properly shou…

Stealth circumvention tools are even harder to write than just plain old circumvention tools, which we already are struggling with. It's a disaster waiting to happen. See Haystack and this comment by Thomas: http://news.ycombinator.com/item?id=1690871 .

From Thomas' post:

"Get circumvention at all wrong and you achieve the opposite of what the tool is intended for: you put a big red flag on people breaking their local laws. ... Don't build circumvention tools."

That attitude is so wrongheaded I hardly know where to begin.

First of all, anyone who uses something like TOR in China has already put a huge (and very very obvious) red flag on their communications stream.

So, if those people are going to be trying to break through the firewall anyway, why should't they do so with the best tools available? Why shouldn't they try to hide their communication in a stream of innocuous traffic rather than obviously red-flagging it?

And why shouldn't concerned programmers write tools to make the hiding of such information more effective?

Look, many people are going to try to communicate even when they're forbidden from doing so, and they're going to try to circumvent censorship. So we can either try to make it easier for them, or harder. I'm on the side of making it easier.

Sure, some people are going to get caught despite using steganographic software. But I'm willing to bet a lot fewer of them will get caught than using bare encryption systems like TOR.

Re: Zed Shaw: Why I Don't Use Tor

#100
post #44

It's shit like this Zed... Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox . God damn Zed, this Hitler sandwich shit is pretty weak. Zed also has a problem with Tor because he thinks ther…

Thing is, you don't have to believe Firefox is trustworthy to believe it's your best bet for surfing the web. The whole point of Tor is to be trustworthy; hence, there's no point in it if you don't trust it. Plus, like you said, using Tor may be worse than nothing, so you have to have a pretty strong motivation and pretty strong trust. Using Firefox or OSX requires no such trust.
Post reply on HN