Live data from Hacker News

Tor and HTTPS

eff.org

91–100 of 135 posts

Re: Tor and HTTPS

#92
post #76

Earlier quoted context omitted.

No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.

Ignoring for a moment the validity of this statement, can I ask why you visit a site that is primarily about business news/Silicon Valley Hacker errata if you're not a fan of the 'bourgeois'?

Maybe he sees dampening the echo chamber as a sort of community service.

Re: Tor and HTTPS

#93

Where does running traffic via a VPN [0] come into this? Does that count as HTTPS, or are they referring to 'SITE.COM' having an HTTPS certificate? Is it possible to use Tor and a VPN together? [0] e.g. I use https://ipredator.se

If you use a VPN to connect to Tor, you can hide the fact (from your local isp) that you use tor.

If you use Tor to connect to your VPN-provider, you can hide your location from your VPN-provider.

Since your VPN-provider may have payment information from your creditcard it makes no sense to use a VPN and Tor together, its just a cascade.

Re: Tor and HTTPS

#94

What would be the highest level of anonymity one could achieve on the modern internet? How could you accomplish it?

There is no level on anonymity, either you are, or you are not.

Addendum for achievement: Connect to Tor from a public accessible network/wifi that is free from surveillance using a pristine installation and never use that network-device again.

Addendum 2: If you use the network device twice, you may achieve only pseudonymity.

Re: Tor and HTTPS

#95

What would be the highest level of anonymity one could achieve on the modern internet? How could you accomplish it?

Hoodie/Gloves/Sunglasses + Cash + Internet Cafe (or hacked WiFi not near you) + TOR or I2P + HTTPS

But then again the internet cafe could be watching you.. So maybe only on a hacked WiFi?

Re: Tor and HTTPS

#96
post #76

Earlier quoted context omitted.

No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.

Ignoring for a moment the validity of this statement, can I ask why you visit a site that is primarily about business news/Silicon Valley Hacker errata if you're not a fan of the 'bourgeois'?

Hacker News features many programming and technology related articles as well.

Re: Tor and HTTPS

#97
post #76

Why does the graphic portray police as mean angry people. Police are good people who provide a valuable service. They do a good thing. They are not the enemy.

No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.

I usually don't see blatant communist / class warfare trolling, at least on HN.

Re: Tor and HTTPS

#98
I think this is misleading. I now believe that the NSA has the private keys for substantially all SSL certs in use, and I expect that a non-trivial percentage of Tor nodes are run by the government.

SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brainer.

For Tor, a bunch of attacks are possible by owning only a small percentage of all nodes. Recently, Tor was issuing a "call for relays" due to a dwindling number of participants that was endangering the network. Considering that Tor came out of Navy research, if you don't think they have a statistically interesting number of nodes, you're crazy. If they don't, it's only because they don't think that Tor is an interesting source right now.

TL;DR: Security depends on your threat model, and while I think that Tor and HTTPS provide strong protection from run-of-the-mill attackers, I don't think that either provides meaningful security if you're worried about the NSA.

Re: Tor and HTTPS

#99
post #70

I have problems even logging in on ycombinator with tor. Not to mention any site with anti-spam protection.

Since nearly every Tor-exit has working reverse-lookup or by using https://check.torproject.org/ it is easy to deny access to Tor-users while authenticating.

It makes imho no sense to authenticate using Tor.

Re: Tor and HTTPS

#100
post #98

I think this is misleading. I now believe that the NSA has the private keys for substantially all SSL certs in use, and I expect that a non-trivial percentage of Tor nodes are run by the government. SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brai…

Tor does not provide security, it can provide obfuscation that may lead to anonymity or pseudonymity, not more.

I concur with your statement that SSL isn't really secure end-to-end communication when 3rd party certificates are involved.

Post reply on HN