Tor and HTTPS
91–100 of 135 posts
Re: Tor and HTTPS
#92Earlier quoted context omitted.
No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.
Ignoring for a moment the validity of this statement, can I ask why you visit a site that is primarily about business news/Silicon Valley Hacker errata if you're not a fan of the 'bourgeois'?
Re: Tor and HTTPS
#93Where does running traffic via a VPN [0] come into this? Does that count as HTTPS, or are they referring to 'SITE.COM' having an HTTPS certificate? Is it possible to use Tor and a VPN together? [0] e.g. I use https://ipredator.se
If you use Tor to connect to your VPN-provider, you can hide your location from your VPN-provider.
Since your VPN-provider may have payment information from your creditcard it makes no sense to use a VPN and Tor together, its just a cascade.
Re: Tor and HTTPS
#94What would be the highest level of anonymity one could achieve on the modern internet? How could you accomplish it?
Addendum for achievement: Connect to Tor from a public accessible network/wifi that is free from surveillance using a pristine installation and never use that network-device again.
Addendum 2: If you use the network device twice, you may achieve only pseudonymity.
Re: Tor and HTTPS
#95What would be the highest level of anonymity one could achieve on the modern internet? How could you accomplish it?
But then again the internet cafe could be watching you.. So maybe only on a hacked WiFi?
Re: Tor and HTTPS
#96Earlier quoted context omitted.
No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.
Ignoring for a moment the validity of this statement, can I ask why you visit a site that is primarily about business news/Silicon Valley Hacker errata if you're not a fan of the 'bourgeois'?
Re: Tor and HTTPS
#97Why does the graphic portray police as mean angry people. Police are good people who provide a valuable service. They do a good thing. They are not the enemy.
No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.
Re: Tor and HTTPS
#98SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brainer.
For Tor, a bunch of attacks are possible by owning only a small percentage of all nodes. Recently, Tor was issuing a "call for relays" due to a dwindling number of participants that was endangering the network. Considering that Tor came out of Navy research, if you don't think they have a statistically interesting number of nodes, you're crazy. If they don't, it's only because they don't think that Tor is an interesting source right now.
TL;DR: Security depends on your threat model, and while I think that Tor and HTTPS provide strong protection from run-of-the-mill attackers, I don't think that either provides meaningful security if you're worried about the NSA.
Re: Tor and HTTPS
#99I have problems even logging in on ycombinator with tor. Not to mention any site with anti-spam protection.
It makes imho no sense to authenticate using Tor.
Re: Tor and HTTPS
#100I think this is misleading. I now believe that the NSA has the private keys for substantially all SSL certs in use, and I expect that a non-trivial percentage of Tor nodes are run by the government. SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brai…
I concur with your statement that SSL isn't really secure end-to-end communication when 3rd party certificates are involved.