How to access the Darknet. The safe way
torgeek.pw
torgeek.pw
Therein lies the problem. You can't trust VPN providers.
In that way he has to find a way to get the VPN provider to give out my real address. What might be possible with a lot, but for sure not with all of them.
Also think countries, my country does barely have any contracts with other countries for crimes like this. So they would have to use a complicated way to actually force them to give out my data.
In most situations we are already way over the realistic damage done in forms of costs to catch the individual.
Why the 'probably'? Of course, no VPN-provider should be trusted at face value, but do you know of any sources that claim that Private Internet Access is in fact an elaborate honeypot?
Looking at the argument though, even if it is a honeypot blowing it is a one-shot deal. The users are never going to trust PIA nor any other VPN that makes similar claims ever again. That means that they probably wouldn't spring the honeypot, if it is one, for anything but the biggest fish.
Frankly, I think you're all splitting hairs. Most of us understood the point he was making even if the phrasing of that sentence didn't flow as well as you may have liked.
One shot? Backdoor and reconstruct in parallel.
I guess that sums up exactly how trustworthy they are.
If they are willing to do that, even TOR isn't real protection due to the fact it can and will be breached in the event of an active attack by malicious nodes on both ends of the circuit.
A VPN you can buy relatively anonymously [e.g. disposable gift cards bought with cash] and use with common sense [e.g. Not via your home LAN] are an effective privacy tool.
However, 99% of people aren't going to go through that level of effort which makes them nearly useless for privacy purposes.
A MitM at the local wifi shop is going to know you are and what you are doing.
A MitM at a VPN you paid for with a gift card you paid with cash is just going to know which wifi shop you were at. If you never go back, odds are they can't figure out which customer you were.
As far as you know. And that's exactly where the problem lies. You are trusting your adversaries to be honest about who they cooperate with, which is a great way to get screwed over, because your adversaries are adversaries.
So no, it still wouldn't necessarily be "better than not using one". The tradeoff is far more complex than that.
(I was able to find some information leaks in their forums, which I reported responsibly, but a malicious actor could have used to exploit an outdated module.)
Despite my less-than-chilly feelings about the service operator, I certainly wouldn't recommend anyone else trust them. An SSH tunnel over Tor (or even better, something like PORTAL) to protect against malicious exit nodes, where the endpoint is a VPS you rent with bitcoin not connected to your real identity, is preferable.
Best case scenario: They're an illegal operation who's defying local laws.
Worse case scenario: We're being lied too.
Their twitter feed is also a goldmine.
Your link is borderline nonsense.
The only real evidence they give about not using VPN's is when hidemyass proxy gave up some Anon's in 2011. However, it very clearly states in the hidemyass TOS that their service is not to be used in illegal activity, which is exactly what the hackers who they gave up were doing. They only gave up the information after receiving a court order, even though they had seen the hackers in chats saying they used their service, at which point they did nothing until the government stepped in.
http://www.theregister.co.uk/2011/09/26/hidemyass_lulzsec_co...
Yeah, and you have no evidence that I don't have a nice bridge to sell you, so will you buy it?
Trusting by default and requiring evidence to distrust is a poor way to protect your privacy. VPNs - unlike Tor, for example - have no protection against logging by the operators, so why would one trust them? Because they pinky swear they won't log?
Which is pretty much the default for anything you use on your computer.
- You ever install a software program?
- You ever click on a link in your email?
- You ever go to a site that contains malware that installs itself covertly on your PC?
- You ever open a JPG file?
- Use a cloud service?
- Save your pictures to Flickr?
- Ever use social media of any kind?
- Use any Google product or service?
- Use any Microsoft product or service.
The world is FILLED with UNVERIFIABLE information, the fact that people seem to put so much mistrust in a VPN provider when there's thousands of other ways and means to get to your data is well. . .absurd. Talking like you suddenly need some high level of verification that a VPN doesn't log your information when there's literally thousands of other ways to get at that information is completely myopic.
Just like your example with TOR, which recently has been shown to be not only insecure, but readily hackable, yet you seem to trust that far more blindly.
https://theintercept.com/2015/07/16/hackingteam-attacked-tor...
https://pando.com/2014/12/26/if-you-still-trust-tor-to-keep-...
http://siliconangle.com/blog/2013/09/09/not-even-tor-is-safe...
If you're concerned about having "verifiable information" to protect you, you're living in a dreamland.
As for Google and Microsoft, I don't trust them. I give them my info with the expectation that it'll be shared with governments and other companies. I use their services despite that.
VPNs, on the other hand, are built in order to protect your privacy, so the same reasoning can't be applied.
As Tor, and beyond the fact that you didn't even bother to understand the links you posted (the first it's not even about any flaw in Tor), sure, it can be hacked if one manages to control 3000 nodes or have NSA-like capabilities in breaking crypto keys ($1 billion dollar custom-made chips, from your link!).
But a VPN doesn't even need to be hacked - though they can, and probably with less difficulty than Tor - all the operators need to do is set "log = True" in their configuration files. There is not even a semblance of a protection. It's just pinky swearing.
1. Not even about Tor, rather about Tor Browser, which is a modified Firefox and is optional to use (and 100% unrelated to Tor as a protocol or daemon). Complaints about this can be directed to Mozilla.
2. Pando loves to fear-monger about Tor and draw 'conclusions' without actually supporting them. Notice how they represent a blog post stating "incapacitated" (ie. affecting availability) as "exposed" (ie. affecting confidentiality)? Notice how Pando nowhere actually describes how a lot of 'fake' nodes could supposedly compromise users?
That's because they are not making a technical argument, and they don't understand the internals of Tor. They are just publishing a hit piece that sounds vaguely to the untrained ear like it might have some technical merit, without ever actually proving the assertion they're making. And their implied argument is wrong.
3. Ah, an actual issue with Tor. But look at the operative phrase: "The problem boils down to this – around 90% of Tor users are still using older software which can be hacked." It's an issue that has long been resolved, and was an implementation error rather than a fundamental issue with Tor.
--
You're really not the first to try and claim that Tor is "broken" by pointing at a bunch of articles like this. The reality is that none of it actually means that Tor is broken, and the one attack on Tor that does exist (and that is very expensive to pull off) isn't even clearly described in any of these articles.
If you're going to argue about the technical merit and security of different proxying techniques (because that's what they all effectively are), then at least inform yourself to a point where you actually understand how they work internally. Right now, you just look ignorant.
I think icebrained nicely covered the other few points, aside from "installing a software program" and "cloud services" - in which case, I'd recommend you look into package/executable signing, how it provides some guarantee of consistency, and how you can use it to avoid dodgy software builds. This kind of thing is also exactly why many people avoid proprietary software and 'cloud services', by the way.
My take is that it is valuable to use Tor to (try at least) to escape companies tracking and government spying.
But to visit any website only available on Tor network is not worth any effort on my part, as I have no doubt (currently) that it is all about illegal porn or illegal drugs and sinister scams.
Anyone care to give some counter argument to why this Tor Network deserves a positive light?
You have come to your conclusion based upon nothing more than feeling, because if you had done any searching at all you would understand the answer to your question.
Everyone has heard the metaphor about leading a horse to water. In this case, it's more like the horse refuses to even be lead to the water but wants someone to go get a bucket of water and bring it to them. No one should or is gonna do it for you, especially since you have demonstrated a clearly exemplary amount of laziness in both effort and thought...
tldr
Tor sites != illegality
tor != darknet/deep web (eg, the darknet/deep web is much broader than just tor...)
That contradicts the comment I replied to, that is why I framed my question that way. I assumed I should consider Tor Network and Darknet one and only (as it is the top voted comment on HN, it gave me the credibility credentials to trust it with no second thought).
Advocates for Tor say it supports freedom of expression, including in countries where the Internet is censored, by protecting the privacy and anonymity of users. The mathematical underpinnings of Tor lead it to be characterized as acting "like a piece of infrastructure, and governments naturally fall into paying for infrastructure they want to use".[139]
The project was originally developed on behalf of the U.S. intelligence community and continues to receive U.S. government funding, and has been criticized as "more resembl[ing] a spook project than a tool designed by a culture that values accountability or transparency".[20] As of 2012, 80% of The Tor Project's $2M annual budget came from the United States government, with the U.S. State Department, the Broadcasting Board of Governors, and the National Science Foundation as major contributors,[140] "to aid democracy advocates in authoritarian states".
But what confused me is that the top voted comment says that "There is no such thing as the Darknet. Please stop referring to the TOR network this way". This phrasing says two things to me, Darknet does not exist, all that exists is Tor network.
So I implied that visiting sites only visible through Tor was visiting sites of the so-called Darknet. And I assumed that what I called Darknet, actually is the Tor network, than all my prejudice against the Darknet should be aimed at Tor network, thus my question.
Now it looks the top voted comment is actually misleading. There IS Darknet, only it is not the same at Tor.
I tried to target my keywords to people who miss that understanding. People coming directly from YouTube having no idea what it is all about. Those search for the darkweb.
Anyway. Kudos on pointing this out.
You would want to both obtain and use Tor nowhere near your meatspace identity, pref with different hardware than you usually use, and leave your phone at home if protection from tracking is your highest priority.
Most countries can barely force any other country to give out consumer data from local companies. If you do not live in a five eyes state we can safely assume that nobody will target you that way for Tor browsing.
Then I believe we agree on this. I think many people would do well to include some overkill, in cases like this, to adjust for the risk of underestimating the difficulty 'killing' the problem.
To be fair, Qubes is arguably not really ready to be put into the hands of a casual computer user without specific threats yet. But for those who can handle it it seems like the most accessible option I've heard of for keeping the underlying system safe and preventing unmasking.
(1) Use a secure OS. Unless you are security guru, that should be some flavour of linux. A liveUSB of Tails is pretty idiot proof. It worked for Snowden.
(2) Don't run any web browser, tor or otherwise, under any sort of elevated privilege (ie not while admin).
(3) Understand how to verify a website's certificates. You can indeed log into social media safely via tor (ie your password won't be harvested by the exit node) if you know how to verify the website.
(4) Don't take anonymity casually. Understand why you are using Tor, what you are protecting, who your adversary is, and develop relevant procedures. Don't rely on easy checklists you find at Tor-for-Dummies.com.
That implies Tails is very secure. Why is that? Is it because it has never been hacked before or has Tails been shown to be virtually hacker-proof? As someone non-technical I might be misunderstanding something. If so, can you clarify that?
Thanks.
It also comes with tor browser, electrum bitcoin wallet, and some GPG utilities preinstalled.
"otherwise"? Is that code for has Windows 10 written on the box?
Go to any store, anywhere. What computers are they selling? Maybe Chromebooks, which are showing to be wildly popular. But they also get returned a lot. Why? Because the user expects X software to run on Y computer, and do not even know what an operating system is because we idled in complacency on Microsofts desktop monopoly for twenty years. Take note of how Walmart sells Ipads but not Macbooks.
The only alternative to Windows is ChromeOS. Which is not an alternative for even half of Widows' use cases, since there is no native application support and its app-store restricted. Half of Windows appeal is the lack of application lockdown to a store, albeit MS has tried their hardest with their Windows Store to stop that.
OSX is not an alternative, Apple Stores are fairly few and far between, and the cost of a Mac is prohibitive, and it would have the exact same software incompatibility problems as Windows. And modern OSX is code signing applications and is, for consumers, even more restrictive and draconian than Windows is - do you want your potential software users on iOS or OSX? I certainly do not, because that gives Apple absolute power to stop my software at their whim, or never approve it in the first place.
Ubuntu (or any desktop Linux) is also not an alternative, because, simply, its not there on the shelf next to Windows or ChromeOS. If Macs are inaccessible due to price and location, Ubuntu does not even exist - and it literally does not, given its market segment size. If Canonical wanted serious desktop adoption they would have to throw ludicrous money getting Ubuntu computers in front of potential users to purchase.
So of course MS gets away with this. Nobody is trying to stop them. And I doubt Xbone is a flop - it has sold 15 million units, half of the PS4 but still well on track to outsell the original Xbox in its lifetime, which only moved 24 million units in 5 years. I am insanely against consoles as a platform and pray they die finally and give consumers their hardware back, but that seems like a distant dream as well.
https://play.google.com/store/apps/details?id=org.secfirst.u...
(i am actually even surprised about the interest)
> The SOCKS server does not interpret the network traffic between client and server in any way, and is often used because clients are behind a firewall and are not permitted to establish TCP connections to servers outside the firewall unless they do it through the SOCKS server.
Consider a service like SecureDrop. Armed with SecureDrop, journalists and dissidents/whistleblowers can communicate in a more secure way.
Or, consider a publication like Propublica. They set up a hidden service so that they could talk about censorship in China...and hopefully allow Chinese citizens to read it without ending up in serious legal trouble.
Statements like yours are the problem and I seriously hope that you take the time to educate yourself. Ignorance may be funny to you, but it makes it more dangerous for legitimate activists and journalists to use Tor.
I don't see what benefits there are of having a hidden service if you don't need to hide. The only thing would be encouraging/enforcing safe usage, but that doesn't enable anything, only forces people to use security that was already available.
(To be clear, I'm only talking about hidden services, not tor in general.)
http://www.wired.com/2016/01/propublica-launches-the-dark-we...
So using a hidden service was easier to set up than enforcing SSL on every page?
>Or even on SSL-encrypted pages, the exit node could simply see that the user was visiting ProPublica. When a Tor user visits ProPublica’s Tor hidden service, by contrast—and the hidden service can only be accessed when the visitor runs Tor—the traffic stays under the cloak of Tor’s anonymity all the way to ProPublica’s server.
The exit node sees that someone visited Propublica, not who, or what was fetched. (Assuming it's over SSL.) That really doesn't seem like sensitive information.
Based on the context, I assumed that the parent was talking about needing Tor to access the Darknet. If that's the case, the parent would be talking about Tor hidden services. While there are some really shitty hidden services, there are also some amazing applications - SecureDrop is one example.