Zed Shaw: Why I Don't Use Tor
sheddingbikes.com
sheddingbikes.com
Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox. God damn Zed, this Hitler sandwich shit is pretty weak.
Zed also has a problem with Tor because he thinks there is a "gigantic percentage of hackers and security experts on the volunteer payroll of a group who's job is to illegally wiretap people and circumvent the law on behalf of the government". He thinks some of these people work on Tor and thus Tor is untrustworthy. Funny though, his ISP is likely guilty of the same thing. I wonder if Zed takes that into account as a part of his paranoid fantasy.
There are serious problems with using Tor and Zed fails to mention any of them. You'll want to read what Thomas has to say on the subject (http://searchyc.com/tptacek). Specifically, Thomas mentions that a general problem with tools like Tor is that it identifies your traffic as a subset of all traffic thats probably worth monitoring. You're essentially adding bright red neon signs to your most sensitive traffic. The amount of traffic going through the Tor network is small enough that it is a tractable problem for a nation state to attempt to monitor all of it. Thomas also goes into how the incentive structure for these tools is completely broken. The defenders are academic researchers going for tenure, the attackers are nation states with millions of dollars to spend, and the users are dissidents that get killed when the tool fails. Unfortunately, arguments with this level of nuance appear to escape Zed in this case. I fear he doesn't have the domain knowledge to write something intelligent about this issue.
You don't need TOR. You do need an ISP.
If someone of sufficient expertise decides to hack you and take your banking info, they will, just like if someone decides to rob you on the street, they will. We assume there are vulnerabilities in any piece of software as big as Firefox. Your security depends on not being a particularly tempting individual target for highly skilled attackers and staying up-to-date enough to avoid mass automated attacks, and those factors depend on relative risks that can't even be objectively measured.
Edit/PS: I am also confident that the government would not insert back doors that are likely to be found by criminals, because those vulnerabilities would be exploited by foreign governments and would hurt U.S. commercial interests, which I imagine is the only kind of mistake that would result in Congress taking drastic punitive action (slashing budgets, reducing autonomy, increasing oversight) towards an intelligence agency.
curl -s http://www.kernel.org/pub/linux/kernel/CREDITS | grep gov
E: becker@cesdis.gsfc.nasa.gov
E: snyder@fnald0.fnal.gov
curl -s http://gcc.gnu.org/viewcvs/trunk/MAINTAINERS?view=co | grep gov
Asher Langton langton2@llnl.gov
My general frustation with your blog post is that your arguments apply to many popular pieces of software. It feels disingenuous and it feels like it's provocative solely for the purpose of being provocative.As I said in another comment, the Chinese government has beaten Tor. You can't download it or even read about it(almost everything Tor related is blocked). Even when you have it you can't connect, as all bridge IPs are blocked the moment the gov discovers them.
It's slow as hell to boot and on top of this the Chinese government is still able to monitor those who can connect with traffic analysis(a Tor weakness).
I'm something of a lazy cipherpunk and had hoped that most services and sites would have moved onto darknets like i2p by now. But sadly this is not the case, however it is the place where we finally need to go.
TLDR: I don't use Tor because it don't work, plain and simple. Never mind the insecurity mentioned by Zed, and no one here is talking about this.
Also, while Tor isn't used in China there seem to be some other Proxy Services that are used. A non-tech-savvy friend of mine who is Chinese citizen and moved back to China one year ago, uses some kind of proxy service to connect to sites like Facebook. I have the impression that the knowledge how to circumvent the firewall is rather common in China.
The reason Tor isn't used in China is that most of the bridge relay IP addresses are blacklisted by Chinese ISP's and net-cops. Now the list of bridge relays are not public, but China has enough man power(working full time I might add) to get ahold of nearly all the ip's and block them.
Actually it wouldn't be too difficult to automate this at all.
Knowlege to circumvent the wall is available, it's the resources to do so that are lacking.
I2P currently is too small to show up on the Chinese governments radar. Apart from this I don't know how I2P gets the ip's of the darknet node. The only guaranteed way to be safe is to have a Freind to Friend network, with absolutely no public connection nodes.
The thing is that for many people the risk of getting killed is worth it, and protecting the source is not the ultimate goal.
History has shown us that dissidents will often and gladly risk their own lives to get their message out. And often, despite the risks, they've managed to evade detection and capture even when they were up against huge, ruthless spy networks like those of the Soviet Union, post-war East Germany, or the Gestapo.
http://en.wikipedia.org/wiki/Steganography
Properly used, good steganographic software will hide your use of encryption. Ideally, your communication stream will seem perfectly innocuous to all observers.
Of course, in real life nothing is perfect. So there's always a chance your use of encryption will be detected. But using steganography properly should still reduce that chance to well below that of obviously encrypted systems like TOR, Freenet, etc.
Also, just as importantly, the more people use steganography, the greater the cost of widespread monitoring will become.
As pointed out in other replies in this thread, when you use regular encryption or systems like TOR, you're effectively raising a big red flag for anyone who cares to monitor your communication. So detection is really easy.
But if you use steganography, the snoopers will have to work much harder to even stand a chance of detecting that there's anything unusual about your communication. Multiply this by thousands or millions of people using steganography (especially if it's embedded in huge data transfers, like video streams) and the resource drain for effective, widespread monitoring could become unsustainable.
Right now the snoopers can go after the low-hanging fruit of obviously encrypted communications, and then maybe use rubber hose cryptanalysis to decrypt it, or simply block it. Steganography has the potential change the game drastically.
Here's some steganographic software for you:
http://freshmeat.net/search/?q=steganography§ion=pro...
"Get circumvention at all wrong and you achieve the opposite of what the tool is intended for: you put a big red flag on people breaking their local laws. ... Don't build circumvention tools."
That attitude is so wrongheaded I hardly know where to begin.
First of all, anyone who uses something like TOR in China has already put a huge (and very very obvious) red flag on their communications stream.
So, if those people are going to be trying to break through the firewall anyway, why should't they do so with the best tools available? Why shouldn't they try to hide their communication in a stream of innocuous traffic rather than obviously red-flagging it?
And why shouldn't concerned programmers write tools to make the hiding of such information more effective?
Look, many people are going to try to communicate even when they're forbidden from doing so, and they're going to try to circumvent censorship. So we can either try to make it easier for them, or harder. I'm on the side of making it easier.
Sure, some people are going to get caught despite using steganographic software. But I'm willing to bet a lot fewer of them will get caught than using bare encryption systems like TOR.
You might want to read Neils Provos' stegdetect stuff, first. The world needs more fun grad student projects, and you wouldn't want people to have to rehash the same stuff he broke 10 years ago.
But if the existence of such an arms race doesn't stop someone from using encryption it shouldn't stop them from using steganography.
Of course, you need to be prudent about it. Use the most secure techniques available, and don't use methods you know have been broken.
Finally, know that you are taking a risk, that nothing is 100% foolproof, and the more powerful and determined your adversary the more of a risk you're taking.
Pot, meet kettle.
Despite this, I'll do you the kindness of actually addressing the point you made by giving you a big, "so what?"
Activists and dissidents often go up against nation states. That's the nature of the business. And they knowingly take risks to do so.
The question is, are they simply going to use bare encryption, thereby virtually guaranteeing to draw attention to themselves in a state like China? Or are they going to wrap their encrypted message in a layer of steganography, thus giving themselves at least a chance to avoid detection in the first place?
Got any suggestions? Because I know the millions of Chinese who attempt to circumvent China's firewall daily would love to hear about it.
The point is that probably 90% of the time, these people aren't using anything better than bare encryption (if that), and they're drawing attention to themselves anyway. If they're going to do that anyway, I think it makes much more sense to hide the communication via stego.
But if you've got a better idea, let's hear it.
How in-depth do you want me to get with you? I gave you an actual (high-level, easy-to-read, summarized) academic source. You clearly haven't read it. Why not go take some time with it and come back not sounding like a crank?
Also, what makes you think activists have the technical expertise available to know what the "most secure techniques available" are and what methods have been broken?
I don't know where you got the idea that nation states are the only ones who use cryptography. Plenty of activists, along with other non-state actors do so all the time.
Plenty of cryptography is also designed by individuals not in the service of any nation state (as far as we know, anyway). In fact, some argue that such encryption is more trustworthy than encryption developed by nation states themselves.
"Also, what makes you think activists have the technical expertise available to know what the "most secure techniques available" are and what methods have been broken?"
I can't speak for any and all activists. It's really up to them to acquire such expertise or get advice from people who have such expertise.
That said, the problem here is no different from figuring out which encryption to use. So your criticism applies equally to encryption as it does to steganography.
We're not talking about users, we're talking about attackers and developers. Why would users have anything to do with our discussion?
Plenty of cryptography is also designed by individuals not in the service of any nation state (as far as we know, anyway). In fact, some argue that such encryption is more trustworthy than encryption developed by nation states themselves.
Developed by academics, but tested by both academics and the government. The testing is the thing that's actually important.
I can't speak for any and all activists. It's really up to them to acquire such expertise or get advice from people who have such expertise.
The point is that the technical expertise is not available. It's not up to them. It's not available. What you suggest they do is not possible.
That said, the problem here is no different from figuring out which encryption to use. So your criticism applies equally to encryption as it does to steganography.
Nope. Get back to me when we get government backed standards and recommendations for anonymity (hint: we have them for crypto).
Actually, in the message you responded to, I was specifically talking about users. I've been talking about users of crypto/stego all along!
They're the ones who take virtually all of the risk. The people who write the crypto/stego often aren't even in the same country, and they do their development in countries where crypto/stego are perfectly legal.
So I don't know why you started talking about developers all of a sudden.
However, I thought you might have switched subjects, so I specifically addressed crypto development in my second paragraph.
"Developed by academics, but tested by both academics and the government. The testing is the thing that's actually important."
That testing is only worthwhile if your threat model does not include the government itself, which has a vested interest in breaking all encryption, whether or not it has been "certified" by them.
"The point is that the technical expertise is not available. It's not up to them. It's not available. What you suggest they do is not possible."
How is it not available? There are plenty of people who design and analyze stego. There's your expertise.
"Get back to me when we get government backed standards and recommendations for anonymity (hint: we have them for crypto)."
Get back to me when that actually matters.
The government also has a vested intrest that the cryptography used by itself and its citizens be reasonably secure, else industrial espionage and other similar activities become trivial. Note that the NSA approved AES for the protection of Top Secret information. If you want to argue the NSA deliberately let the majority of classified information in the United States be protected by a flawed algorithm you're going to have to provide some proof.
How is it not available? There are plenty of people who design and analyze stego. There's your expertise.
The people that are good at building and designing crypto and stego (Are there any good stego systems? Doubt it.) systems are outside the paygrade of most companies, nevermind activists. The expertise is not available.
--
Your arguments are disconnected from reality and don't really have any particularly notable knowledge of this domain. This conversation has been a net loss, and judging by your average of ~2 karma per comment, other people seem to agree. I'll let you have the last word if you'd like it, but please refrain from wasting so much space in the future.
But, personally, I think the best place to hide them right now is video streams.
The thing about steganography is that the smaller your hidden message is and the larger the data it's hiding in is, the less of a chance there is of it being detected, and also the greater the cost of such detection will be.
Think of it this way:
How effective you are at hiding your message, and the cost of hostile detection are proportional to:
size of covertext
--------------------------
size of hidden message
In my opinion, the ideal medium for two-way, realtime steganographic communication would be something like Skype, where large, bidirectional video streams are used. It might not be too hard to hack up some webcam filter that injects hidden messages in to the outgoing videostream and another filter to decode messages from the incoming videostream.For one-way communication (or even two-way, delayed communication) any of the video hosting services like Youtube or Vimeo would be great. This should be even easier to implement than the Skype filters I describe above, as the processing can be done offline at your own leisure.
If using steganography to hide information in these videostreams becomes common, the cost to snoopers trying to find messages in them will become simply gigantic. And those costs will only increase as videostream sizes dramatically increase as they inevitably advance to offering higher resolutions (in the short-term), and even 3D-video (in the long-term).
An extra tip, if you're going to try something like this, is to make sure to use crappy/defective webcams that naturally inject noise in to the videostream anyway, and maybe film whatever you're filming on a nicely chaotic background like a closeup of trees billowing in the wind, ocean waves crashing on the shore, etc... that should hopefully provide plenty of chaos for your message to hide in.
I'm particularly amused by the comment about using complicated images of ocean waves and trees, as if computers were just mechanical humans trying to make sense of the shapes in the picture.
X is a video of a completely featureless white screen.
Y is a video of a jungle canopy in the midst of a storm.
At some point in both videos, one pixel changes color slightly. Which video do you think it will be easier to spot the change in?
Of course, the amount of information that can be transmitted in the color change of one pixel is ridiculously small, so in a real life example more pixels (or perhaps some other data in the video) would need to be used to embed the message, but the video size can grow along with the size of the hidden message.
As for "anomaly detection", the thresholds at which such detectors function have to be tuned in such a way that they don't give too many false positives to make them useless.
And they're not magic. They can only detect certain types of anomalies, not any an all past or future steganographic techniques that could conceivably be used to hide the message.
Steganographic techniques can and have been designed to mimic expected statistical profiles. Take a look, for instance, at Peter Wayner's work on Mimic Functions:
http://en.wikipedia.org/wiki/Mimic_function
The other thing I should note is that even if it is (theoretically) possible to detect a message hidden via steganography, the cost of doing so goes up as the amount of data the message is hidden in increases.
Even detecting a message hidden with even the simplest steganographic technique will be much higher than detecting the use of bare encryption, which is already out in the open.
So widespread use of steganography in large datastreams like youtube videos and Skype will create a huge computational burden on the snoopers attempting steganalysis.
Appelbaum, https://twitter.com/#!/ioerror/status/19703396818747392
Anyone got good instructions on how to actually BadExit his nodes? I want to post them so people actually can.
Enumerating some bad nodes does not substantially improve this. The above can only be prevented by using something like SSL plus a trusted certificate on top of Tor.
To further malign him of course.
ExcludeNodes $0AD3FA884D18F89EEA2D89C019379E0E7FD94417,$3100A70862157E5F9136B6AAEB7571745D4DC055,$49E2C345FDA5E9ADFE13320690BF2C77EA803E6C,$4A0CCD2DDC7995083D73F5D667100C8A5831F16D,$5FABB67A4C229ECACD53F5E02B62C87E5300728D,$62665FD8A07D2E0F6ABDB4A36283A5A8824C0128,$6AF64BD1DF8B92D5194760C2256EBF80F70273DD,$71B7F2406DDAE829979B53963B952E17CD021125,$8522EB98C91496E80EC238E732594D1509158E77,$D67C5F501DAA0EE65AF9422A36385217D8AD3927,$EFE02E652CA2EB6FD96B30DC77EA55ABF7EFC1A5
Then your traffic will never pass through any Tor node that Jacob has publicly admitted to controlling.To verify this:
Check https://www.torproject.org/docs/tor-manual-dev.html.en for the ExcludeNodes directive. There is an ExcludeExitNodes option, if you're willing to tolerate him as a middle-man, and just not exit out his nodes.
Check one of the online directory servers (e.g. http://torstatus.blutmagie.de/) and use the Advanced Query Options to find all the nodes where "Contact" - "Contains" - "appelbaum.net" to find which nodes he administers. Then add the fingerprint of every node you want to avoid to the ExcludeNodes entry.
You should obviously confirm the list above with other sources, because one or all of the following might be true:
1. I may be in cahoots with Jacob, plotting to hack your codez.
2. The directory server I linked to may be a co-conspirator. Fortunately, there are other directory servers you can query.
3. There is no three. Anybody can put up a node and declare anything. If Jacob, or I, are using Tor nodes nefariously, do you really think we'll put our names on them?
P.S. Don't forget to restart Tor after you change the torrc.
Tor exit nodes are already extraordinarily untrustworthy, one run by anyone associated with Wikileaks might as well be a chinese room with Hitler inside!
Complaining about tech speech being hyperbolic whilst simultaneously [implicitly] comparing Applebaum to Hitler is a little ballsy, tbh.
Using der Fürher in an internet argument is a realization Godwin's law, not a violation of it.
a) Read Greenwald Salon article accusing Wired of having shady connections.
b) Roll that basic premise into a set of wild accusations and things we already know about Tor.
c) Sit back and enjoy the whole chaos of the troll. When someone attacks bring out the usual sockpuppets and sycophants to say "but Zed does all this great coding", "Zed is not like that in real life/conferences".
d) Profit/save on therapist fees by feeding own teenager-like angst and need for attention.
Note that those two things can be conflated in one: if you disapprove some goal, then a part of your goal is to make that not happen. So in the end, the only thing that matters is the influence of the deed on your goals, period.
Now the deed cannot be evaluated alone. You need to know how it interacts with the world. And the first place to look at is the other deeds of the same person. (There lies the validity of Ad Hominem arguments.) However it's not the only place to look at.
For instance, if a Paper-Clip-Maniac wants to solve the Friendly AI problem, you probably don't want that problem solved: it could fill the universe with paper clips, wiping out all sentient life in the process. Now, say you're a transhumanist, and you want to cure Death. Solving the FAI problem suddenly look much better. It may even be worth the risk induced by that Paper-Clip-Maniac.
"The sky is blue." "He's a Nazi!" is ad hominem.
"Has anyone noticed the Jews have an awful lot of banking jobs?" "He's a Nazi!" is, if true, very relevant. The first statement is likely not just a mere observation that may be true or may be false but is historically associated with antisemitism and is probably being used as the thin end of the wedge and not a neutral observation. It's relevant here because it expands into an argument where the origins and motivations of the arguer are in fact very relevant.
Similarly, when you see a new physics theory coming from a known crackpot, while the fact they are a crackpot may technically have no effect on the truth value of the theory, when it comes time for you to evaluate the theory you are justified in noticing it's coming from a crackpot.
Bayesian logic lets you express it even more cleanly; in Aristotelian logic the motivations of the speaker are irrelevant to the abstract truth of the statement; in more practical Bayesian logic, as you personally examine the likely truth value of somebody else's statement (with no presumption of access to the abstract truth) their motivations can be very relevant. "ad hominem" is over-weighting their motivations or falsely weighting their motivations, and under this formulation you also get reverse ad hominem, in which you under-weight their motivations, which is every much a fallacy as the original ad hominem, and which Zed talks about in his post.
All things considered, people being hyper about ad hominem is probably better than letting it slide too often, because it is certainly true that on average it is not a valid attack. But he's absolutely correct that it is sometimes valid, and while I'm not sure Zed's necessarily correct about Tor, I do think he's a lot more justified in his opinions than the pileon here consensus is indicating.
"He's a Bayesian!"
This is probably why Zed has the words "Conflict Of Interest" as a section heading in a very large font.
For example: "I will go on record right now saying Wikileaks rocks. ... if anyone from Wikileaks tries to work with me or on any project I'm on you bet your ass I'm not trusting them one bit. Never trust a traitor, no matter how noble their intentions."
So Wikileaks "rocks", yet anyone involved in Wikileaks is a traitor and shouldn't be trusted? That seems contradictory. Taking this logic further, are journalists who cite Wikileaks' work also traitors that shouldn't be trusted?
As a fan of Zed's and someone that isn't completely sold on Tor, I'd love to see a sober critique of the project's vulnerbilities from Zed, but this post isn't it.
For example, your post doesn't have a single link giving counter evidence. You'd think you could bring some of that out but so far, in this entire thread, there hasn't been one link with counter evidence. There's been links to our twitter conversation, links to things supporting Tor is crap, links to discussions of Steganography, but so far I can't see 1, not ONE link with counter evidence proving me wrong.
I actually would love some, and was hoping I'd get some since I provided references, but nope. Just bullshit rhetoric and ad hominem from people who claim to hate bullshit rhetoric and ad hominem. So don't go acting like you're all above the drama.
Zed, find a therapist, please. You are a talented person but your mind needs debugging.
And, Thomas, "ritualizing" may be the only way to keep forensics sound. When you prove something, you want it to remain proved.
Conversely, if the NSA had compromised it one would expect to see no outward signs, as they a) don't care about pedophiles, b) would claim "national security" to hide the means of tracking terror suspects from the public's eye, and c) likely wouldn't tell anyone when they did apprehend someone.
I think it's probably pretty likely that the NSA is running a few nodes, but that's the risk you take wit something like Tor, just as bittorrent seeders risk riaa proxies downloading from them.
Most of the CP cases are done with a lot social engineering. Instead of having some sort of super router that can sniff through all the packets its just a bunch of LEOs in an office trying to gain the confidence of the criminals.
A pedophile running a hidden TrueCrypt volume and using Tor to trade chid pornography on onion sites is likely to get caught only if they pull a Bradley Manning, that is, saying the wrong thing to the wrong person. Unfortunately, most pedophiles these days that trade in child porn are likely more technologically advanced than the people responsible for tracking them.
> so would simply use the information to compose a list of
> people to watch for slip ups
How would they 'watch for slip ups' though? One would think that they would have to justify to a judge why the person was under surveillance in the first place.Goodness me! We should also be examining that DARPA developed honeypot called Teh Internets and take a second look at that ominous collaborator Sir Tim Berners-Lee.
Once I got to Zed quoting Project Vigilant's volunteer count I had to laugh. Zed's bullshit detector needs a tune-up.
(I'm in no way affiliate to NearMetter, it's just the best way I found to easily read a twitter conversation)
This is all TOR is supposed to do. This allows you to be anonymous to the receiving end, but it does not guarantee it. It is your responsibility to surf safely, to sanitise your traffic, to encrypt your traffic and do the rest. We know that most people can be uniquely differentiated by combining all the available information from their browsers (some of which doesn't need javascript) http://panopticlick.eff.org/ . Therefore we know, using TOR or not, that we need to be careful to do things well when we want to be anonymous.
There is little in this article which makes me worried about TOR. TOR isn't the problem, if any of this is true, then the problem is the government collecting data in various ways. Whether you agree with this is a matter for yourself to consider and not a reason to avoid using TOR.
Tor is used in China to access censored data. Tor is used to send encrypted data anonymously from oppressive countries. Both of these things align perfectly with the honest motives of Wikileaks.
Step outside your world Zed. Some people have a real need for projects like Tor.
It's certainly true that humans have all manner of interesting behaviors owing to the fact that we're smart apes with huge numbers of survival heuristics. I would pause before taking a sandwich from Hitler, because I'm human, but it's not pertinent to the question of whether the sandwich is any good. (Except in as far as you think it more or less likely that the sandwich is poisoned etc.)
So I find the whole first half of the text to be a flabby way of saying that the arguments of dishonest people need to be evaluated more critically than those of honest people. But I find that the arguments of honest people need to be critically evaluated too. I think that the authors of Haystack were honest, but their assertions turned out to be dangerously wrong. (Which, by the way, we know thanks to Mr Appelbaum.) So, as a guide, the motives of the author don't seem to be very useful to me.
Then, in the second half, we find a mixture of arguments that I find valid, and many that I don't. A sense of vertigo at the amount of trust that we have to put into software is justified. It is possible to hide major bugs in code and we're standing on a stack of hardware, kernel, and userland which is incomprehensible to any one person these days.
It's also true that there are some fairly effective attacks against Tor for the capable opponent. It's a real-time mix-net, with all the tradeoffs implied and it generates a lot of research. I recommend reading some papers of the papers, I find them often to be very good.
But accusing the Tor people of being NSA agents because they once got funding from the navy doesn't hold water. The Internet was an ARPA funded project. Military spending has subsidised much of the modern world.
Many people have read through Tor's source and evaluated the protocol etc. Of course, all those people could be NSA agents too, publishing fake papers. You could, in fact, be in The Matrix. But you probably aren't.
Some, likely massively exaggerated, secret project might be monitoring every ISP on the planet and thus able to break any real-time mix net, but they probably aren't.
Likewise, all the Tor node operators that I have met might all be NSA plants, but they probably aren't.
And finally the author picks out Mr Appelbaum for special criticism because he connects him with Wikileaks. I think his assertion that the goals of Tor and Wikileaks are in conflict is wrong, but we could go around all day trying to pin down the goals of Wikileaks so that's probably not fruitful. But it does seem ironic that the author voices support for Wikileaks right after asserting that such supporters are not to be trusted.
So, while the stack of software is, indeed, large, Tor remains a reasonable tool to use. If the author is so concerned with the human aspect, the Tor authors are make regular appearances at conferences and are wonderful people to meet. So do, and are, node operators in my experience.
Also, on top of Tor, there's a fair chance that the author is using a browser who's network and SSL stack I've had a hand in. And who knows what kind of person he's taking a sandwich from now?
Its extremely troubling to say the least from a trust aspect..
You over-simplified the argument here, I think. I read it more as a person's motivations need to be considered, not particularly honesty. And nearly everybody has motivations that may influence how and what information they present to you.
But how can we know a person's actual motivations? Those are internal to the individual, we can't see them. Heck, in many ways the individual himself doesn't really understand his own motivations.
Trying to consider motivations is thus completely fruitless. We only have the history of a person's actions, and to a lesser extent, the history of his statements, to guide us.
What is a used car salesman's motivation? It's reasonable to assume that their motivation is to get you to buy a used car.
What is a crack addict's motivation? It's reasonable to assume that their motivation is to get more crack.
These are somewhat extreme cases, but you can almost always tell what a person's motivation is by observing them. What is a married man's motivation for not wearing his ring? He either: forgot it, lost it, is having an affair, or is no longer married. And you can probably tell which if you ask him the right questions.
but there is also minority who wants to surf child pornography undetected.
and then there is really small minority who are there so that NSA can have a better look at what's happening.
what then will be the end result of the code produced and deployed do you think?
If you were dying of thirst and Hitler had a water bottle, against any other concerns, you're taking it. Also, if you needed change for a pay phone to call a tow truck and Hitler offered you a quarter, you're probably not going to stick to your principles in that case either; because the risks are so much lower and need a bit higher than the aforementioned sandwich (we'll suppose you have gloves and no plans on licking the quarter before inserting it into the phone).
So, really, that Zed doesn't use Tor says more about his own situation than whether he thinks a better or truly-trustworthy way to anonymize live bits is even possible.
Surely most of us don't use Tor because
1. It's slow as hell
2. We're not doing anything illegal or trying to get past
censorshipI think 2. is interesting to talk about, because the intersection of legal activities with what those in power find objectionable is the battlefront of liberty.
So while Tor may not be interesting to joe public yet, I do think it's worth exacting discussion of it's strengths and flaws.
FWIW this includes Zed's criticisms up until the point he took his ball and went home.
They (Tor) are losing their fight. IMO
That should turn the tide, don't you think?
The Chinese government collapsing within 5 years? That takes a revolution. I assign less than 0.1 probability to that.
The EFF themselves present many of the problems: http://www.torproject.org/download/download.html.en#warning
On top of that, the EFF has demonstrated that they are worried (reasonably) about the trust given to the global CA structure: http://www.eff.org/deeplinks/2010/03/researchers-reveal-like...
In terms of protecting your anonymity, even when correctly managing cookies you may be uniquely identifiable by browser fingerprinting: https://panopticlick.eff.org/
At least the last time I looked, the network appeared quite thin, with much of your traffic by default traveling through a small collection (perhaps as low as one) of exit nodes.
TOR also represents a juicy target for eavesdropping by its nature as a concentrator for people trying to avoid it. If you were a burglar, it would make sense to stay the hell away from a place the cops had identified as a hotbed of burglary since they'll probably be concentrating their efforts there.
And, of course, there is the issue that it's been used in the past to publicly out users traffic: http://www.theregister.co.uk/2007/09/10/misuse_of_tor_led_to...
Most of these things apply to other possible solutions, but at least there you may get the advantage of most users of those services "having nothing to hide" making them not as juicy a target.
If I was super, super concerned about my privacy and anonymity when sending a specific few documents or such, I'd most likely take a page out of the black hat handbook and compromise a few lightly administered servers and use a not commonly used covert channel.
Here we see the again the conflation of organizations and individuals in an opinion piece connected to Wikileaks. Why does this happen so regularly?
I don't know anything about Appelbaum, but it's perfectly possible that he believes in personal privacy and institutional transparency, a not particularly radical, surprising, or unusual stance which would resolve this "conflict of interest" perfectly.
"Assange has founded Wikileaks, so how dare he oppose leaking details of his alleged sex crimes trial!?"
Woo, Zed is the new Glenn Beck.
When I access some random website from home, my traffic is vulnerable to capture and analysis by my ISP, the intervening backbones, and the website that I am accessing. I don't trust my ISP and the backbone providers not to examine my traffic, but I do have quite a bit of confidence that they don't care about me. I'm not very interesting.
If I use Tor, I add another party who can capture and examine my traffic: The Tor exit node.
I most emphatically do not trust random Tor exit nodes not to examine my traffic. I'm quite confident that the NSA and other government organizations run their own Tor exit nodes--after all, a stream of traffic generated by people who are interested in hiding their activities is likely to be quite interesting.
I can encrypt my traffic...but not all of it, and do I really want to trust that everything important is properly encrypted?
If I had something to hide, I'd do so by blending into the crowd, not by slapping a big "I'm trying to hide" label on my traffic and sending it to the people most likely to be interested in it.
Geeks are opposed to certain sources of knowledge, probably because they see themselves as on the receiving end of bad assumptions based on their clothes and mannerisms, and I agree with them that it's always best to avoid subjective judgments when possible. However, there are so many situations in life where you can't audit the source code yourself, and when there's serious risk, you have to make use of the information you have. You can't investigate the provenance of the cheese sandwich, and even if you could, do you really want to spend your whole life playing Sherlock Holmes? I'm thankful for open source and the people who read code, but I am not going to read the source code of every damn piece of software I use. Sometimes I'm just going to say, "The only source for this software is a shareware site in a country I've never heard of, and it claims to come bundled with porn, so I do not feel comfortable installing it on my Windows PC no matter how good some guy on 4chan says it is." Nothing against porn or countries I've never heard of, but my Spidey sense is tingling.
Anyway, motivations do not matter one bit when it comes to evaluating whom to trust with your data, if it's not safe by design then it's not safe period.
If you're running an international criminal network I imagine it's ideal.
I think Zed's fallen wide of the mark here. He's failed to address the technical failings with Tor, instead opting to launch his own ad hominem attack on Jacob Applebaum (who's done more than just work on Tor and Wikileaks) and the history of the project as a US Navy tool.
If he has such a problem with Tor then it's worth auditing the code and seeing for yourself. It's not perfect, but Tor has it's uses. If you really need the kind of anonymity to protect something life threatening then don't use Tor (due to it's failings in the cheese sandwich quality department, not because of it's history or contributors).
Where is the conflict?
I wonder how he makes the conspiracy theories about NSA when Tor is open source? He is free to investigate the source code for 'backdoors'.
Such conspiracy theories and trolling are nothing but desperate attempts for attention.
This article isn't that useful without knowing the nature of what Zed doesn't use Tor for.
I've tried Tor in the past and I stopped because:
* It's really slow.
* It's the chatroulette of really questionnable material. You stumble into some shit and think WTF?!
* The amount of traffic it generated caused my shitty router to slow down significantly or crash completely.
I must admit that I am simply too chicken to use Tor. In Germany I think it can actually get you in trouble if some pedophile exits through your node.
Also last I checked, there really were some issues with the security model. That was quite a long time ago, not sure if they have been fixed now.
If people do bad things through your exit node, you are in danger regardless where you live. The law enforcement must be aware of what your server was doing. Its understanding varies from place to place.
I don't know if it's an NSA backdoor, but there were several security alerts related to SELinux. I don't understand why all common distros use this. I don't, I compile my kernels from unpatched vanilla source.
Can you elaborate?
I'm not aware of any time SELinux has actually introduced a new hole.
Just because the Swastika was co-opted by Hitler and his cronies means nothing to most people outside the western world (which is in a minority).
Secondly (while I have this soapbox): whether you take the sandwich from Hitler or not depends on whether Hitler is your "Der Fuhrer" or not (remember, he's long dead, so time travel is involved in Mr. Shaw's hypotheticals). If Hitler is your Fuhrer, then you _better_ take that sammich and eat it if he offers it to you! :-D
It was all fun and games when Zed was talking shit about Ruby but he's jumped the shark. It was bad enough when he freaked out because someone was converting his books code to Ruby from Python. Free code but not free book?