MoreOnionsPorfavor: Onionize your website and take back the internet
blog.torproject.org
blog.torproject.org
https://community.torproject.org/onion-services/advanced/oni... works better, it shows the configuration, but assumes there is already an .onion address and does not point to documentation how to set it up.
Hey, I know documentation is hard. But this could be improved a lot. By now I figured out that I'd have to install Tor on the server (not my machine, as the docs stated), find the torrc (the documentation has to mention where it is), point to the localhost port active of the webserver, the .onion address is autogenerated (so this will be an unreadable mess?) and can be taken from a file the tor software generates.
And this:
> We're not going to cover how to set up a web server here. If you get stuck or want to do more, find a friend who can help you. We recommend you install a new separate web server for your onion service.
Just cut it out. I'm actually lucky enough to have friends that could help me with this, but what if I hadn't? Cover in the documentation what needs to be done, or at the very least don't show an attitude about it.
Running a default or standard configuration of the bigger web servers like Apache or NGINX is a terrible idea if you're actually trying to hide the identity of your server. Setting up a secure hidden service usually requires that several default or common features be disabled, if one actually wants to hide the location of the service.
The first time you setup a server or a relay expect it to take half a day to a full weekend.
And if you're an Ansible user, you will enjoy Nusenu's ansible-relayor: https://github.com/nusenu/ansible-relayor
I forgot why exactly I didn't use ansible-relayor last time I setup relays but I had a reason. I'll try to use it next time I deploy a batch of relays.
google.com/recaptcha connect.facebook.net static.chartbeat.com ak.sail-horizon.com pi.pardot.com htlbid.com
A separate concern, besides this choice of example, is why ProPublica is normally helping to leak the identities and intimate browsing behavior of people who visit their site, to some of the most powerful and invasive corporations, given this mission:
> ProPublica is an independent, nonprofit newsroom that produces investigative journalism with moral force. We dig deep into important issues, shining a light on abuses of power and betrayals of public trust — and we stick with those issues as long as it takes to hold power to account.
So overall, I guess this move isn't intended to protect the masses but provide more cover traffic mainly.
I would love to run a TOR relay again but I'm a bit paranoid now.
> Tor relays are also referred to as "routers" or "nodes." They receive traffic on the Tor network and pass it along. Check out the Tor website for a more detailed explanation of how Tor works.
> There are three kinds of relays that you can run in order to help the Tor network: middle relays, exit relays, and bridges.
IMO the real issue is that my bank is reckless for picking a shitty UK service (who don't even speak our local language - just imagine some poor soul getting blocked because someone else running a Tor node over DHCP).
I also agree that it shouldn't be a problem if you're not an exit node, but that's the way it works.
I will definitely repeat the "experiment" in the near future, just as soon as it is feasible.
EDIT: As I mentioned in another comment:
> I thought one of the points of the article was the propagation and subsequent democratization of Tor/Onion sites? If I have to rent a VPS to run a node, isn't half the point defeated?
A traceroute to the Xiaomi servers revealed that my packets were dropped somewhere in the ChinaNet AS. I stopped my relay and everything went back to the normal a few days later.
If you don't want to use the Xiaomi app there is an API to control the vacuum on the LAN. See also "34C3 - Unleash your smart-home devices: Vacuum Cleaning Robot Hacking" [1]
Privacy and security concerns aside, I find that pretty magical that you can control a device from the other side of the planet, with only a few hundred milliseconds of latency :-)
If my bank blindly blocked IPs like that I'd switch banks.
Yes, unfortunately some sites and such "protection" services block Tor IP addresses to mitigate abuse. While just blocking exit nodes would be sufficient (though still an overly blunt instrument), some carelessly block Tor relays as well.
In the case of Onion Services, unlike running a Tor relay or exit node, you are using Tor as a client, much the same as when you use the Tor Browser. Your IP is not on any such global list of "Tor IPs". Your ISP (or VPN, if applicable), can see that you're using Tor (unless you use a bridge), but this doesn't get you on these sort of block lists.
On a side-note, if you're thinking of running a Tor relay from home to help contribute to the Tor network, but don't want to risk getting your IP address blocked, consider running a bridge instead. https://community.torproject.org/relay/setup/bridge/
It's basically an arms race all the time; you'll need to pick as side. It's sad but there's a touch of "we don't want to do business with people who have something to hide" that has to get weeded out before you're not guaranteed to suffer any inconvenience from running a for relay.
If my bank blocks me again, my solution will be to use a VPN instead of giving in.
They do it with rooted phones, and they do it with Tor. If you're using those, you're an acceptable loss based on their metrics. Unless you can figure out a way to set up your friends and family to be Tor'd, and everyone else does too, that won't change. Also, no matter how much you point out that from the inside, you can't avoid the fact that a lot of fraud inevitably ends up using the same tools.
I'm not saying I agree with or like that state of affairs, I've just fought that fight and it really doesn't go much of anywhere. They have their reasons, and what they deem to be acceptable reasons to make the decisions they do. As long as that is the case, you just end up having to live with it, or not do business with those companies. By fighting that fight, I mean doing things like pushing against things like adoption of device fingerprinting, and picking apart under what conditions it works and doesn't. From the perspective of the business these measures make sense. From the perspective of a society at large and what even a modest understanding of what courts would do with some meta-info if they knew it existed/was collected on the other hand, that resilience to fraud is not a luxury we may reasonably be able to afford for long.
Sadly they stopped doing that a while ago [2]. If anyone has insider knowledge about the reason behind, I would be really interested to hear about it.
[1]: https://blog.cloudflare.com/cloudflare-onion-service/
[2]: https://community.cloudflare.com/t/tor-alt-svc-header-not-be...
Cloudflare only sends the header to clients it detects as Tor Browser. If you have tweaked your config or are running an older version, it may not detect correctly. Even if it had previously worked.
This technique is not "better than" the "Onion-Location" approach. They complement well. Use the 'Alt-Svc' header for all users with Tor Browser's user agent and send "Onion-Location" to all users. If a user decides to opt for the .onion address, they can. But they don't have to.
A user should plainly know if _any_ traffic exited the Tor network and that is not always the case. (See mixed content on most HS mirrors of major sites like NYTimes)
The .onion TLD is named for onion routing[1] and has been around for quite a while as you pointed out. If it caught on, I imagine most people would accept the name without much thought. I think the bigger barrier to .onion catching on is getting people to install Tor at all.
[0] https://en.wikipedia.org/wiki/List_of_Internet_top-level_dom...
I thought it was going to be some random "AI" project that could rewrite your prose in The Onion humour ala:
https://www.theonion.com/fuck-everything-were-doing-five-bla...
For me who don't live in the states and have very little exposure of that satirical newspaper, .onion brings no connection to it. If I did not know about The Tor Project I would had guess it was a cooking related domain name. I would also have guessed that google was a company trying to sell glasses.
"Ogres are like onions..."
"The 'internet' is like a spider's web, but each point in the web is a different computer."
vs
"Tor is like an onion, where each layer of the onion represents a computer acting like a relay, in a giant network of computers, which your traffic is routed through....."
Yes, older members of Gen Z have already been enjoying Shrek "post-ironically" for years. Younger members of the generation are editing together clips of teenagers from the 00s as though it were some bygone halcyon era. Whether we like it or not the trends of reference and farce seem to be accelerating.
Tor is not targeting a “normal” person, as the media has already told the “normal” people that the only things available on the “dark”/“deep” web are illegal.
That being said, I am curious what happens if you don't click "accept" on those ones. I'm assuming you're implicitly accepting by not leaving?
Reality is all over the place.
That's an interesting statement - what are the "users" doing there that "normal users" are not?
I am almost done reading The Surveillance Economy and it feels like almost an obligation to push back. (Using ProtonMail, use a large leased server in Germany at Hetzner for my routine work and writing, and using private browsing tabs when I must use Twitter or Reddit.)
It looks like Onion domain hosting services are $5-$8/month, but going through their checklist and making one of my VPSs approved would be educational.
You don't need a special host. You just need to run Tor and connect to the network.
Furthermore if you are not hosting any illegal/objectionable content and don't need to hide from law enforcement or state-sponsored attackers, a lot of the security concerns around anonymizing the server no longer apply either.
> Bitcoin uses digital signatures (ECDSA) to prove ownership of funds, so sending bitcoins requires the owner of them to digitally sign authorizing the transfer. This transaction is sent to Bitcoin’s public network and later recorded in Bitcoin’s public database (blockchain), so anyone can verify it by checking its digital signature.
If everything is signed and verified to come from a specific account then that's by definition not anonymous. To be anonymous it would need to be the case that no one could figure out who sent the transaction (making the sender of the transaction anonymous), i.e. it couldn't be tied back to any specific account.
Monero makes it impossible to tell what is what and gives people who want to trace money a very hard time doing so.
ZCash uses Zero Knowledge Proofs. A ZK Proof (in this case zkSNARKs) is a way you can prove that you own a key to a second party without a third party being able to tell if there was an actual key involved (it is very easy for two colluding parties to fake a successfull ZK Proof).
IIRC ZCash basically allows you to prove that a transaction has moved money correctly between two accounts without revealing what accounts those are or how much money was transacted. There is knowlegde of how much money is in the shielded pool, ie, all money behind ZK Proofs.
Either approach has different advantages and disadvantages.
Still, I feel better using ProtonMail than FastMail, and I consider FastMail to be preferable to gmail.
I also feel better only touching Twitter, Reddit, and Facebook in a private browsing tab. I understand that they can to some extent still use my data to make money for themselves and not share any back with me. I understand that even limiting the data collected in me, I am still subject to nudging, herding, and conditioning - but I hope to impede these actions against me.
I am an author and I rely on social media a few times a year to notify readers of new books, updates, etc. Otherwise I would be happy disconnecting, as I have disconnected from corporate news services.
I often take the effort to convert the URL's to these sites before sharing with others (there are plugins that do this automatically).
Also check https://switching.software
https://en.m.wikipedia.org/wiki/Cypherpunk_anonymous_remaile...
However the system by which they operate is relatively easy to implement by volunteers. The model is very similar to Tor's onion routing (they're both Chaumian mix networks). I could see middle relays run by volunteers on their Gmail accounts (or whatever) with exit nodes being established addresses specifically for the purpose of being exit nodes.
Exit nodes might require messages be signed by a publicly available key or one registered with the exit node. The sender does need a public key for all the hops. So the final recipient needs to have a key known to the sender.
While spammers could send stuff to people they know public keys for, they wouldn't necessarily be able to send random spam to people.
IIRC in the historical spam problems the sender would make an anonymous (non-crypto) remailer the final recipient so the network would forward the encrypted messages around but the last one would remail the unencrypted message to an included distribution list or listserve or something. Since anonymous remailers aren't a thing anymore that spam vector is closed.
Remailers were an interesting thing a long time ago. Because they work on extant infrastructure I think they could be a cool thing again.
What I love about them is also that it works in in tricky NAT situations where WebRTC struggles.
My file manager "cryo" also uses Tor hidden services for signaling without a central server to initiate peer-to-peer connections. https://cryonet.io
https://community.torproject.org/onion-services/advanced/oni...
IRC help: https://support.torproject.org/get-in-touch/irc-help/
Nothing came of this "wave", if I'm not wrong, right.
https://en.wikipedia.org/wiki/Facebookcorewwwi.onion
edit: and it seems down to me right now.
edit2: it works... but slower, than just going to regual HTTPS version with Tor. Which makes sense, because it needs to hop more.
edit3: .... but it doesn't let me log in, as I am logging from "suspicious location".
* You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end
* The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic
* It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion endpoint
And also it precludes any attacks a malicious exit node could run on your https traffic, like the other comment says
Computerphile did an interesting video series on this!
Which is good because CAs are useless; they're complete overhead. Back when EV certificates meant something, they were marginally useful, but at this point, we might as well just switch to a TXT record that validates domain ownership. (Obviously, that doesn't protect against DNS MITM attacks, but that's a separate issue.)
I wonder if anyone has tried putting .onion addresses into DNS and have clients treat them like address records...
An onion service's IP address is protected. Onion services are an overlay network on top of TCP/IP, so in some sense IP addresses are not even meaningful to onion services: they are not even used in the protocol.
End-to-end authentication
When a user visits a particular onion, they know that the content they are seeing can only come from that particular onion. No impersonation is possible, which is generally not the case. Usually, reaching a website does not mean that a man-in-the-middle did not reroute to some other location (e.g. DNS attacks).
End-to-end encryption
Onion service traffic is encrypted from the client to the onion host. This is like getting strong SSL/HTTPS for free.
From here: https://community.torproject.org/onion-services/overview/
And there's another good reason for the Tor network: if you run an onion service, the traffic will use only Tor non-exit nodes in the circuit, giving a relief to the exit nodes.
However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit.
Should you make your site only available via onion routing, or primarily available on onion routing, all workplaces will immediately block access and look at anyone who accesses with great incredulity
For example in a hospital, there is no good reason for employee to use Tor on work computer.
I would argue that hospitals and other public settings are actually more in need of higher privacy in electronic communications.
Imagine a physician working on, say, Scarlett Johansson's health issues; he periodically sends this data to the specialist that will run some test, and a creepy sysadmin finds out. Should he be able to MITM those comms, and resell the info to newspapers (or worse)...? Nope; the physician should have perfect privacy from network operators.
"I'm a doctor in a very political town. When I have to do research on diseases and treatment or look into aspects of my patients' histories, I am well aware that my search histories might be correlated to patient visits and leak information about their health, families, and personal lives. I use Tor to do much of my research when I think there is a risk of correlating it to patient visits. - Anonymous Tor User"
From here: https://blog.torproject.org/remote-work-personal-safety
What kind of industry do you work in where the mere act of using Tor is reasonable suspicion of a law being broken?
I do remember the "kids who use Linux are hackers" arguments from schools; arguments that still occasionally pop up on rare occasions. And even more recently, I see the pushback from administrators and ISPs over encrypted DNS.
My instinct in this situation is that the "only criminals need privacy" argument is probably evergreen, and that Tor probably isn't in a unique position.
Of course, companies can choose what to install on their own devices, and they can choose what software they'll allow to connect to their networks. The Tor project changes nothing about employers' rights to control and monitor the hardware that they issue. It's normal for workplace networks to have more restrictions than ordinary networks.
Nevertheless, if (beyond those policies) your instinct is that anyone you see using Tor is probably a criminal, then I'm not sure you can honestly claim that you "generally support the Tor project and the goals of having a surveillance free internet." A casual observer would be forgiven for thinking that maybe the opposite is true, and you're terrified of a world where the Internet can't be monitored -- particularly the ordinary, everyday Internet as accessed by regular nontechnical people on their regular, everyday smartphones and laptops.
There's no legitimate usage for World of Warcraft on a work computer, and I'd happily ban that from work computers. But I also wouldn't hop onto an unrelated article for new players and imply that all of them were criminals. The linked article never mentions work computers, it's talking to website operators.
If your objection here is that you think Tor is inappropriate at this moment in one specific work setting, then fine, but that's not really adding anything to the conversation about whether or not general websites should be made available over Tor. It's just unrelated FUD.
I want to be clear, the goal of Tor proponents is for everyone to be running Tor (or something similar), and for most websites to be available over Tor by default. People should be running Tor on their smartphones, on their home laptops. Tor should be the default way that people share files with each other, and the default way that people set up technical blogs, or even just quick websites that show off pictures of their cat. The vision of the Tor project is a world where Tor is normal and ubiquitous for regular, non-technical people.
So unless your work policy bans all personal devices from your network, creating an expectation that any smartphone that joins and boots up a Tor browser automatically belongs to a criminal is contrary to the goals of the privacy movement. Our goal is that every device and every website should be private by default. Your network should be the exception, and it should only have company-owned devices on it.
And of course it's fine if you disagree with that, you don't have to be a privacy proponent. Lots of smart, reasonable people disagree with us about what the balance is between security and privacy. But demonizing Tor users in ordinary, everyday contexts is anti-Tor.
> or primarily available on onion routing, all workplaces will immediately block access and look at anyone who accesses with great incredulity
To go a step farther and suggest that making a website available over Tor should automatically mean that people who visit it are suspicious -- that is also anti-Tor and (I would argue) anti-privacy in general.
If I went into an interview for any company in any field offhandedly mentioning that I ran a Tor website, and then had to field a bunch of questions about whether or not I was a criminal, that would be a major red flag to me to avoid that company.
The network policy does ban all personal devices, in order to control what connections originate from inside the network.
To be clear, I'm not demonizing Tor or Tor users. I like what the Tor project wants to do, and I support it, but believing it will be allowed in many corporate settings, in July 2020, is extremely naive. As I already mentioned, there's no legitimate use case to allow this in a corporate setting.
Do concerns about being tracked between websites suddenly disappear at work? Is it no longer legitimate for an employee to log in to a personal account for non-work purposes via the corporate network on (for example) their lunch break? Etc, etc.
Also I'm a bit confused by your stance given the realities of encryption. Does your network strictly block all outbound traffic that it can't actively MITM? If not, a nefarious employee could proxy their criminal (Tor or other) traffic through an external machine that they controlled. In fact this would be the obvious thing to do as visiting an HTTPS (apparently) website on a personal device would seem much less likely to arouse suspicion.
Yes - with some exceptions (lunch break facebook/youtube etc)
Plenty did, but they were typically outgunned by the need for ecommerce transactions. Everyone had to order something with a credit card at some point.
TOR needs to find a mainstream killer-application like that, if it is to ever go beyond the current stereotypical demographic (hacktivists and criminals).
Yet, the Tor browser was recommended to protect employees from targeted attacks based on browser fingerprinting.
I'd like to hear what threat you are mitigating.