Tor is not just for anonymity (2022)
blog.pastly.net
blog.pastly.net
Live in a shitty country, want to tweet the truth without your government finding out and treating you like Assange? Just use tor, make a social network account and publish the truth!
And the reality? Every cloudflare based site first gives you a long and hard captcha. Then you try to register an account, and again, one of thoss arkose labs[0] captchas. Then after rotating the 7th image in the right orientation, you finally get your twitter/facebook/instagram/whatever account... you try make a first tweet/..., bam, your account closed, you need to verify with a phone number. You buy a disposable prepaid sim card, risk exposing yourself, and again get banned. A bunch of services even block tor exit nodes directly by IP.
Yeah, sure, you can run a hidden service, and all three users, that know how to use tor and find that address will see your writings, but reaching wide audiences is impossible.
yeah, i know it's just a rant, but it's a pain still
[0] https://old.reddit.com/r/ArkoseLabs/comments/o4ab5r/minecraf...
Tor could create their own society network but that will do nothing for people who need to reach people on those platforms.
Also there isn't really good technical solutions.
It is very hard for an individual to get out the truth against large groups and a preconditioned public opinion.
I just wonder what truths you have been attempting to divulge that are being censored.
I imagine that it's very difficult for a North Korean to discuss things openly on the Internet, and that people in less restrictive authoritarian societies need to be cautious in how they do it to avoid suspicion. Still, Americans like me do learn things about Russia and China that they would rather us not find out and discuss.
I'm not sure you can downvote a tweet, and ratioing a tweet usually increases its reach. The weird thing about Twitter is that for things to disappear they had to actively delete, or the tweeter deletes to avoid embarrassment.
All very calmly and with a superior attitude.
Some articles explaining a bit how and why:
https://blog.decred.org/2022/12/09/Trapped-in-the-Web/
https://blog.decred.org/2022/12/14/Bison-Relay-The-Sovereign...
The excuse given is that Tor is used for abuse but I really doubt that and I doubt banning the exit node IP addresses is the appropriate fix. My opinion is corporations don't want anonymous people using their site and second that blocking Tor is sold by snake oil salesmen for network products.
That's actually exactly what some folks want. To communicate privately with a small network of family/friends/colleagues. Tor does not have to be for everybody. If onion services only appeal to those people who bother to learn how to use them, then that's fine. What's important is that onion services work.
The silver lining of it being impossible to reach wide, i.e., large, audiences with onion services is that this means there is no incentive for advertising and thus no incentive for so-called "tech" companies to act as eavesdropping, centralised intermediaries under the guise of providing "free services".
Some folks might not want Google to snarf their content and try to profit from it in some way, or have Facebook offer them up as a highly specific demographic ad target.
I wouldn't call Tor a secure alternative to DNS, though. First of all, DNSSEC is easy to set up on a domain or in your DNS resolver settings if you care about such things (even if the underlying protocol is kinda shit), and second of all there's no way to know if hackernewsfjsushfoufbeldufbfof.onion is the real service or if you need to go to hackernewsfkfhfofusnsodifnekdj.onion; you can bookmark one and hope it's the official source, but it's basically TOFU for domains. You could use the special onion location header to specify the real onion address, but then you're back to trusting DNS again.
That should get you to a point where you can at least ask for a particular clarification.
That others can connect to securely. So long as you can connect to the tor network you don't need to worry about firewalls.
One criticism is that while onion addresses are secure and have authentication built in (it's kind of like if websites could be connected to by the public key of their SSL certificate) they are hard for humans to compare.
The problem is chicken and egg you have to connect over SSL using DNS to get the onion address if one is advertised.
So the first time you access it you just assume it's trust worthy. "Trust on first use" TOFU.
[0] the BBC for example advertises it's address https://www.bbcweb3hytmzhn5d532owbu6oqadra5z3ar726vq5kgwwn6a... here https://www.bbc.com/news/technology-50150981.amp but getting it requires accessing the regular website first.
That's not an issue of Tor. The same thing happens in the clear web, how do you know www.bbc.com is the BBC you trust from the TV?.
That happens to any domain, in fact, that happens to any source of information.
How did you start trusting in your current religion or politics?. Chances are that you were convinced by a source(s) that for some reason you previously decided to relied and trust.
We build some kind of web-of-trust in our heads, and it's normal that we do not trust in any .onion address initially. Eventually we import trust from sources outside of Tor that we currently trust (like you did by getting bbc's .onion address from its website), and then we start adding some .onion addresses to our "trusted sources" list
I suppose your criticism is that last step of adding that .onion address to your trusted sources is really painful. It's easy to remember www.bbc.com, but not its .onion address. We eventually need to automate this, something like password managers but for trusted sources
I do like that website can know advertise an onion address the browser can highlight.
People used to rely on Grams before it went out of business.
https://en.wikipedia.org/wiki/Grams_(search)
Or DeepDotNet
https://en.wikipedia.org/wiki/DeepDotWeb
Presumably once Reddit closed /r/darknetmarkets discussion moved to forums or probably Discord.
Back in the late 90s my local car boot sale (like a jumble sale), sometimes sold lists of websites. I never really knew what was on them but it feels a bit like what we're back to now.
With an onion site on Tor they would not be able to do so easily.
But hopefully if they were running an onion site and not any regular site, they would mention their onion address frequently on their TV channel, and that way many people would know the real address.
The most reliable solution is to type the business name into Google if you remember to skip the scam ads. Google doesn't track Tor, though.
Several websites (that are legal, legitimate in nature) get censored by tier-1 ISPs (for whatever reason) however even though they are clearnet websites, you can still view them out of country, since with TOR you can keep refreshing your routes until you get access.
an eagle screeches in the distance
https://www.clickondetroit.com/news/local/2023/03/28/do-you-...
Late at night I also get those classic spooky owl noises (great horned owl).
This is why we cannot have nice things. Ticketmaster wants to keep all the scalping on their platform and not anyone else's.
Maybe since it was official government affairs, any US ip address had to be let through no matter what.
[0] https://communitydocs.accessnow.org/147-Tor_force_exit_nodes...
> Note: even though it originally came from an acronym, Tor is not spelled "TOR". Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong.
[0] https://support.torproject.org/about/why-is-it-called-tor/
Now that the TorProject has opted to correct the record, it is too little too late. Most presentations at the time did use "TOR" and it was called the TOR router. Even they understand the acronym comes from the original onion routing project from the Naval Research Lab.
All that to say, I don't know why they would try to distance themselves from what it was, and what it still is.
Either way I don't mind, but personally I think "Tor" looks more professional, less shouty, and doesn't conflict with "top of rack" router/switch (which is a thing in datacenters). I have noticed that the Tor project is pretty protective of their brand, e.g. if you start a project including "Tor" in its name they will complain and ask you to clarify lack of affiliation.
Kinda messed up devices come preloaded with unchangeable trusted CAs
Guy knows his stuff, also works for dod.
Don't we have transparency logs to check that now?
(in memory of Douglas Adams)
It's this one. https://bugzilla.mozilla.org/show_bug.cgi?id=505521
RunSet™: Install everything everywhere all at once.
[Donate]
They don't actually go check and compare the embedded SCT with what is in the logs. It would be incredibly slow to load the site if they did that.
It's not clear to me how you know who asked for the certificate in the log. Do you somehow compile the private keys of all entities that are allowed to request certificates and compare that to the CTL?
So yeah, .onion services are secure but they're also transient. Don't try to build a community that relies on .onion links continuing to work over years.
v2 and v3 coëxisted for over three years, giving 16 months advance warning of the deprecation, ending in a four month period where support was removed from the server but the client could still connect to it.
Operators had plenty of time to upgrade their services.
It's not like you can just google an old Onion bookmark that's gone stale to get the current address.
Address longevity is especially important if you're trying to re-democratize the internet and give everyone equal opportunity to host content, not just a handful of mega corporations. In that ecosystem, it wouldn't be out of the ordinary to have 5+ year old bookmarks laying around that you haven't visited in a while but want to check out again. It's a pre-Google internet.
I don’t think there’s any reason to suspect v3 will be removed because it’s “in the way” of standard clear-web proxying. If they are removed, it’ll be because there’s an issue and a v4 is needed.
Not TOR's fault, but it is something holding it back. Sadly.
Interestingly, they allow Tor users to post. It's an anonymous imageboard with no CAPTCHA, so I'm not sure how they intend to address spam this way.
Any time I see these chan sites, it kind of stuns me about how racist they are relative to anything else on the internet.
Can't resonate. In my part of the world, people are generally racist.
People are generally awful people as well.
Still beats the toxic effects of curating identities in an social media echochamber. Dedicated boards also work as plumbing on chans.
edit: Totalitarians are also not shy about employing Zersetzung. For example, the CREST Research ("Mining the Chans") people are very open about attacking chans through AI generated garbage/extremism content to make them unusable. So chances are high that this is what you are seeing and reacting to.
Other sites use proof of work here
40 years ago there were competing protocols to DNS, its just not common to think of it that way anymore.
I realize that might come across as naive, because it's not as though they somehow know more about your abuse problems than you do, and it's also unlikely that they know something obscure about Tor that would turn out to be surprising and important for you. But they're certainly motivated to see if they can help people think of alternatives.
(I'm not actively involved with Tor right now, but I've been pretty close to the project in the past.)
all VPNs need authentication and payments, otherwise your just connecting to another open network with the same issues as TOR.
if you make payments, and then auth on connection, they "know" who you are and TOR at the start is not giving you anything
2. Not all payment methods are connected to your identity. Mullvad for example accepts cash in an envelope, or cryptocurrency payments.
Perhaps I don't know how it works, but I would just imagine they would be, since Tor seems like it's mostly geared towards increasing availability of internet resources, and that aligns with Cloudfare.
However, the definition of security seems a little narrow. Security is more than just technical personal risk. And the view that TOR increases security does not sit right.
Does TOR increase security for a single individual browsing the internet? Perhaps.
Does TOR increase security in an enterprise system? Perhaps not. The value and need for non-repudiation might be greater than the need for individual session security.
Does TOR increase security in the view of a nation? E.g. national security interests? Quite the opposite. The need for traceability might be vital, even for your individual personal security and safety (counter-terrorism and whatnot).
The blog-title is great. "Tor Is Not Just for Anonymity"! The author points out that security is a wide umbrella term. I agree! To the point that the term must be defined even wider than what is presented. And true to this: I am not stating that traceability, the need for control and non-repudiation increases security one-to-one. What is "secure" is relative.
Tor is not just for anonymity. It's also for reachability.
Tor has received significant funding from the US intelligence community through it's entire existence. If you are US aligned is Tor safe? Advocating for democracy in some war torn dictatorship? Probably. On the other hand if you are doing something that upsets US intelligence how much would you really trust Tor?
However, just because something makes sense, doesn't mean it is actually true. It is incredibly difficult to determine whether or not this stuff can be effective, even with a detailed use case. At the periphery of society, there is nothing but uncertainty.
It was written in response to someone claiming something like “Tor provides no benefit over TLS unless you want anonymity” and strives to demonstrate it provides non-anonymity security benefits beyond what TLS can do.
It discusses a very specific scenario because that’s what I was arguing about with someone. The title could’ve been better.
got a mini at home serving as an exit node
set this up one time the it dep was being obtuse about fw rules, and locked us out of ssh, so we couldn't push to gh - amateur hour; add more shadow it
> DNS hijacking is impossible. DNS is simply not used.
Sure, but now you have a new problem that tor hidden service identifiers are not really human identifiers. This makes attacks where you trick the user into going to the wrong site much easier.
Which is more likely - DNS hijacking + no TLS (or at least no HSTS) or a user being tricked into typing the wrong incomprehensible string of letters. Personally i find the latter to be the more realistic threat to the average user.
> BGP hijacking is impossible. Every interaction a Tor client has with a relay or onion service is authenticated such that you are guaranteed to be interacting with the relay/onion that you intend to be.
I dont understand. BGP attacks in order to do passive monitoring seem just as do-able for TOR, although i guess now you need to do it in two places.
Isn't bgp hijacking (if you can do it arbitrarily, which is unrealistic) basically a global passive adversary - the main thing tor famously doesn't defend against.
> There are zero places a corporate firewall can inject itself to decrypt the traffic. There are zero places and zero parties between the Tor clients that a MITM attack can be performed.
They could be the bridge. They could just spy on the client directly (usually the assumption is the corporate firewall can install stuff on your computer like custom CA certs. If push comes to shove just install spyware directly)
The main benefit tor has against corporate firewalls is it is to obscure for anyone to care.
> Do you assume the CT lookup process is secure? Are the parties you're communicating with misbehaving? Are your lookups in CT logs being logged and associated with you?
Admittedly im not super familiar with CT validation, but i was under the impression that certificates contained the SCT, which is a signature that is validated on the client and that there is no (online) CT lookup . So i dont understand - how can the CT lookup process be insecure or privacy violating if it essentially doesn't exist. All that is happening on the browser is a signature validation - no additional network requests needed.
Tor promised to address v3 addresses being much less human-readable before deactivating v2, and I look forward to them doing it.
Either way, the original has fortunately been archived:
https://web.archive.org/web/20230715011947/https://blog.past...
In my opinion, TLS itself is not secure enough to preserve anonymity because of the threat actor (ISP/gov) being able to have recordings of "when and what" is being requested in which Browser Engine on their tracked websites. They tend to scrape websites and have recordings of time differences when which assets of a website is requested, and there's differences between WebKit, Chromium, Edge, Firefox etc. in regards to CSS, HTML, images etc. also in terms of TLS fingerprints and how their TCP/UDP stack behaves.
I wish that Tor would have support for a couple more things that are necessary to really preserve privacy from the god's eye perspective of an ISP:
- Randomization of TLS fingerprint, in the sense that the order of offered ciphers in the handshake, the TCP window size etc is randomized.
- Traffic scattering (e.g. have multiple exit nodes that are selected via a ronin to request the resources from each website)
- Traffic "trailing", which inserts random amount of NULL bytes at the end (with randomized encodings, e.g. chunked encoding, gzip Transfer Encoding, etc)
- Offline cache for both HTTP/S, DNS and WS/WebRTC in the Browser, so that websites continue to work when they've been requested already. A lot of the Browser cache mechanics are useless because webservers are implementing stupid understandings of ETags which won't work with Tor due to them being connection-specific
- Cache headers have to be modified by the Tor proxy, because they can be abused for fingerprinting. ETag and Last-Modified date headers in combination with the Pragma/Cache headers can be used to uniquely re-identify Browser clients on the other end (e.g. by using a fixed datetime in the past for each new client like 1970-01-02 03:04:05).
- User-Agent headers have to be randomized and sticky to Tabs and what the website in those Tabs request, even when they're seemingly foreign domains; but even more so when those domains have a CNAME entry.
In the past I implemented a lot of the mentioned concepts into the Stealth prototype [1] which aimed to solve this by offering a local Proxy which routes/modifies/cleans network traffic and can be used by a webview that points to it (no matter whether it's a mobile or desktop one); but I had to shift focus with my efforts to cyber defense because we Europeans are getting hit by a lot of "Kremlin-loving hacker groups". At some point I wanted to revisit these ideas again, but who knows what the future holds.
I've checked Apache, nginx, and Caddy, but all of them have open issues. Chrome has the feature locked behind a flag and so does Firefox.
When it finally comes out, ECH will be great, but for now it's practically useless.
At this point it's obvious that censorship in the Internet is inevitable. So I'd prefer to reduce blast radius.
Blocking the web isn’t an economical choice and shitty countries know that.
Iran would keep the internet blocked to the level they had during the height of the protests if no one cared about economics. They don’t because it actually costs everyone.
During times of tension (e.g the protests) the cost becomes worth it.
They would've effectively made Internet inaccessible. That has political consequences, and they would have to live with that, or revise their policies around content censorship such as finding a common ground with content providers so there would be no need to block the web site.
That is what differentiates it from all the other options. There is no company behind it trying to make money by exploiting internet subscribers trying to connect with each other (not the so-called "tech" company).
Tor can have uses other than the ones normally discussed such as anonymity and evading censorship. Tor can provide reachability without use of commercial eavesdropping third party intermediaries.
For example, one can use Onion Services for advertising open IP:port information that is needed for peer-to-peer connections over other, faster peer-to-peer overlay networks, not the Tor network. The Onion Service can function as the "rendezvous" server for making peer-to-peer connection outside of Tor. Tor's Onion Services can be used to exchange IP:port information for making direct connections over the internet without using Tor. No need to use commercial third parties. Ngrok, Tailscale, etc. all require use of servers run by a commercial third party. Tor does not. There is ample free software that can establish peer-to-peer connections over the internet but in every case it requires some reachable server running this software on the internet, and for most users that means they have to run a server and pay a commercial third party for hosting. Tor has no such requirement.
Imagine being able to share content with family, friends, colleagues without the need for so-called "tech" companies^1 acting as intermediaries ("middlemen"). With a reachable IPv4 address this becomes possible. It would be nice if every home internet access subscriber received a reachable IPv4 address from their ISP. No doubt, some do. But on today's internet most do not. The so-called "tech" companies all have reachable IPv4 addresses. Hence they assume the roles of middlemen and use this position to exploit internet subscribers for profit.
Something like Tor provides a solution. Again, it is not always necessary to route all traffic over Tor. Tor can have other uses. When the goal is simply peer-to-peer connections, Onion Services can be used to bootstrap peer-to-peer overlay connections using the user's choice of software by providing a secure, reliable way to exchange IP:port information. Goal here when using Tor is not anonymity nor censorship evasion, it's reachability. Similarly, goal of peer-to-peer is not necessarily anonymity nor evading censorship either, it's bypassing commercially-motivated, eavesdropping middlemen known as "tech" companies, and avoiding the annoyances of advertising. A possible additional benefot of using Tor in this way is elevated privacy. Google, for example, cannot easily discover Onion Services. No one can discover Onion Services using ICANN DNS.
1. The term "tech" as in "tech company" means a company, usually a website, that collects data from and about people to support the sale of advertising services because advertising services are the only services the company can sell on a scale large enough to sustain a profitable business.
More reading/viewing:
https://github.com/anderspitman/awesome-tunneling
Tor Hidden Services (now called "Onion Services")
https://jamielittle.org/2016/08/28/hidden.html
As one author wrote on Github:
"onion-expose is a utility that allows one to easily create and control temporary Tor onion services.
onion-expose can be used for any sort of TCP traffic, from simple HTTP to Internet radio to Minecraft to SSH servers. It can also be used to expose individual files and allow you to request them from another computer.
Why not just use ngrok?
ngrok is nice. But it requires everything to go through a central authority (a potential security issue), and imposes artificial restrictions, such as a limit of one TCP tunnel per user. It also doesn't allow you to expose files easily (you have to set it up yourself)."
https://github.com/ethan2-0/onion-expose
As another Github contributor put it:
"With onionpipe, that service doesn't need a public IPv4 or IPv6 ingress. You can publish services with a globally-unique persistent onion address, and share access securely and privately to your own allowlist of authorized keys.
You don't need to rely on, and share your personal data with for-profit services (like Tailscale, ZeroTier, etc.) to get to it."
https://github.com/cmars/onionpipe
https://news.ycombinator.com/item?id=36734956
https://news.ycombinator.com/item?id=30445421
https://news.ycombinator.com/item?id=29929399
"Finally, onion services are private by default, meaning that users must discover these sites organically, rather than with a search engine." [Small websites with small audiences get buried by advertising-supported search engines anyway.]
https://nymity.ch/onion-services/pdf/sec18-onion-services.pd...
https://media.ccc.de/v/31c3_-_6112_-_en_-_saal_2_-_201412301...
https://wiki.termux.com/wiki/Bypassing_NAT (Termux recommends Tor over Ngrok)