Tor’s shadowy reputation will only end if we all use it
engadget.com
engadget.com
* If you’re concerned about the MAANGs of the world hoovering data for targeted adverts I think you’d get far more traction with aggressive privacy legislation and brutal oversight, or (and I recognize this is extreme) straight nationalization of some of their products with a mandate to operate them in the public interest like PBS or the Beeb
* If you’re concerned about an authoritarian state actor Tor was pwned years ago. TBH I think trying to win against ex. US TLAs in straight cryptography or protocol supremacy is kind of a fools errand (you’re ultimately going to get clobbered purely on the resource differential) and that the best bet is security through obscurity.
Just my 2c, maybe overly fatalistic so curious about counter views
EDIT: They do not.
(Ed corrected link to be the sentencing rather than raid)
This _inevitability_ ensures/d it never could be set up like that.
You don't seed the sites you've visited you serve _any_ site the visitor wants.
I mean.. wasn't it created by a department of the US Navy? What did everyone expect? The "white label" slapped on it years ago was that this was meant to help "Iranian dissidents" share information on the web.
The utility of this network to everyday people was never going to exist.
Lately, it's been surreptitiously fingerprinting or exploiting their Firefox fork, timing attacks (if you can see metadata all of the packets in the country or world, they can take as many hops as you choose, someone and or something can still easily line them up),
or other op-sec screwups (controversial, because what is reporterd as fatal OpSec flaws can just as easily be parallel construction finding something that would look or sound blatantly obvious in retrospect).
Definitely slower and this is a pretty minimal page, but I've got a hunch it really starts to choke when a page is loading a ton of different css/js assets at load
Visits to normal websites were only somewhat affected and were still pretty reliable.
All this stuff is on the Internet, so the Internet's decentralization is a floor that we can build further decentralization on top of.
But wouldn't a hypothetical direct data link to somewhere be faster than using the Internet to get there?
It'd be more brittle, yes. It can go down with little fault tolerance; it can't serve someone else; it can be trivially MITM'd. These are the downsides of centralization and the upsides of decentralization.
> BitTorrent is often faster than regular internet
I torrent a lot, and one thing that doesn't come to mind is "fast".
You can stream 4K movies on Netflix. I'm betting you can't do that as well with a torrent...
> I suspect TOR is slow due to intentionally long and twisty routes, added encryption, extra hops that require more processing, low numbers of exit nodes, and limited bandwidth at the exit nodes. In a way, the speed is probably partly a byproduct of TOR accidentally centralizing traffic at the scarce exit nodes.
Like with torrenting or Bitcoin or PeerTube or whatever, you've listed a bunch of extra complexity that's all corollary to the thing being decentralized and necessarily making it slower. :p
A lot more has to happen to solve a harder coordination problem. You end up using random, non-industrial grade relays. It's more complex, and it's going to be slower.
What does that buy you though? Resilience, like if a relay goes down. Flexibility, like if you wanna use a different relay to circumvent a geolock. Privacy, in that it's much harder for an adversary to monitor you. There's no free lunch for those things, though, tragically, and they're secondary/tertiary on many people's priority list.
We can’t exactly compare Netflix to an unnamed slow torrent of your choice in any fair or reasonable way given that Netflix is something like 15% of all internet traffic and is heavily optimized. The fair comparison is using BitTorrent to download a file compared to a direct http or ftp download from the original source/host - and for that BitTorrent usually wins handily in my experience. Plus I’ve definitely seen some popular torrents download much faster than anything Netflix has ever served me, in terms of bytes per second.
Depends on the torrent. Any popular "Linux ISO" can easily saturate my 1400mbps download speed so I download the UHD bluray remux whenever it's available. Videos encoded at 100mbps look at a lot better on a high dpi display compared to Netflix's 10mbps "4K" and also doesn't limit you to clients that support DRM.
The UX isn't great, but if you select the "Download in sequential order" option you can start watching a torrent in 5 seconds while it downloads in the background
There isn’t an interesting statement on Bittorrent vs internet here. Browsers just don’t make this optimization themselves, probably because most files are small, but also out of respect for the single origin server.
Don't actually take this bet.
Not decentralization, but anonymous decentralization that involves indirect routing. Decentralization can actually offset that anonymity tax somewhat by the fact that you might have multiple sources that you can request data from in parallel.
I'd want to see every computer connected to the internet turn into an exit node! It makes it infeasible to block those IPs, and also prevents people from being charged a crime for such traffic.
Depending on the jurisdiction, this may not be true. In any case it could cause punishment by forcing the exit node operator to get the runaround of the legal system.
Also it is conceivable that governments would update laws to make it illegal, if there was such an impact to NSA data collection to warrant it.
It's a nice thought and running an exit node is on my short term to do list, but I also recognize the costs associated with it and what it may mean for my family.
As it stands, it seems most people (of a certain race and class, anyway) feel more threatened by vague stories of child abductors in white vans at WalMart[1,2] or terrorists (c. 2000's generally) than being randomly victimized by our j̶u̶s̶t̶i̶c̶e̶ legal system.
Nothing to hide, nothing to fear, as they say. Abstract thought and generalization are hard, I guess.
[1] https://www.cnn.com/2019/12/04/tech/facebook-white-vans/inde...
[2] https://www.snopes.com/fact-check/white-van-facebook-hoax/
Some people are literally targeted for harassment and murder because of some aspect of their identity, journalism, or activism. This isn't a hypothetical.
Here's one example from the top of my head:
https://www.independent.co.uk/news/world/middle-east/khashog...
Tl;Dr the dissident Khashoggi was infected with NSO malware before he was murdered by the Saudi government. That's a pretty clear violation of privacy in service of something I would guess you disagree with.
This story isn't an anomaly, I think if you looked into this further you would find innumerable privacy violations which bother you.
Leaves the context of the story incomplete, otherwise.
"Not long after the Saudi journalist was killed at the Saudi consulate in Istanbul, the CIA assessed with high confidence that MBS had personally ordered the killing, but intelligence officials never spoke publicly or presented evidence."
How many journalists get their deaths investigated at all, let alone laid at the door of a...whatever you want to call their government, and what it is to the US'.
Not part of human nature. Save the children/Rethoric is embedded. Reflexive thinking has variying energy requirements and for most requires external kickstart, when possible at all
Forcing tor in all new network adapters is more feasible, which is saying much.
This is ahistorical. Childrens' rights are a late-19th Century creation. We have become child worshipers, we are not naturally child worshipers.
There's a quasi-Christian doctrine that states that children are born virtually unstained, and that being unstained makes you more deserving of life. As you grow older, you are stained by the demands of the world, which makes you less deserving of life. However, the idea that a child's life is more important than an adult's life would seem moronic to people much before the 20th Century. It just takes 6 years to make a 5 year-old. It takes 51 years to make a 50 year-old. 5 year olds know almost nothing, and need to be taken care of. Every 50 year-old has a bunch of knowledge that can't be recovered, and generally can take care of themselves.
You know we used to send them into the mines... and we used to value them because of how deeply they could get their little hands into factory machinery.
I’m not worried about clowns in white vans or terrorists. If you want protection from the government, you need to advocate for protection under the law. Journalists, NGO workers, etc have to figure out how to manage risk and may need to self-censor to avoid those risks. Tor won’t protect you if you irritate MBS.
But if a government is already crawling up your ass, it won't help much.
E.g, once you're not anonymous, anonymization tools don't help much.
There is active targeted surveillance by a nation state. Tor is not going to help you. No crypto or tech alone will help you, you’ll need to develop extreme opsec practices to stand even a remote chance against a well funded and well equipped adversary focusing on targeting you.
Then there is passive mass surveillance, i.e. the presidential surveillance program, which Tor/VPNs/HTTPS etc will absolutely help with.
I wrote a blog post on tactical privacy a while back that I think is still relevant: https://everytwoyears.org/2020/07/13/tactical-privacy.html
Doxxing/blackmail protection.
If a few people collude to secure moderator positions at different sites and each gains access to IP logs (or someone just bruteforces/exploits the site and dumps logs), anybody can be outed across those sites-- the adversary has effectively compromised the server and can map page accesses directly to your IP.
They don't break HTTPS, they break the weaker link-- the trust of the server owner.
The next step is gaining access to the VPN provider's logs (they don't keep any, right? Right?). They all keep logs. Even if they say they don't, assume they do. Nobody is held accountable for lying about it.
Again, not breaking HTTPS, but breaking the weaker link-- an unscrupulous VPN owner already exploiting the trust of you, the customer.
Tor is the only "safe" way to be anonymous, but even that is dead through fingerprinting, gatekeeping and forced Javascript enabling.
The story’s walls are closing in on cracking down on cryptographic guarantees of privacy, network access, and information sharing.
That said ... paying electronically is so convenient, damn it.
(haven't been to Germany)
For debts. Steal it, get caught, be ordered to pay restitution. Then your legal tender argument will make sense.
https://www.law.cornell.edu/wex/legal_tender
Various laws may exist elsewhere enforcing a requirement to accept cash (or not, depending on the jurisdiction). But an appeal to "legal tender" isn't going to cut it. Legal tender for what? For debt.
In most other regular shops on the other hand, you'll only enter into the actual contract the moment you pay for the goods, so unless your jurisdiction has a specific law mandating the acceptance of cash in that kind of situation (like e.g. New York city I think?), the merchant is perfectly free to simply refuse entering into a contract with you.
[1] With the caveat that depending on the jurisdiction the shop owner may fully legally put up a sign along the lines of "No cash payment" and in that case it's you who are in breach of contract in the first point. Maybe if you then get sued for non-payment you can pay cash through the court system, but that certainly wouldn't be a pleasant way of paying by cash.
Yes, but the interpretation is that you picking up a bottle of milk or whatever in a supermarket or elsewhere doesn't yet make a contract and that the goods haven't actually legally changed hands at that point.
It's only when you're presenting your chosen goods at the register that you're legally making an offer to buy those goods, and unless there's a law specifically mandating cash acceptance for shops, the merchant (as represented by the cashier or a self-service checkout machine) is free to simply refuse your contract offer. And because in that case no contract was ever successfully made, there's no debt, either, and the concept of legal tender doesn't even enter into it…
Germans have a certain paranoia. I understand where it comes from but how are you ever going to move on if you hold these beliefs so tightly?
In some ways we're already seeing the foreshadowing of this in some of the previously most liberal places on Earth, like Canada. Even if one may not agree with what the truckers were protesting about, it seems unconscionable to freeze people's bank accounts as punishment for engaging in, or supporting, a completely and genuinely peaceful protest. [1]
[1] - https://fortune.com/2022/02/16/trudeau-freeze-freedom-convoy...
Japan though, now there's a place where cash only shops are still prevalent.
We were hitting cash only places all the time there, whereas in Germany I found that cash only became rare during the pandemic.
Hell, even recharging the IC cards in Japan had to be done using cash at a machine. Why can't you use a debit card? Who knows.
I love it. I drove to Germany to have the maintenance done, change the tires and renew the extended manufacturer warranty for two years on my german car (extended warranty which I need to pay for) and it was a hefty bill. I pulled a bit more than 3 000 EUR in cash and they were just used to it. As in: a totally normal occurrence.
I did it basically to test if it was true that cash was king in Germany: I had credit and debit cards in backup just in case. But cash just worked.
The stores are getting wiser about this. My local Fred Meyer (a Kroger brand now) has a fuel rewards program -- for every $100 you spend, you get 10 cents off per gallon on your next fillup. Given how expensive groceries are, a lot of people are saving more like 50 cents per gallon, not 4.
They've also started doing instant discounts at the register, which was something that Safeway aggressively did from the beginning. FM isn't quite that aggressive yet, but when I scan the shopper card just before paying, it isn't unusual for it to knock $20-30 off a $150 purchase.
If it really were just 4 cents a gallon, I expect less people would bother. But it's not. The stores are steadily increasing the penalty for shopping without a loyalty card.
It's a shitty psychological trick that Fred Meyer pulled off.
People think shopper cards save money, and while it's technically true, it's the wrong framing of what's happening. What's really happening is that the store requires the card to get sale prices.
In other words, Fred Meyer creating the shopper card did not create additional savings. It just started gatekeeping sales behind data collection.
Or another one: when you use a savings card, you trade some of your data for a couple bucks off.
(While on that note: in many countries – pretty much everywhere I've been, actually – you can just get a new savings card every couple months, or get a few and round-robin them and replace every couple months etc. Just fill out the sign up form with some garbage data and you're good to go.)
So what are they doing with the loyalty card data? Nothing? Is it all just a mental trick to get me not to go elsewhere?
Also if they were thinking they could have bluetooth beacons at the registers to track cash users that have bluetooth enabled.
Also they have cameras looking at every checkout line. They implemented them originally to observe when lines got too backed up so they could automate sending out more cashiers. They could move to facial recognition of they really wanted. Not sure if they do that now.
Since the register already priced my bill higher at the time I swiped my card and then dropped the price, I have to assume it's the former.
Everyone should know how to use Tor, but we shouldn't have to, at least not all the time.
People's data is being farmed and their identity leaked and sold on the dark web, and they're probably not educated enough to care. That's what you want to preserve?
You mean, after it's sold and resold by the likes of facebook or google in open transactions?
It weirds me out any time I open YouTube on the TV and the first thing I see is an ad related to some recent online purchase, however obscure.
The existence of crime is not an example of the need for anonymity.
Normal people don’t care if their metrics are being tracked - that is happening to practically everybody all day every day, and very few people are experiencing any direct and measurable negative consequences. In their defence, why should they weigh the hypothetical-risk above the real-benefits of giving up privacy (ie, convenience and price)?
I believe if the message of privacy advocates is to have any effect at all on normal people, we really need to start focussing on things that normal people care about, not hypothetical and philosophical arguments
* Firefox ESR -- For sites that are necessarily linked to my identity, such as HN and shopping. Sometimes this also gets sites that don't have to be linked to me, such as if I'm too lazy to copy&paste a link from HN into Tor Browser. (Keyboard switching/starting: Mod+F)
* Tor Browser -- Almost everything else. This is the bulk of my traffic, and innocuous, not "he just switched to Tor Browser, so must be doing something interesting". (Keyboard switching/starting: Mod+W)
* Chromium -- This is my total subjugation browser, used when more-private&secure options fail for something I really need/want to access. No ad blockers, but some awful DRM enabled. Current used only for one obnoxious video streaming service. I would like to get rid of this browser entirely. (Keyboard starting intentionally discouraging: Mod+P C H R O M Enter)
My vintage laptop can handle all 3 at once, just fine. Though I usually make them short-lived -- to reduce clutter, free compute resources, and clear trackers.
That's the personal laptop. My work laptops will partition browser use differently, such as for whatever the current Web development needs, and keeping all-day corporate SaaSes (e.g., GitLab, and mandated Web apps) open in one browser, while making another browser for short-lived public Web browsing sessions.
There's also a place for Tor Browser on the work laptop, for public browsing about topics that you don't want to hypothetically leak to competitors, but some companies will flip out if they detect Tor on the corporate network.
Nobody that’s not halfway suicidal is running exit nodes on their home machines (I won’t, I don’t want police knocking on my door).
And just for the onionspace… yeah I saw some bad stuff there. After what I saw I don’t think anonymity is a good idea. There is darkness inside people that lack of rules, lack of order, lack of accountability brings out.
In the end Toe is just a legacy project from the CIA/NSA that has outlived it's usefulness. The NSA has certainly redteamed all the ways to take it down or uncloak users, if needs be, so it's not even a tool against a potential fall into dictatorship of the USA.
Actually, this isn't true: Tor with private Snowflake bridges can be very effective against the Great Firewall. I'm an activist who works in this area and I've spoken with activists who were using it as recently as this year.
The issue is scaling bridge discovery, since any automated bridge discovery mechanism rapidly exposes available bridges to a determined censor. But any team doing high profile, notable, or sensitive work can find an individual or organization outside China to provide them with private bridges. So Tor is one effective option now for key activists in China, just not a mass-scale solution for everyone.
And as others have pointed out, Tor wouldn't scale if everyone was using it. Contrast this with I2P which not only would scale but become more resistant to DDOS attacks with the more nodes on the network. Unlike For, I2P has no distinction between nodes, mostly because it's not designed to be an outproxy. But no, let's keep insisting that everyone use a deep state tool with chronic flaws because reasons. /s
One objection a lot of people in this thread have to using Tor is the (misconception) that they'll be relaying Tor traffic. (It doesn't work this way in Tor.) But what you're saying is that i2p will scale because this is the default behavior in i2p. But is that what people want?
Also, hidden services have been harder for Tor to scale than exit nodes, at least in the past few years. I don't think this is the result of the fact that Tor provides exit nodes. I think it's just a result of the onion service connection process being a series of fragile steps.
I do agree that supporting traffic to the web results in the Tor dev team prioritizing this use case over traffic to hidden services, but that's understandable given that it's the vast majority of their traffic and usage.
Um. I'm pretty sure that nodes relaying Tor traffic is the fundamental principle underlying Tor.
Everyone relays Tor traffic when using it.
This should be assumed. So what?
In 2023, almost every website supports https and unencrypted traffic is the exception, not the rule. So if someone sets up an exit node, they can only collect metadata from a few circuits from a competent user. Of course, this becomes a problem when someone sets up hundreds or thousands of nodes, but that - including statistical analysis or the use of 0-days - can only be done by a small minority.
This extends to social networking too. As much angst as there is about moderation, it’s a feature people want.
Maybe, but it's nothing in comparison the darkness that comes out of people who want rules and someone held accountable.
This is a somewhat one-sided way of thinking.
Tor is a tool that can be used for useful things as well as misused for bad things (like a knife or a truck). Now, leaving aside the fact that websites related to credit card fraud, child pornography, and terrorism also have a large presence on the Clearweb.
Also, I'd like to note that Instagram is a global hub for human trafficking, and the moderators' stories don't sound any more innocuous than the Onion stories.
I use Tor daily and abide by the law, but don't want to miss the anonymity or pseudonymity of a Whonix VM and a Tails session.
Since I've been hosting Tor Nodes since I was 14, I don't have to worry about showing up on blacklists of 3-letter organizations, since I've been on top for over a decade anyway.
But anyway, to answer your question: mustard gas is not one thing, it's a class of chemicals. But one of them became the first ever chemotherapy drugs, Mustine:
Honest question: why do people host exit nodes when they aren't 14 anymore?
Given how dangerous it is to host one, and how little personal benefit one gets from it, I kinda assumed most exit nodes are hosted by three-letter agencies from various countries. Is that so? If not, how so?
Any ideas for how to eradicate it without authoritarianism?
I have yet to find something which lets you get a good peek at that data. Does anyone know of anything?
I had a look when I went in there a few years ago to disable all their collection and they basically know every website you go to.
You can see something similar with your Google ads profile, but only if you have personalized ads on. (I am sure they still have the profile on you, you just can't view it)
You don't need Tor to avoid advertisers. Blocking all cookies and browsing in private mode will get you 99% of the way there. Throw in an ad-blocking VPN and there's basically nothing anyone can know about you that you aren't explicitly sharing.
A VPN that has multiple users using the same IP simultaneously can help on this front, but I don't know how common this is? Basically emulating how Tor exit nodes work. Though even that is also almost certainly possible to break.
If cloud flare is silent, they know who you are.
Chrome feels a lot faster than Firefox to me (Especially on Facebook!), yet I still use Firefox to resist Google's stranglehold on the web.
Hope you trust Mozilla with that same level of info (in twenty years)!
Misleading way to say more APIs, I presume?
Can you imagine google chrome bringing Tor integration into their browser? Why not?
So I think the answer to question is - absolutely nothing. The very few missteps Brave has made get broadcast from the ends of the world. The fact the biggest thing people can find to complain about it is some crypto stuff, which is opt-in and easily completely disabled, or an autocomplete tagging a referrer - that was patched out in less than 24 hours, is strongly indicative of the quality and integrity of the browser.
That functionality (which would modify some literal URLs typed in by users, not just make autocomplete suggestions!) was present in the source repository for roughly a month and a half until it was disabled by default, and remained present as an option for over a year after that.
https://github.com/brave/brave-core/commits/master/component...
You may mean that it was modified less than 24 hours after users noticed it and raised an outcry, but that still doesn't exactly inspire confidence.
Further, there is no way to pre-emptively disable the cryptocoin elements on new profiles on the same Brave installation.
- Part of the protection Tor provides is due to having the single browser made specifically for Tor. Nearly everyone uses it; this gives you a sufficiently large crowd to blend into. There are fingerprintable clusters inside this crowd, but at least they are still large enough. By using any other browser, you make yourself stand out and even diminish the anonymity of the whole network a tiny bit. This can become a problem if enough people are using custom browsers. Brave in particular is also not restricted enough by default (no JS etc). Default settings for everyone matter.
- Brave's Tor feature wasn't thoroughly tested in real situations. AFAIK they had issues with it, and also warned users not to rely on it as it's not complete.
While I'm in agreeance with everything you've said it should be pointed out that Tor Browser doesn't ship with JS disabled either, it simply breaks so much of the web that they've concluded it's not reasonable for a browser to do by default if they want to attract new users.
Meanwhile, we know for certain that Firefox has played a role in multiple deanonymizations.
The people on KiwiFarms are actively harmful and engage in illegal harassment activities.
Well then why haven't they been prosecuted?
Not even wikipedia own founder believes on it anymore. It's essentially useless for anything political related because you already know that they will be heavily biased in favor of a given side...
https://www.independent.co.uk/news/world/americas/us-politic...
Sure, you're hidden, but you're also in with a lot of stuff you don't want to be in with and that can come with legal liabilities and ethical issues that I don't feel qualified to mitigate. And as other people have pointed out maybe the government or your least favourite company actually has a camera in the bin you chose to hide in.
This is not the case, unless you explicitly set up a relay node or volunteer to run a Snowflake bridge.
True, you're mixed in with other users from the point of view of websites that might treat you as spam, say. But you aren't taking on any liability unless you run an exit node, and even that is fairly well-established as safe in at least some jurisdictions.
I know there are deep fundamental technical differences, but I could see an outcome where the end result is the same across both services. I'm not trying to justify to use tor as well, just that I don't think the argument of guilt through incorrect association is solved by not using tor.
Just morality-lacking trash, at best.
You may not _lose_ but you may find yourself with your life seriously disrupted.
Quite a lot of serious projects in this space are US-government funded.
OTF does somewhat focus on needs in regions that are geopolitical priorities for the US, but since most of these projects (like Signal or Wireguard) are building general purpose tools, it seems pretty good for the world overall and not nefarious. Germany recently started a similar fund and hopefully more countries will too! [2]
(I know people involved in both OTF and Sovereign Tech Fund I work with a user researcher who's funded by a small grant from OTF on my project Quiet.[3])
One funny historical note is that OTF grew out of Radio Free Asia, a program started after the Tiananmen Square massacre to broadcast AM, satellite and shortwave pro-democracy propaganda in Mandarin into China.[4] So the mission of funding general purpose anti-censorship and privacy tools kinda makes sense!
1. https://www.opentech.fund/results/supported-projects/
2. https://sovereigntechfund.de/en/
4. https://www.opentech.fund/about/our-history/ & https://en.wikipedia.org/wiki/Radio_Free_Asia
The other downside would be how trying to be secret can shine a spotlight - kind of like the bomb threat at that school (I’m forgetting the name). The student used Tor, but was quickly identified… because nobody else on the school network used Tor. (Make no mistake - I’m glad the student was caught - I’m just taking about how trying to increase your privacy can backfire.)
I think these and other rebuttals fall into the category of completely logical arguments that should, but won't, convince a non-tech-savvy judge or jury.
In the US, at least, juries are generally less sophisticated than a random sample of the general public; anyone who displays significant world knowledge or critical thinking during jury selection will be removed.
Most jurors are gainfully employed in stable jobs, or were but are now retired, and care enough about their civic responsibilities not to try to get out of jury duty.
Usually people "too knowledgeable" get bumped from the pool.
No, never. The defense never wants a hung jury, because the prosecution will just get another chance to have another jury trial, with a new jury, but having learned from the failure of the first trial. The defense always wants finality.
Prosecutions don't want hung juries either, because there is always the risk that the judge will either dismiss the charges (if more than half of the jury leaned toward the defense) or pressure prosecutors to offer a better plea deal to avoid wasting time on a new trial.
Usually people "too knowledgeable" get bumped from the pool
If by that you mean people who know too much about the case already, then yes, because the defendant deserves a fair trial. If you mean people who are "too knowledgeable" in general, then no, unless it's clear that they're going to take this "knowledge" and rely on that "knowledge" instead of what is presented to them in court. Lawyers generally try to exclude tech bros, because they think they know everything about criminal law based on watching a few episodes of Law & Order and CSI.
https://www.theverge.com/2023/7/24/23806093/mastodon-csam-st...
Except that the law has come to terms (outside the UK) with the possibility of peaceful knife ownership, whereas the law around Tor and such things is still in the "probably non-technically savvy judge has heard scary terms around Tor and wants to be on the safe side" stage.
but it is indeed a problem, and mastodon mirrors all remote content that is in your federation network and now you have csam splattered across the connections of mastos w only blacklists if entire instances to recourse.
its a bad approach but they've buried head in the sand years ago. things like pleroma do not do this by default
On Japan and nudity, I know some of it it's being used not as sexualization, but as a hard prank (Takeshi's Castle, hidden camera pranks on toilets with falling walls, nudity jokes at Doraemon/Crayon Shin Chan, Dragon Ball and Bulma...), but for sure in this case didn't have an intention to ridicule anyone.
Akibahara had a mall where on a single flat there were magazines were displaying illegal nudity as if they were used as a sports magazine or something like that. Creepy stuff. It seems the Japanese people are sexually represend in their teens so they can hyperfocus at school over anything else but then this creates "sexually disabled" adults with lots of troubles on relationships and a hard lack of teenage discoveries.
Privacy is good even when you have nothing to hide, but it is imperative for those who do need to be hidden. The ethical issues I generally see people concerned with are ethical issues with privacy itself, not a specific implementation.
Heliocentrism, democracy, etc.
Without some degree of freedom to violate the majority's morality (or even one's parents' morality!) without judgement, we should expect society to stagnate due to arbitrary lock-in of the status quo on any sufficiently controversial issue.
Privacy is great because it lets groups violate the majority's morality invisibly, without flagrantly disrupting the sense the majority has of there being a moral order.
Privacy gives you the upside of social innovation without the downside of a generalized, diminished belief in the morality of others (which can be a downward spiral for societal self-organization.)
How do you convince a company to intentionally stand up an onion site that provides any real value? You lose the ability to apply some defensive controls to thwart attack, you're associating your brand with something identified as 'shadowy', and most customers won't use Tor or even understand what an onion site is. If a company is unwilling to justify the effort or take the chance on standing up a hidden service, why would they be willing to take a similar risk of abuse by allowing traffic sourced from the Tor network?
1. Follow published links with a crawler
2. Host an exit node and observe where traffic goes
That said, that was enlightening, thank you for pointing this out. It's disgusting that there are companies selling this.
Consistent visitor ID over months or years, even as browsers are upgraded.
This advertisement implies some things that could potentially be illegal, but I don't think that practice is by itself. Stalking as a service really gives Saas a new meaning .
This one overestimates uniqueness because it doesn't consider stability (e.g. it uses your current battery charge level as a uniqueness measure, which is obviously not stable minute-to-minute let alone day-to-day).
Also, while you should always assume your traffic is open to inspection/modification before it reaches its destination, this is more likely to happen with tor, not less likely. The Tor browser does help here, by not easily allowing obvious mistakes like using http.
>There are sites that I have been unable to get working
This happens, most of the time because of Cloudflare. A solution is to get a new Tor circuit 3-5 times, and then the page will load. If a site simply won't work, like Meta platforms I won't use them. Using alternative front-ends[1] makes most sites that usually wouldn't work, work as well.
>The Tor browser does help here, by not easily allowing obvious mistakes like using http.
This is false, HTTPS only is enabled by default in Tor Browser. It's common knowledge for everyone including users of Google Chrome and Firefox to not use HTTP sites.
> This is false, HTTPS only is enabled by default in Tor Browser
I think you misread me. I said the Tor browser does help here.
My bad, you're right! That shows my bias when it comes to this topic, way too much FUD.
Some services block Tor. Sometimes they can be bypassed by pressing "New Tor circuit for this site" a few times, sometimes they cannot. Some of the methods listed here [0] can help (though I wouldn't log into any accounts using this as TLS isn't being terminated at your machine).
Some features don't work in Tor Browser, off the top off my head, sites using AudioContext, Webauthn, Webassembly. (webassembly can be a pain due to some encrypted paste bin sites using it).
I run multiple instances of Tor Browser (separated with Linux namespaces, particularly netns because Tor Browser will fail to load if an existing Tor service is running at port 9150) so that I can multitask between for example posting this on HN and random browsing in another instance. That also helps with the webassembly thing as I run a script to spin up a temporary instance of Tor Browser, enable webassembly in about:config, and load the failing page.
For the sites that block Tor that I need to login to or that don't work with the ad-hoc methods listed above, I will fallback to using a VPN + an about:config-modified version of Tor Browser that has the Tor proxy disabled. Mullvad Browser can also be used as an alternative.
I also use it outside of TB for IRC among other things. You have to be careful as there is no uniform configuration for everyone like TB.
0: https://gitlab.torproject.org/legacy/trac/-/wikis/org/doc/Li...
Did you forget to read the article? They make the point that this is not the case. Tor Browser can be used to access most of the web besides aggressively anti-privacy platforms like Meta.
If you choose to go on a "Dark Web Search Engine" and that's what you find, that's entirely your decision and not something you would stumble upon.
>but normal people aren't going to put up with that. Nobody wants to see that stuff.
They would never see that stuff by accident, as they never do right now.
This could be an alternative to some of the instant messaging systems that provide privacy but not anonymity.
I know that some chat messaging systems can use Tor as the transport, but they have problems of their own.
What I'm thinking about is something along the lines that each user app hosts a hidden service that receives messages through a standard HTTP API. Users need to hand their hidden service address to friends. The protocol itself already handles payload encryption and routing but messages could be further encrypted at the app level before being sent (using the other user's public key once an initial exchange has been done).
Granted, sending a message would require all parties to be online at the same time, but there could be a set of relay servers to hold messages until they get fetched.
I'm sure there are lots of hairy issues to take into account, but I would expect the existing protocol to mitigate some of these compared to a ground-up approach (like Session is doing). Tor is fairly mature and, despite all attacks on its infrastructure and protocol, it is still standing.
I'm also wondering if such a messaging system couldn't be useful for some IoT types of scenarios, as it would protect the location and communication of the source of the data, so the devices could not be easily physically found and hacked.
None of this would be useful for high-bandwidth real-time data, but you can get reasonable latencies and traffic sent this way.
Maybe it's all just a dumb idea...
Ricochet was a big inspiration for my project Quiet.[3]
Cwtch also deserves a mention, though it depends on ephemeral servers and isn't fully p2p. Briar is another and frequently comes up on HN. [4][5]
1. https://en.wikipedia.org/wiki/Ricochet_(software)
https://github.com/TryQuiet/quiet/#readme
> Granted, sending a message would require all parties to be online at the same time, but there could be a set of relay servers to hold messages until they get fetched.
We actually do a bit better than this! We use a gossip network (libp2p gossipsub) so all peers don't have to connect directly, and a CRDT over a private IPFS network so that everyone in a community eventually syncs all messages. As long as there's a continuity of online peers, the availability of messages is the same as a central server, and with a few Android users in the mix it's pretty easy to get to that level of continuity.
(The battery impact of staying connected all the time on Android isn't as bad as you'd think, and we haven't even begun to optimize it.)
And yes, it builds on the maturity of Tor rather than trying to roll its own onion routing layer as Session is doing. Quiet is still a work in progress, but we've been dogfooding the desktop app for over a yearn now as our main team chat, and the Android app for a little less than that. We're working on iOS now, which is... tricky. But we're hopeful.
Ironically, anonimity here stops terror and helps innocent people. Any terror.
We agree it would be a very bad fit to use the torrent protocol over Tor, a seedbox would be better for your purposes.
a seedbox would be better for your purposes.
A seedbox would suit my torrenting needs but it doesn't fulfil the additional roles of bypassing video stream throttling on my mobile network or letting my overseas friends bypass network censorship.
Tor gained a lot of popularity after the Snowden revelations. We would need several Snowden-like leaks over the coming years to ramp Tor usage up substantially. And then there's no way of knowing how Tor would scale to support a new influx of users, year-on-year.
But I agree with Patil, the more people that use it, the better. If we could just shake the stigma that Tor = crimeware then that would be great.
IMHO, financial incentives for relay and exit operators is the best way to make sure more people without ulterior motives participate.
Personally for me it is about the traffic that may be routed through my computer by the Tor network - I definitely do not want child porn, drugs or terrorist related site transactions packets to even touch my computer. It maybe a rare occurrence, but I want certainty. If we could control the traffic that is allowed on our network / computer, I'd be a more willing user of Tor. (A use case example would be to allow a Tor user to create a white list of onion sites from which they would be willing to accept traffic).
Not only that, but TOR is something that becomes more private the more someone uses it. Iirc it's really easy to distinguish TOR packets from regular packets. Combine that with how few people use TOR, you're job of narrowing down who's abusing it becomes much easier.
Finally, just running an exit node opens one up to many legal liabilities. It's not something that's worth the effort, but it's strength comes from many people running one.
No traffic is routed through your computer by using Tor, running a relay is a completely separate thing that can't be done by accident.
Use services that respect your freedom. Hacker News works just fine using Tor Browser. ;)
Hypothetically, if the USG wanted to produce "official" backdoored TOR clients (e.g. only served as prebuilt downloads to IPs geolocated in Iran, etc to make detection difficult), they are in an excellent position to influence that work. And as the story of Julian Assange makes clear, that should concern anyone who purports to care about privacy, human rights, etc.
That includes being selective about who you allow to have an account.
Would love a reputation service that correlates IPs and/or email addresses to the amount time users spend on Facebook. I'm sure this data is out there and purchaseable, to be honest.
When the phone went into power saving mode, tor closed and lost my place. And since it doesn't keep local browsing history, I was back to square one.
Honestly though, Tor is not the solution for a lot of people. If you're just going for good enough there are other alternatives, if you're already under heat from a big enough actor you are screwed whatever you use.
We need a new solution.
No, I tried building normal websites and community on tor for 10 years. Then the tor porject wiped it out for potential future security. They will always prioritize the needs of the people who really need privacy over us. And that's fine. But I will not make the mistake of building on tor again.
Tor definitely has a commitment to people building communities using hidden services, but they also have a commitment to your community members' expectations of security, no?
1. https://support.torproject.org/onionservices/v2-deprecation/
As for fundementally insecure, yeah, in a few years maybe by spending $10k you could brute force a hash and take over a domain. So they killed it entirely to protect the people that need absolute privacy and security. They could've left v2 alongside v3 and let people choose but the tor project considers that too risky for their prized use case.
Those of us just using tor for owning our own domains were not important in comparison. That "not being important" will continue. Shadowy users are what tor cares about. Not open communities. Tor is great for pseudo-privacy. It is not great for people wanting to make normal sites on it.
I don't really understand the threat model that would make Tor helpful here.
Then you should probably stop using the web altogether.
I'm seriously confused how using Tor places you closer to "illegal stuff" then browsing as you do? Could you clarify?
Even if we're going to draw the distinction between .onion sites and the plain web (and there's nothing about Tor that requires you to visit or interact with .onion sites) I'm nearly certain that there are many orders of magnitude more "illegal stuff" being shared on traditional websites than the "dark web". Plenty of drugs are purchased through Venmo, and Tumblr and Twitter have had pretty high incidents of child exploitation materials being shared on there (and, despite having been a heavy user of those sites at some point, never came across any content close to that).
My experience has been that, barring 4chan 10 years ago, it is extremely rare that you'll ever come across any "illegal stuff" unless you are looking for it.
Road B: Takes 2 hours, chance of getting robbed is 2%.
Fixed it.
No, using Tor is equivalent to holding up a sign to the spooks "Hey, over here! Look at me!"
Right now it has a shadowy reputation because the only people who require that feature are criminals. A few of those are committing crimes against unjust laws, but they are badly outnumbered by widely-disapproved-of behavior.
The anonymity comes with a cost. Tracking makes for a smoother web experience for most people.
So it's a hard sell to say, "Hey, you should do this thing that makes your life harder, in order to help disguise criminals". There's good reason to think that ordinary people should take better care of their privacy, even if they don't realize it, but I don't think that they're itching to apply a technology that has a "shadowy reputation" for a reason.
Most of us don't live in authoritarian regimes where something as silly as saying the king looks like an idiot is a crime
Also, deities: https://en.m.wikipedia.org/wiki/Blasphemy_law
I think all communication and activity should be anonymous to companies, somewhat visible to your inner circle, and able to be exposed to authorities only when they have something akin to a warrant. That sounds hard to achieve in practice, but Tor is not the answer to any of it.
What stops companies from using various fingerprinting techniques to continue to track me online? Does Tor stop JavaScript running client side?
So you agree that Tor is not the answer to preventing corporate invasion of privacy. As I said, Tor isn’t the answer to any of the true challenges. Balancing accountability and privacy. Allowing law enforcement to be effective. Preventing large corporations from abusing tracking.
Those things do actually matter, but they aren’t technical problems inherently, they’re people problems. Technology comes into the mix as part of the solution, but Tor does not factor.
In the government space, I think permission should be required from the individual to share information between departments, and the data to again be owned by the individual.
How does Tor do anything meaningful about allowing me to both participate in society, and preserve my privacy and data ownership? This is not a technology problem.
I can't speak for your specific situation, but I'll give you an example. In Australia we have mandatory data retention laws. If you don't think private companies (that are exposed to data breaches [1]) should have access to your activity then Tor is the solution to that. That's a more practical solution than waiting for legislation which may never come.
https://www.optus.com.au/about/media-centre/media-releases/2...
Practically everything I do on the web involves authentication and a login and an identity. They're all US-based services. It's stuff that I use to manage my household, and finances. It's also social media stuff; some of it's pseudonymous, but I've got Facebook too.
These services factor in security hints such as device fingerprinting, and a consistent local IP address that belongs to an ISP account I pay for. That's as safe as it gets in this modern digital jungle.
I also use Chrome. I don't use Firefox. Don't try to get me using Firefox; it's incompatible with my workflow. I don't even have it installed to debug website errors. I also own a Chromebook and I do a lot on the Chromebook. 100% of my employment relies on it, and 20% of my personal use is there, too. TOR isn't compatible with ChromeOS (prove me wrong.)
The #1 error of TOR users is that they eventually reveal themselves online, by authenticating to some service, or by going to haunt specific websites or URLs they like. This is similar to people in Witness Protection or abuse victims who run away: they eventually contact family or friends and reveal personal details, and then they're re-victimized.
Sorry TOR, you're not for me.
If you reveal yourself by logging today none of your other sessions from yesterday or tomorrow will be revealed or connected.
It seems futile to use Tor when the OS itself is made by a notorious spyware vendor. But there are Tor browsers for Android that should work.
So, like, Windows 10?
Tracked by whom? Anyone? Is it OK if your parents track you? Does your government have a direct involvement in, say, public city streets?
Is this about technological tracking? What if you walk through a forest, and some stranger comes up behind your path, and uses natural evidence to find out something about you, and which way you went? How would you prevent that?
Please tell us what sites you worked on so we Firefox users can avoid using them :)
Or they're so bad they wouldn't even load the entry page in FF?
The only One who is in power will judge me justly, and I eagerly anticipate that with joy and thanksgiving.
How about using HN to make this comment? Even if you use your real name for it, you add some traffic to Tor, which helps.