WebTunnel
blog.torproject.org
blog.torproject.org
If you want to setup your own details are here: https://community.torproject.org/relay/setup/webtunnel/
I became very skeptical of the Tor project when I found out that the CEO of CMYRU (data broker /threat intelligence for governments and large corporations) was on the Tor board.
https://www.vice.com/en/article/z34jbj/tor-projects-moves-aw...
Privacy was incredibly hard 10 years ago, even harder 5 years ago, and it’s twice as hard today.
All of the sudden a solution comes out that makes it easier using what? Modern day web apps and browsers? The things that are like pulling teeth out of a pit bull to secure unless everything was diligently threat modeled from start to finish before a line of code was written?
If anyone has ever had the need to hide their IP address and be anonymous. It’s a real pain in the ass and takes a lot more OpSec then just using Tor.
This seems like it’s just opening the door for MITM attacks between the web app and the tunnel.
I’m not implying that there is a vulnerability in WebTunnels. Just that the interface (Web Applications) is riddled with vulnerabilities and now less controlled. Compared to using something like the Tor Browser. WebApps are generally not open source.
Intelligence agencies abuse vulnerabilities. CEO of Intelligence agency is on board. Not saying they will directly do anything but it’s hard to argue that the particular board member is acting in the best interest of privacy and could be swaying descsions to favor intelligence gathering
What makes you think that? Looking at the set up guide, it looks like on the server side it's just a websocket server that you add to a random path on your reverse proxy, and on the client side it's just a websocket client. I'm not sure how this is "riddled with vulnerabilities and now less controlled".
https://gitlab.torproject.org/tpo/applications/tor-browser/-...