However, some things, like Tor, can make your use of the Internet safer.
If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.
However, some things, like Tor, can make your use of the Internet safer.
If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.
When people say they're distrustful of Tor (for various reasons) to the extent they refuse to use it, they seldom suggest alternative tools/measures that provide anywhere near the level of safety offered by Tor.
Functional security means understanding your risks, and using privacy tools is a risk - in the sense that it does single you out in the current environment.
Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.
Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.
Pigs have significantly higher density than birds and lack wings. Getting them to fly under their own power would be quite a challenge. By contrast, installing Tor Browser is actually pretty easy.
> Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.
In general this is not what happens in e.g. the United States. The act of installing or using Tor doesn't in and of itself cause anyone to beat you with a wrench. Try it. Visit HN using Tor Browser. No one comes in the night to put a bag over your head.
> Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.
If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.
If you live in a country that has a modicum of respect for fundamental rights like privacy and due process, then you can use Tor when you're not breaking any laws and are just trying to avoid being tracked across the internet by Google and Facebook, because using Tor isn't in itself illegal. And doing this not only benefits you, it benefits the people in the first group who need it even more than you do, because it makes them stand out less.
So who are the people who shouldn't be using it?
HN used to often not create new user accounts when connecting from Tor.
Twitter doesn't let a new user account to pass the prove you're human AI challenge. It says it passes but then shows an error message that there was a technical issue.
By using Tor I'm cut off from Twitter. Twitter is my social media of choice. By using Tor I'm cut off from social media.
The reason tor traffic is often denied is because it's hard to block or track "the same" tor use, and some people used to abuse this to perform actions that the platform does not want.
You cannot really have true privacy, and also have moderation of content.
Consider this: just like fraud, the ideal amount of it in any purportedly liberal civilization is non-zero, because the freedom from which is derived the opportunity to engage in the behavior is more important than perfect attribution, detectability, and prosecubility of it.
People don't realize that when you set goals of zero'ing out these sorts of things, you're throwing the baby out with the bathwater.
My statement is pretty clear - using a privacy tool can single you out. Am I afraid of that in the US? Nope, not really.
Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.
> If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.
You know a clear way to avoid this risk entirely? Don't trust your communications to a public network. Is TOR better than posting directly online? probably. Is TOR still a risk? Obviously yes. Understanding your risks is important, and simply saying "Use it anyways" is not an appropriate answer. Like... at all.
Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.
> Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.
But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.
Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.
> You know a clear way to avoid this risk entirely? Don't trust your communications to a public network.
"Just build your own internet" is frequently not a realistic proposal.
> But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.
Don't use online communication. Period. Talk to people face to face.
> "Just build your own internet" is frequently not a realistic proposal.
Don't use online communication. Period. Talk to people face to face.
> Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.
Not my damn point. And you well know it, you just don't want to concede a breath of air to the idea that you might be wrong...
> Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.
Fallacy is fallacy. Dreaming of a utopia does not make it so, and expecting the average person to take this stance just isn't a realistic expectation. Noble goal. Shit thing to risk your personal safety on.
---
And that's the point. I advocate for these tools, I use them I when I think they're appropriate. Failing to be able to consider a possible downside isn't a "good" thing. It doesn't make the argument for these tools stronger... it makes it hard to evaluate your risk, and personally - makes me think you're actively undermining real efforts for security.
So if your actual stance is "Use these tools even though I understand it compromises your personal safety - I don't care because blah blah blah"... then I don't have enough respect for you to continue the conversation. You are only acting for you, and that's shitty.
I also use tor in my work in order to get a third-party perspective on a website, or when inspecting suspicious links.
Exactly, and this same form of spurious argument came up in an hn post yesterday about cavity prevention, centering on an argument that a new advance in cavity treatment "cannot guarantee" to end cavities forever. [0]
I feel as though I've never been fooled by these arguments, although surely I have different types of weaknesses that are unique to me. But it seems to stand out as a form of argument that somehow has persuasive power among intelligent types whom I would never expect to fall for other forms of obviously fallacious arguments.
SSL/TLS was introduced for POP3/IMAP, but I don't think that was bad.
Email to this day is unencrypted at rest and completely transparent to whomever is running your mail server. You don't think Google runs GMail out of the goodness of their heart do you?
I think the Middle East gave us a very clear example of how state actors may target channels in unexpected ways.
It's entirely appropriate to pursue a defense in depth strategy while questioning any particular layer.
You don't do something, once, and then are good to go forever. Banks don't just put cash in a safe and forget about it; they have audits, security guards, cameras, threat intelligence profiling criminal gangs, etc.
For instance, for buying drugs, the ordering isn't the risky bit. Receiving it in the mail is. Even if tor was magically "100% safe" the crime overall wouldn't be. The point of using tor is not to eliminate all risk, it's just to decouple payment from reception. I had my drugs intercepted by customs once, but they couldn't prove I ordered them, so they dropped the case. I'm sure it might've been possible for them to prove it if they spent a lot of resources trying to trace crypto transfers and so on, but police only do that if the fish is big enough because they're resource constrained.
Tor is just another tool criminals can use to reduce risk. It's not perfect, but for most things it's the best thing available.
An analog crime I think about is the murders in Moscow, Idaho. The criminal did take some careful measures like wearing gloves but he left a knife sheath behind that contained DNA evidence. Everything else they had on him was circumstantial, he owned a similar car to what police thought they saw on people's doorbell cameras and his phone went offline during the time of the murders and also pinged a tower close to the crime scene hours afterwards. Police found a partial genealogy match to his DNA which I'm sure they compared to similar car owners and cell tower records. If he hadn't left the sheath behind, wore something like a Tyvek suit, and simply left his phone at home, the suspect pool would have likely been too large. His careful measures (turning off his phone, making multiple passes in his car) likely contributed to police focusing on him once the DNA proved a link.
Nope. Not even that is 100% safe because you can be falsely convicted of a crime you never even committed. Many privacy tools reduce that risk as well, because you're less likely to be convicted by e.g. a lazy prosecutor willing to take things out of context if you provide them with less source material to trawl through.
If you weren't actually buying drugs online then there shouldn't be any evidence that you were (or the cops planted it and then we're back to it not really mattering whether you have Tor installed). And then what are they charging you with that would even make it to a jury instead of being dismissed by the judge for lack of evidence?
If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP. There are privacy use cases, but just like using crypto as a currency and not a speculative gambling investment, its in the small minority of uses.
Why did you do multiple searches for std::vector? Are you worried about sharing needles? You also read an article about caffeine, which is often used as a cutting agent. You've been participating in internet discussions about using Tor, which the prosecutor argues is only used for CP and drugs.
> If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP.
Nobody really knows what Tor is used for, by design. But the media likes to rile people up, and "Tor used by privacy activists to read Facebook" isn't a headline that does that.
It's all too easy to lie with statistics. For example, some people have looked at which hidden services are most often looked up. That's not going to tell you about real usage, because bots do lookups at a much faster rate than real people, and government agencies run automated crawlers. Then you get statistics that say a significant percentage of the lookups are for CP and drugs, but not what percentage of those lookups were made by law enforcement running crawlers 24/7 specifically looking for CP and drugs.
Here's another example:
https://www.sciencealert.com/only-a-small-fraction-of-the-da...
> "In countries coded as 'free', the percentage of users visiting Onion/Hidden Services as a proportion of total daily Tor use is nearly twice as much or ~7.8 percent."
> In other words, people living in liberal democracies are more likely to exploit the dark web for malicious purposes, whereas users living under repressive regimes in non-democratic countries might be more likely to use Tor to circumvent local censorship restrictions and access free information on the internet.
Tor is used to bypass censorship. This use case happens more often in countries where there is censorship, and less often in countries where there isn't, because obviously. Reaching from there to "people living in liberal democracies are more likely to exploit the dark web for malicious purposes" is ridiculous. A higher ratio of B to A because of a smaller need for A does not imply a greater occurrence of B.
That's so exceptionally unlikely as to be something you can discount as a possibility, providing you don't actually commit crimes.
As opposed to... people who undergo illegal activities with the intention to BE caught???