Why is this something that needs to be repeated to the technically skilled people on HN?
Why is this something that needs to be repeated to the technically skilled people on HN?
But we don't just communicate with technically skilled people. Something that can be used by everybody and can be trusted would be really awesome.
Maybe being superstitious isn't helpful, but in this instance, I'm not so sure Tor is able to be relied on.
A proxy server won't work for the same reason a personal server wouldn't work. It's tied to you eventually, either through a paper trail or a packet trail.
Oh, and drop the condescending attitude, okay?
Tor has been analyzed extensively by cryptographers and security researchers; there is literally a mountain of published research about it. It is operated by an independent organization. I would be more cautious about the Linux kernel, a vastly larger codebase that could and probably does have numerous back doors, than about Tor.
"A proxy server won't work for the same reason a personal server wouldn't work. It's tied to you eventually, either through a paper trail or a packet trail."
Which is why it is below anonymous remailers and Tor on my list. Proxy servers are better than nothing at all.
And that research says that if an entry node and an exit node are both under control of an adversary, then that adversary can deannonymize the target.
I don't know enough about it, but I know that deannonymizing someone is a matter of resources, not a matter of ability. And the USG has a lot of resources.
For what it's worth, it is not hard to encrypt a message and post it to Usenet. It is imperfect and vulnerable to traffic analysis, but it is not hard. It is even easier to just send encrypted emails and not bother with anonymity. I have personally seen non-technical people using PGP or S/MIME without assistance.