Tor Appliance
schneier.com
schneier.com
https://github.com/grugq/PORTALofPi
P.O.R.T.A.L. Personal Onion Router To Assure Liberty https://github.com/grugq/portal
A Linux router that connects to Tor over one interface and shares the connection over another one. Simple and secure.
> This is a commercial variant of the FOSS PORTAL project that I released in September 2012 at Ekoparty. You don't need to run a closed source commercial device to get easy Tor anonymity, just use PORTAL on the RaspberryPi.
I like Tor and think that making it easier is a great idea, but when you sell it as an easy path to security and anonymity, you are going to get some people hurt. Tor can be both anonymous and secure if you take certain paranoid precautions when you use it, but are general consumers going to have any idea about those precautions? It's a challenge to get people to not just bypass browser cert errors or to secure their Wi-Fi, advanced tor browsing precautions may as well be instructions for using a zero G space toilet.
Downloading the Tor Browser Bundle is "taking paranoid precautions"? It already has HTTPSEverywhere built in, disables JavaScript by default, etc.
There's also a large concern that using NoScript in any form harms anonymity, as your NoScript whitelist/blacklist is somewhat detectable by websites and can act as a fingerprint.
Also, on TLS, you will not be perfectly secure, and I think it's dangerous to consider yourself secure against a state-sponsored actor by using it. TLS has quite a large surface area for attack in its current form - The PKI. If you're going to take paranoid precautions, it's probably best to assume one or more CAs are rogue/compromised already (or that they could become so at any time).
I'd really like to see a Tor browser distribution that spins up a clean VM each time you open a new session. Until then, the guys building the Tor Browser Bundle are doing a pretty decent job.
You can't use Tor without understanding the basics of how it works and what the risks are. If normal consumers are going to stick these things on their network, they're gonna have a bad time.
Is there a more technical analysis of this, and how it works, and what it restricts? Because nearly all the benefit of this can be lost pretty easily, unless they make what I assume would be rather painful decisions for users (strip all cookies, etc, which obviously they don't do).
If this is just about avoiding geo-IP lookup, then I think it's a hard sell. People who would care might be offended that it does little else, and people who don't have no reason to spend $50.
Tor has a lot of trade-offs for little benefit, and the tool is designed for being used for specific purposes rather then as an everyday browsing tool.
Can I use ad-blocking software with Safeplug?
Safeplug has ad-blocking software built-in out of the box.
My only worry is that people may keep it off most of the time, because of slowness, and eventually forget about it.Also, eliminating the surface area for fingerprinting a browser is useful - so for example, removing flash (which can fingerprint you based on installed fonts), having NoScript enabled, and having a default web-bug blocking setup (such as disconnect.me), and self-destructing cookies should be a must.
https://www.mail-archive.com/tor-talk@lists.torproject.org/m...
There are quite a few people on there advocating using technology like this to route other peoples traffic through Tor without their knowledge, including Jacob Appelbaum. I argue against this.
One example would be how we are giving them a world where they will have no privacy at all.