Tor in Google Summer of Code 2014
blog.torproject.org
blog.torproject.org
It seems to me that arresting an exit node's maintainer for child porn serves to have a real chilling effect on the system. As much as I'd like to provide, say, a dissident with a means to voice their opinion, it's not going to help when the cops cart away the exit note and haul me off to jail.
I guess what I'm thinking is that hidden tor services sort of 'close the gap' when it comes to problems like I describe above, since conceivably a political dissident could post to a hidden service (never appearing on the Internet at large) and have something of an intermediary in a country with greater freedom post it for them?
Also, if people would like to help Tor but are afraid of running an exit node, Noisebridge (a hackerspace) runs a fucking giant exit node. Donating time or money to them would help.
I have a tor relay on amazon[1] and have had no problems.
https://trac.torproject.org/projects/tor/wiki/doc/GoodBadISP...
Aren't there also safe-harbour provisions for transmission of lewd/indecent content and for trademarks, libels and such?
Of course there being legitimacy of your actions in statute [if indeed that's the case] wouldn't mean you don't get hauled off to jail.
As more law enforcement become literate in technology and become aware of what Tor is, this will happen less than the vanishingly improbable rate that it happens now, until it never happens at all.
One of the bigger advantages of a hidden service is that you can't be sure who's hosting it and where. They're great for hosting websites but do nothing for allowing access to other services. If you're worried about trouble from running an exit node you could contribute by running a relay or a hidden bridge which would be way more useful than a hidden service.
I've actually been contacted by the Michigan State Police in a child porn investigation and after explaining that I run a TOR exit node and have no ability to help in their investigation the officer I talked to was quite pleasant. I've heard nothing about it since then.
There are several news outlets that run hidden services for whistle blowers and people in danger or unable to speak openly so your idea isn't without merit but it does require pre-planning to be of any use. If you've got no way to communicate the existence of your service to people before they need it, it'll be of little use.
Anyway, I'm only running two non-exits. :-)
Hidden Services use only the internal network and don't rely on exit relays at all. All communication is end-to-end encrypted, so all relays will only ever see encrypted content.
If you have less than a couple of Mbit/s of upload capacity, you might want to run a bridge. Bridges are especially useful for people in heavily censored regions, and only provide an entry point to the Tor network.
https://www.google-melange.com/gsoc/org2/google/gsoc2014/tox
The project I want to see is running the tor router in zerovm in docker, and running a full browser and all plugins in a child docker in such a way that it is fully fire walled and can only communicate via the tor container, with vnc screen scraping etc.
And set up so the browser container can be launched in persistent mode to make changes eg browser plugins, but normally runs with aufs on a ram disk so it never touches disk and is completely lost when closed.
The point of hosting in docker in docker is to firewall the browser so it can't talk to anyone else, and to add extra layers of protection - however flimsy - against any eventual targeted compromise.
It's not a good idea. If you want to use the web on Tor, use the browser bundle.
"A dedicated hardware device which forces all internet traffic to be sent over the Tor network. This significantly increases the odds of using Tor effectively, and reduces the potential to make fatal mistakes. " https://github.com/grugq/portal
It works well.
Instead of just having your ISP able to sniff or MITM your web traffic, now you may have some random exit node operator doing the same - likely with more malicious intent than your Internet provider.
While the exit node will be able to sniff the users, it won't be able to link it back unless the user gives up some information. ISPs can link back every time, regardless of behavior.
The FBI busted a child-porno ring on Tor using only an iframe and some javascript. They were able to take control at the data center the site was hosted, and then trace back to the ISPs for the Tor users who didn't disable java.
Java is not allowed on Tor Browser Bundle and shouldn't be allowed in a browser, ever. (And probably in general if you care about security.)
JavaScript in general should not be that dangerous - however, there was a 0-day bug in Firefox, that Tor Browser used, that leaked the IP anyway, and NSA used that 0-day.
In general - at least in my opinion - JavaScript is much lower on the "dangerous" list than Java, but yeah, still can leak something.
The best way is probably to just use Tails - a linux distro made to be secure from the start.
I have read somewhere the point is that one is anonymity provider, other - encryption to hide from your ISP.
If you think about it, you'd be using Tor to connect to either public or roll your own VPN. The issue with using Tor is that all exit nodes are (probably) monitored. Some websites even refuse to serve you, as they have a list of exit nodes. Use of public VPNs is easier, as semi-officially they track you, hence they can be trusted by websites. Your best option is use Tor & custom VPN with a clean IP address. Trouble here is leaving payment data and you'd still probably would trigger some alarms by connecting from a registered Tor exit node...
I use it with my normal Chrome browser.
brew install tor
then setup a new user in Chrome and install the proxy switchysharp extension and add 127.0.0.1 9040 socks5 as a proxy.-- https://www.google-melange.com/gsoc/document/show/gsoc_progr...
Just kidding, turns out Google is not always evil. Good that HN gets a reminder once in a while.
Truth is, Google doesn't care what open source project you want to make into GSoC, as long as someone likes your proposal, the project will get the $$ it needs :) Note Mercurial didn't make it to GSoC officially this year (probably have to go under PSF's name) - so even popular OSS doesn't automatically becomes a GSoC participant.
When a company is recruited into a program like Prism, that doesn't necessarily happen through the CEO. Certainly, the company doesn't announce such a deal at an all-hands meeting, and omits it from their financial and regulatory filings.
The vast majority of a company's employees might be legitimately offended at the suggestion they are collaborating in such a program.
And yet, such a company can lose their customers and reputation, and may deserve that fate. It's a form of corruption. It's a hazard for customers. Those companies listed as participating in Prism have to bear the responsibility, whether or not most of the employees and even most of the company leadership can correctly claim to be victims.