Tor Browser 4.0 is released
blog.torproject.org
blog.torproject.org
All this to say, I'm really impressed at the lengths the project has gone (and continues to go) to make Tor safer, more accessible, and easier to use for nontechnical folks. I just downloaded and installed this, and it worked, and worked well. A far cry from the earlier days. Cheers to Tor and the people working on it, running exit nodes, bridge nodes, and offering legal support to those that need it.
https://trac.torproject.org/projects/tor/wiki/doc/TorAbuseTe...
https://blog.torproject.org/blog/tips-running-exit-node-mini...
Some may reply that is a legal risk as well. I believe it is clearly within the bounds of the law. If the police shut then down I would fight to the extent of my ability in the courts to have them restored.
I believe strongly in our system, and that all men and women (including law enforcement) are bound by the same set of laws, and are equal before them. Tor is legal under those laws, and the courts stand ready to vindicate my rights if they are violated.
BECAUSE IPs SHOULD NOT HOLD UP IN A COURT OF LAW AS PROOF OF IDENTITY.
Wow, that feels better.
(I used to have a source for this, but I think I bookmarked it on my dead laptop.)
also, the same argument applies for tor at large
That would be true if only if that's the only extra thing you would be doing on the node though. Even then seems like pretty thin evidence.
It seems that the biggest threat to the Tor network right now, are web sites that treat Tor users differently. For example, Cloudflare is currently serving captchas to Tor users. It's an automated response based on reports of abuse from the exit node IP at some point in the past.
Some individual sites have been doing this for a while to tackle abuse problems, but for a service that handles as much internet traffic as Cloudflare does, this is not a good sign for Tor.
https://blog.torproject.org/blog/call-arms-helping-internet-...
Currently, they aren't preventing Tor users from reaching the web sites of their customers, they're just making it a little more difficult.
- The exit nodes can see all traffic being routed through them[1]. Be wary of using Tor for regular web surfing - the exit node can not only monitor any unencrypted traffic, but can also inject browser exploits, attempt to strip SSL[2], etc.
- HTTPS Everywhere is only enabled for sites that the EFF has whitelisted[3]. Even if a site supports SSL, don't expect HTTPS Everywhere to automatically send you to the encrypted version - always doublecheck.
- NoScript is not enabled by default in the Tor Browser Bundle[4]. Don't expect it to protect you from malicious Javascript exploits out of the box.
If you absolutely must use Tor for something, the safest way to do so is to connect to Tor, make whatever connections you need to make (and only those connections), then immediately get off.
[1] https://www.torproject.org/docs/faq#CanExitNodesEavesdrop
[2] http://www.thoughtcrime.org/software/sslstrip/ (it's long, but the video is worth watching)
[3] https://www.eff.org/https-everywhere/faq#automatic-https
[4] https://www.torproject.org/docs/faq#TBBJavaScriptEnabled
I will take your advice to heed if I'm ever in a truly sensitive situation, but I use Tor out of solidarity. Do you think that's unwise?
That said, feel free to use it for whatever you want - just be aware of the tradeoffs/risks. You can't just turn on Tor and assume that you're instantly more anonymous and secure - to achieve that, people need to completely change their browsing habits. Surfing the web through Tor without taking extra precautions is essentially saying "I don't trust the web site I'm visiting or any node between it and me, but I will implicitly trust this random group of volunteer exit node operators who have assured me that they have no malicious intent."
https://github.com/kevinjacobs/HTTPS-Finder/tree/master/dist
The only added risk I see is that an exit node arguably could be more likely to attack the user than an ISP, but I think the difference is that attack in different ways. Most ISP's attack confidentiality as part of their business, though probably they don't insert browser exploits.
Whereas a Tor exit is more likely to snoop, theoretically they should have no idea who you are (as long as you don't send any identifying information in plaintext).
I think the most important thing is that we should try and make the implications of both clear to as many people as possible.
Tor Browser is making tor more accessible to average computer user in the same way selling minefields cheaply makes real estate more accessible to average human.
The only reasonable way of using tor for even remotely illegal purposes is by using whonix, or roughly equivalent schemes (eg. a tor-only router + tails).
[0] http://nakedsecurity.sophos.com/2013/08/05/freedom-hosting-a...
Also Tor Browser is usually better than using Tor + another browser.
Explanation about attacks: https://blog.torproject.org/blog/improving-tors-anonymity-ch...
Apart from the obvious (Firefox vulnerabilities, dangers of running Javascript or other plugins, etc.) weaknesses, I mean.
The security of the TBB is generally limited by the security of Firefox, which is not awful.
You're the perfect example why tor browser is so bad.
>was only used against older Windows boxes
It was only used against windows systems, but it was a firefox exploit.
[0] http://www.cvedetails.com/vulnerability-list/vendor_id-452/p...
Many of the vulnerabilities fixed are discovered by Mozilla's security team as well as community members, so while there may have been a vulnerability in the browser and it was fixed, it does not mean the vulnerability was known or used maliciously previous to being disclosed.
This is why you cannot judge the security of a product based upon the number of CVE's published. If the vendor in question has an open security program they will publicly disclose all security vulnerabilities they discovered internally. This is a common practice will most (all?) of the major browser vendors.
For example, look at the history of Google Chrome CVE's. You will notice huge spikes in the number of vulnerabilities. A little research, and you will find that was when the Chrome Security team started heavily fuzzing their code and fixing vulnerabilities before most of them were discovered by outside parties.
What you have to worry more about is vendors who don't publicly disclose security vulnerability information, so the only CVE's you see are the ones that independent parties published.
Of course, really solid security requires a lot more effort. If I were to engage in illegal purchases using the Tor browser, I would run the browser in a VM and route all VM traffic through Tor. However, as we know from experience, the Tor Browser's (very mediocre) security is sufficient for the vast majority of casual criminals.
>You're the perfect example why tor browser is so bad.
Gee, thanks :)
Also, none of those CVEs are for the latest version of Firefox.
e.g.
https://rednerd.com/2014/10/16/tor-transparent-proxy-on-a-gl...
https://rednerd.com/2013/12/07/portal-for-debian/
Using the TBB gives me the feeling of painting a giant target on my back.
The TLDR of the situation is that you shouldn't worry about what the NSA flags you as. They flagged everyone. Just assume you're on their list because you probably are anyway.
I've likened it to that scene in V for Vendetta. They can only take what you give them.
Does HN support Tor?
Edit: read City and the City by China Mieville?
I feel that fear of big brother is a limitation on citizens personal freedom since people will be more guarded about what they say, inquire about, and behave. No shifty behavior. The constable may be watching.
What do you mean by "support"? You can access HN through tor, though sometimes it is blocked (perhaps depending on which exit node you happen to be routed through).
Probably less the name of the site as the confluence of money, power, technical expertise and occasionally violent anti-government rhetoric. Honestly, I find it surprising how many people seem to feel perfectly safe here while avoiding Facebook, Google, etc.
And government officials (esp. in other governments) are obvious targets for NSA surveillance.
How can you confidently say that you know what the NSA is interested in?
Read whatever you want to.
For all the hullabaloo about censored books, surveilled reading is just as much of a threat to the formation of free ideas as censorship, if not more so.
http://www.amazon.com/The-Terror-Factory-Manufactured-Terror...
I've heard of much of this kind of behavior before. Doesn't this generally involve some form of entrapment, rather than mere browsing behavior?
Important to consider, regardless.
They have alerts on everything. If you say something they may not like online, you're probably already on a list. Tor or not.
This is exactly what's wrong with the whole situation.
To my dismay, the TSA did not attempt to search me at my home airport. Perhaps the data had not propagated to screeening yet. Regardless, it seems harder than I initially thought to get onto one of these NSA lists.
For me, at least, I don't really care about security, but usability and stability.
Well, that is my speculation. I never get into any trouble for breaching the firewall.
https://trac.torproject.org/projects/tor/wiki/doc/meek#Style...
Can get bridges here: https://bridges.torproject.org/bridges?transport=obfs3
I suggest you run a non-exit relay instead, like I did for almost a year (at home). About to put it up again, after 3 months offline, now that I got better hardware to do it. Didn't have any trouble from my ISP, which was Tim, but I think that the biggest reason for that is that they are new in the business and they are trying to make things as painless as possible. It was a heavy traffic relay, I was limiting it to 4gb per day up/down bandwidth, which is quite alot, and never heard any complaints from Tim.
It seems that if you don't run the limited exit policy, you'll be hit with DMCAs pretty much instantly.
If you do run the limited exit policy, you'll get hit with abuse notifications (you hacked my site, you're posting spam, etc) pretty quickly.