[HN Gopher] Twitter's new Tor onion service
       ___________________________________________________________________
        
       Twitter's new Tor onion service
        
       Author : mooreds
       Score  : 130 points
       Date   : 2022-03-08 20:47 UTC (1 days ago)
        
 (HTM) web link (twitter.com)
 (TXT) w3m dump (twitter.com)
        
       | mulmen wrote:
       | Ok but I assume the user-hostile dark patterns are still present?
       | So I can't scroll past more than a few tweets without a full page
       | popover driving me to sign up?
       | 
       | I have no interest in ever "tweeting". I do not need an account
       | to read tweets from a link sent to me. At this point I refuse to
       | log in or comply with the wishes of Twitter PMs just on
       | principle.
       | 
       | If the onion site does not feature these dark patterns then this
       | will actually drive me to use Twitter _more_ , and will actually
       | take some of my usage off the web and onto tor.
        
         | dillondoyle wrote:
         | And IIRC you need a cell phone to get an account. At least it
         | made me when I signed up for one to read the news. Maybe it was
         | so dark I missed how to skip.
        
           | jazzyjackson wrote:
           | Yes even if you skip they'll just flag your account for bot
           | like activity and require a phone number to unlock. Happened
           | to me first time I replied to Elon Musk, have to hand it to
           | them, definitely something a bot would do.
        
         | Georgelemental wrote:
         | Instead of the terrible Twitter website, have you considered
         | Nitter[0] with an extension like Privacy Redirect[1] (or on
         | mobile, an app like UntrackMe[3])? No login prompt, no dark
         | patterns, no JavaScript
         | 
         | [0] https://github.com/zedeus/nitter [1]
         | https://github.com/SimonBrazell/privacy-redirect [2]
         | https://f-droid.org/packages/app.fedilab.nitterizeme/
        
           | mulmen wrote:
           | I don't _use_ Twitter. Someone texts me a link and I tap it,
           | then we discuss. Is there some way to make mobile Safari
           | automatically parse Twitter links and redirect?
           | 
           | Twitter is extremely low-value to me. Any additional effort
           | and I will just do something else with my time.
        
       | amai wrote:
       | Using Tor is illegal in China. In Russia the situation is
       | similar:
       | 
       | "Since December 1st, some Internet providers in Russia have
       | started to block access to Tor."
       | 
       | https://blog.torproject.org/tor-censorship-in-russia/
       | 
       | So I'm not sure if Twitters Tor support helps a lot.
        
         | carlosdp wrote:
         | Someone correct me if I'm wrong, but I believe you can still
         | use a non-blocked Tor Bridge to connect to the network in this
         | scenario.
        
         | [deleted]
        
       | stingraycharles wrote:
       | Could someone elaborate on what potential threat is addressed
       | here for the users? As far as I understand, a hidden service's
       | main purpose is to protect the privacy of the domain operator (in
       | this case, Twitter).
       | 
       | For a user, however, just the act of connecting through Tor will
       | protect their privacy (to a debatable degree). At the very least,
       | it will circumvent any blocks put in place by their ISP and/or
       | upstream.
       | 
       | What's the advantage of a hidden service then?
        
         | anonporridge wrote:
         | Another reason I can think of is that as more and more
         | "legitimate" traffic moves onto Tor internal (no exit nodes) it
         | becomes increasingly non-viable for nation states to execute a
         | blanket ban on Tor traffic as it would be too disruptive to
         | people and the economy.
        
         | xxpor wrote:
         | Perhaps an ignorant question, but don't hidden services not
         | need exit nodes? It'd make using Twitter a lot faster, I'd
         | assume?
        
           | bragr wrote:
           | Traffic to hidden services stays within the tor network so
           | you don't need exit nodes. However it isn't necessarily
           | faster. As I understand it, with a typical hidden service,
           | the hidden service nominates certain nodes for clients to use
           | to make contact with it and the client and the service build
           | tor circuits to those nodes thereby preserving the privacy of
           | both clients and servers but you end up with longer circuits
           | than those to exit nodes, and you are limited by the slowest
           | node in that chain. There is a mode for hidden services where
           | you don't care about staying hidden (say you are twitter or
           | the NYT running a service and everyone already knows who owns
           | the site and where the datacenters are) where, as I
           | understand it, you allow clients to build circuits directly
           | to you which preserves client privacy but not server. This is
           | more performant than a normal hidden service but I wouldn't
           | call it fast.
        
         | zrm wrote:
         | A major practical advantage is that Tor exit nodes regularly
         | have their IP addresses marked as abusive and then you have to
         | do a million captchas to sign in, and the onion service doesn't
         | do that.
        
         | esnard wrote:
         | Alec Muffet, who helped Twitter on this, replied to your
         | question on his blog: Why offer an Onion Address rather than
         | just encourage browsing-over-Tor? [0]
         | 
         | [0] https://alecmuffett.com/article/16007
        
           | anonporridge wrote:
           | > Using onion services mitigates attacks that can be executed
           | by possibly-malicious "Tor Exit Nodes" -- which, though rare,
           | are not nonexistent.
        
             | amelius wrote:
             | Would it make sense to be able to select your Tor exit
             | node, in this case from a bunch offered by Twitter?
        
               | anonporridge wrote:
               | Then you'd have to trust these Twitter run exit nodes to
               | not attack your traffic towards non twitter sites.
        
               | amelius wrote:
               | Exit nodes run by Twitter sounds less scary than exit
               | nodes run by random folks.
        
         | Karrot_Kream wrote:
         | Another benefit is that exit nodes tend to be saturated with
         | traffic from folks using them to transit traffic onto the
         | clearnet. As such, latency and throughput through these exit
         | nodes is going to be pretty bad. Using Tor to directly view
         | Twitter means that you aren't bottlenecked around an exit node
         | to reach Twitter.
        
         | celticninja wrote:
         | IIRC With an onion site you don't need an exit node to visit
         | the site.
         | 
         | So all traffic stays within TOR.
        
           | mritzmann wrote:
           | This. Result: The website (here Twitter) load faster, because
           | Exit nodes are sometimes not that fast.
        
       | 2OEH8eoCRo0 wrote:
       | Good. Now please allow me to lurk more easily without an account.
        
         | [deleted]
        
       | btdmaster wrote:
       | twitter3e4tixl4xyajtrzo62zg5vztmjuricljdp2c5kshju4avyoid.onion
       | does not work due to CORS. (For me, it doesn't matter much since
       | Twitter depends on JavaScript and Nitter does not.)
        
         | capitainenemo wrote:
         | Big fan of Nitter. Switched to it when Twitter killed off non-
         | javascript last year, and I rewrite all Twitter links in it
         | when resharing with others. Works great in w3m, or in NoScript
         | without need to whitelist a social media tracker.
        
           | largbae wrote:
           | Would it be possible for one of you experienced NoScript'ers
           | to write a set of tips and tricks? I have been using NoScript
           | for about a month since someone mentioned it here, and it has
           | been wonderful. I never imagined I could opt out of just the
           | trackers and APM bloat so easily, and my phone battery life
           | is improved dramatically too. But I bet there are more things
           | like Nitter that I haven't yet discovered.
           | 
           | Thanks!!
        
             | capitainenemo wrote:
             | I'm not sure what to focus on. On the desktop, I combine
             | uMatrix+NoScript for better coverage of CSS, cookies and
             | images across domains, while still having convenient one
             | click whitelisting in NoScript. That's just a personal
             | preference.
             | 
             | Expand/collapse sections that default to collapsed.
             | Particularly annoying if no one bothered to put fallback
             | CSS in a noscript block. Using custom CSS style rules can
             | help with this. Unfortunately Mozilla killed the vast
             | majority of their extension ecosystem on the phone. One
             | silly hack workaround I found was that their darkmode
             | extension they did whitelist allows custom CSS rules that
             | can be used to fix things like this. It isn't nearly as
             | elegant as using Stylus on the desktop for this.
             | 
             | Reader mode can help with broken sites. Disabling all CSS
             | also a quick fix if you just want to read stuff. Almost
             | like browsing with w3m. (View-Page Style-No Style) Dynamic
             | image loading - regrettably despite HTML support for it,
             | many sites use JS hacks and are probably pretty disinclined
             | to support NoScript users. I've made custom fixes in
             | violentmonkey for sites I care about on the desktop -
             | mostly out of sheer cussedness. No solution on mobile that
             | I know of apart from whitelisting.
             | 
             | old.reddit.com  - shame Mozilla killed the addon to
             | autorewrite the urls.
        
         | LinuxBender wrote:
         | That's a good idea. Nitter proxies behind Tor onion service
         | nodes.
        
       | benmw333 wrote:
       | Login to a service with Tor that will just kick you off if you
       | hold views contra to corporate media.
        
         | Taylor_OD wrote:
         | That is a little unfair. There is a lot of nonsense on Twitter
         | that doesnt get banned.
        
           | nerdponx wrote:
           | And keep in mind that Twitter would much rather not have to
           | censor anything. Content moderation, legal compliance, etc
           | are cost centers.
           | 
           | It's easy to get lost in the "evil corporate overlord" idea
           | and forget that companies only ever commit evil because evil
           | is sometimes profitable.
        
           | nathias wrote:
           | its the sense that gets you banned
        
           | bonoboTP wrote:
           | Why did you equate "contra to corporate media" with
           | "nonsense"?
        
         | [deleted]
        
       | makerofspoons wrote:
       | I wish this page elaborated on what "Additional domains used to
       | enable parts of site functionality" means. What additional
       | functionality is available when I use the different links?
        
         | bragr wrote:
         | Just poking at the two home pages (tor and not)
         | twitterhbmit57bzbcjnujedrn7uk73geo4ackio4lxdj6t7w6f4zsid.onion
         | is the equivalent of the abs.twimg.com CDN, so assets,
         | javascript files, fonts, etc
         | 
         | I don't immediately see what
         | twitterhpgjerufcvrmzerg2novpipy42rk3anvb5b7np4zggm4rwaqd.onion
         | is being use for though.
        
         | nightpool wrote:
         | I think they just mean CDN domains, asset domains, etc.
        
           | markstos wrote:
           | Right. For example, normally "twimg.com" is used for serving
           | images and "t.co" is used for link shortening and engagement
           | tracking.
           | 
           | So they may need additional Tor domains to map the additional
           | domains they normally use.
        
       | mike-cardwell wrote:
       | Twitter was already available over Tor, via
       | https://www.twitter.com - Creating an onion service didn't make
       | it any more available.
        
         | tanduv wrote:
         | One of the devs working on this already answered -
         | https://alecmuffett.com/article/16007
        
           | mike-cardwell wrote:
           | I get the arguments he's listed. But to be honest, and this
           | may just be me being pessimistic, I suspect the real reason
           | is that it's just a cool thing for an interested dev to want
           | to set up, and the list of reasons at that URL is really just
           | a list of excuses.
        
         | [deleted]
        
         | hnarn wrote:
         | The entire Internet is available via Tor but only via exit
         | nodes, saying that it "doesn't make it any more available" to
         | offer it directly within Tor shows a fundamental lack of
         | understanding of how Tor works.
         | 
         | If you can access a service, any service, completely within Tor
         | without having to exit to the Internet, this significantly
         | improves your anonymity[1] since you no longer have to go
         | through an exit node, and as such the amount of nodes you can
         | "exit" from increases substantially.
         | 
         | [1]: That is, the anonymity that Tor already provides.
         | Obviously signing up for Twitter under your real name with your
         | phone number will compromise your anonymity regardless, but
         | that is not the problem that Tor solves.
        
           | mike-cardwell wrote:
           | I'm pretty sure I'm right, and that I understand how Tor
           | works.
           | 
           | The existence of the Twitter onion service does not help a
           | single person access Twitter that couldn't already access it
           | anonymously without the onion service just by using Tor
           | normally.
        
             | MayeulC wrote:
             | An exit node (or multiple ones) could block twitter.
             | 
             | Exit nodes are rarer than other nodes, as they're difficult
             | to host. That limits the bandwidth.
             | 
             | An onion adress doesn't rely on DNS at all.
             | 
             | I think this should provide better bandwidth, availability,
             | and anonimity.
        
               | wolverine876 wrote:
               | Also, if I understand correctly, exit nodes have vectors
               | for attacking your security that are eliminated by an
               | onion address.
        
       | superkuh wrote:
       | I can't imagine many of the people accessing twitter over Tor are
       | going to be okay with running random executable code to be able
       | to read text. But maybe in this context they're assuming people
       | will be using Tor that don't care about privacy and only care
       | about access.
        
       | boredumb wrote:
       | Finally a reliable way to read opinions from ill informed and
       | over socialized authoritarians at 100KB/sec.
        
       | YaBomm wrote:
        
       | wolverine876 wrote:
       | I saw a diagram of traffic to an .onion domain, I think in a Tor
       | Project browser, and it showed the traffic going through ~3 Tor
       | relays, _then ~3 'regular' Internet relays_, then perhaps
       | something else, then the .onion host.
       | 
       | Why the 'regular' Internet relays? It wasn't a hijack of some
       | sort, this diagram was from the Tor Project. It wasn't an
       | exception AFAICT, I saw it for multiple .onion hosts.
       | 
       | I assume the traffic is encrypted over the Internet relays, but
       | it seems to add a bunch of potential vectors of attack, not to
       | mention potential performance issues.
       | 
       | EDIT: 'clear' -> 'regular'
        
         | sp332 wrote:
         | Tor hidden servers have changed recently so this may be a bit
         | out of date, but the client (at the Twitter user end) has to
         | choose all the relays between itself and the endpoint. The
         | server (Twitter) is also hidden here, so the client cannot make
         | a path all the way to it, the way it could for a normal
         | website. So Twitter publishes the address of a trusted relay
         | instead. The client makes a path to the relay, and the relay
         | forwards the request on to the hidden server.
        
           | wolverine876 wrote:
           | Thank you. Why do some relays need to be public Internet
           | hosts (if I understood correctly what I saw) instead of using
           | all Tor hosts as relays? Sorry if the answer is somehow
           | implicit in what you already posted.
        
             | sp332 wrote:
             | https://www.jamieweb.net/blog/forwarding-tor-hidden-
             | services...
        
               | wolverine876 wrote:
               | Thanks for all your help and I understand if I've
               | exhausted the efforts of free HN technical help!
               | 
               | I read the link and while I learned more about Tor, the
               | article seems to describe how to secure Tor traffic that
               | is forwarded to regular Internet hosts, for example if
               | someone using a Tor client visited ycombinator.com. My
               | question is, if you use a Tor client to visit twitterhpgj
               | erufcvrmzerg2novpipy42rk3anvb5b7np4zggm4rwaqd.onion, why
               | is part of the route through regular Internet hosts
               | (afaict) and what are the implications of that? The
               | article shows what I am describing in this screenshot;
               | the blacked out parts next to "Portugal", "Germany", and
               | "United States" are IP addresses:
               | 
               | https://www.jamieweb.net/blog/forwarding-tor-hidden-
               | services...
               | 
               | (Also, my original post had it backward: the traffic goes
               | through regular Internet hosts and then through Tor
               | relays, not vice versa)
               | 
               | Again, maybe I am just missing the implications of what
               | you are saying.
        
           | LMYahooTFY wrote:
           | Isn't determining the full path in Tor for routing to it's
           | .onion sort of defeating the purpose? Can the client request
           | this level of specificity?
        
             | sp332 wrote:
             | Only the trusted relay in the middle knows that half of the
             | path. Sorry if that wasn't clear. And again, this was a
             | hack on the original protocol that had some security
             | issues. The implementation of hidden servers was recently
             | updated and I don't know exactly what changed.
        
               | Bombthecat wrote:
               | But... Cant you noch the relay?
        
         | wolverine876 wrote:
         | EDIT (too late to edit parent):
         | 
         | This screenshot, from an article linked below, shows what I'm
         | talking about. The blacked out parts next to "Portugal",
         | "Germany", and "United States" cover publicly routable IP
         | addresses (afaik):
         | 
         | https://www.jamieweb.net/blog/forwarding-tor-hidden-services...
         | 
         | Also, note that I had it backward in the parent: The traffic
         | first goes through publicly routable IPs, then through Tor
         | relays.
        
           | I_Byte wrote:
           | I think I may be able to help sort out the confusing bits. I
           | know a lot about Tor so if you have any further questions
           | feel free to ask. Sp332's comment is a good explanation so I
           | will simply expand upon it. Also, if I misunderstood your
           | question let me know.
           | 
           | Tor works by ensuring that there is three Tor relays between
           | the Tor client (the software that connects to the Tor
           | network) and the destination the Tor client is connecting to.
           | 
           | However, what happens when you want to establish a connection
           | between two hosts who are both using Tor through the Tor
           | network? Well, in that case both Tor programs establish a
           | path through three Tor relays and link the last Tor relays in
           | each of their separate chains together (if you are interested
           | in learning about how each Tor program knows the others end
           | point look up "Tor hidden service directory"). Now with both
           | ends of their Tor relay chains linked, both hosts can
           | communicate with each other securely and anonymously over the
           | Tor network. (For example: you are using Tor browser to
           | connect to a hidden service. Both Tor browser and the hidden
           | service make a chain of three Tor relays each and connect the
           | chains together through the last node of each chain. The Tor
           | browser only knows the relays that it uses for its chain +
           | the end of the hidden services chain. The hidden service only
           | knows the relays in its chain + the last relay in your chain.
           | Thus keeping you both anonymous.)
           | 
           | I hope this helps!
        
           | Ajedi32 wrote:
           | The screenshot shows the traffic going through 3 Tor relays
           | (which your browser knows the public IP addresses of, since
           | it created that circuit in the first place) followed by three
           | more Tor relays (which it _doesn 't_ know the public IP
           | addresses of, since that circuit was created by the hidden
           | service), followed by a final hop to the hidden service.
        
         | edm0nd wrote:
         | .onion traffic never leaves the Tor network and stays inside.
         | 
         | Clear internet is for when someone is using tor and goes to a
         | clearnet site like blah.com. This is what exit relays are for.
        
           | wolverine876 wrote:
           | That is what I believed but what I saw seemed to conflict:
           | Install the Tor Project browser, connect to an .onion host,
           | then click on the icon that shows the route. It appears to
           | show the route goes through non-Tor hosts (I don't call them
           | 'clearnet' because I expect the data and some metadata is
           | encrypted).
           | 
           | EDIT: See this screenshot from an article elsewhere in this
           | discussion. The blacked out bits next to "Portugal",
           | "Germany", and "United States" are publicly routable IP
           | addresses (IIRC):
           | 
           | https://www.jamieweb.net/blog/forwarding-tor-hidden-
           | services...
        
             | yuliyp wrote:
             | This is normal: your computer picks the set of 3 relays you
             | want to use, hence it knows their IP addresses. The 3
             | relays from there to the hidden service are _not_ known to
             | your computer though, so those are just listed as  "relay"
        
       | aosaigh wrote:
       | Twitter is almost useless now unless you login with an account
       | (that requires a phone number). I'm not sure who the subset of
       | Tor users are who are comfortable logging into a service such as
       | Twitter?
        
         | 2OEH8eoCRo0 wrote:
         | On desktop I disable all cookies from twitter and it allows me
         | to browse freely.
        
           | azangru wrote:
           | It used to do the same for me in the incognito mode on
           | Chrome. Not anymore :-(
        
         | probotect0r wrote:
         | It doesn't require a phone number. Created an account the other
         | day with only email.
        
           | Aissen wrote:
           | Yup, they usually lock the account once you start using it,
           | possibly using some kind of pattern detection.
        
             | bierjunge wrote:
             | Tried it two times in last six months. Once via the Android
             | app and the second time on the website on my laptop. Both
             | accounts were blocked after less than 15 minutes without
             | even doing anything (except following a few accounts which
             | Twitter suggested based on my interests... [0]). Both times
             | they wanted a phone number to unlock.
             | 
             | I tried to contact the support, but they never responded.
             | 
             | [0] different accounts, based on different interests
        
               | bierjunge wrote:
               | It's getting even better. I just logged into one of the
               | suspended accounts. Pretty much everything is locked, but
               | without any information about the suspension. It's pretty
               | much "Oops, something went wrong. Please try again
               | later." on everything.
               | 
               | Ok, let's try it with the "Twitter privacy policy
               | inquiries" form (while logged in). Nope, can't submit
               | anything, because of the suspension. So why not have some
               | fun? Just sent a GDPR request via the "suspension appeal"
               | form. Why? For the lulz and to have some legal leverage.
               | 
               | Not even five minutes passed and I got a email. My
               | account is not suspended anymore... WTF twitter?
        
             | SketchySeaBeast wrote:
             | And there my account sits, a year later. I can't close it
             | because they won't let me do that without adding a number,
             | but I'm not going to add it.
        
             | danuker wrote:
             | > possibly using some kind of pattern detection.
             | 
             | The pattern of "not having provided a phone number"
             | perhaps?
        
               | Aissen wrote:
               | I wanted to provide them the benefit of the doubt.
               | Probably.
        
         | ravenstine wrote:
         | Whom do you trust your identity with more? Twitter or the
         | regime you're under?
         | 
         | As much as I despise Twitter, I'd much rather that they
         | exclusively know my identity than both they and the regime.
         | This isn't to say that I agree with Twitter requiring phone
         | numbers.
        
           | pyronik19 wrote:
        
             | mrtranscendence wrote:
             | Twitter is not a "leftist organization". Contrary to the
             | belief of the somewhat unhinged, there's no conservative-
             | hating conspiracy of tech giants, which are on the whole
             | not particularly left-leaning where it counts. There are
             | absolutely conservatives on Twitter; there have always been
             | and it remains that way now.
        
               | hecatoncheires wrote:
               | Twitter literally banned the sitting President of the
               | United States, a Republican. Other Republicans like
               | Marjorie Taylor Greene have had their accounts banned,
               | while this has never happened to a Democrat. People were
               | banned for questioning COVID (e.g. the lab leak
               | hypothesis), banned for questioning the 2020 Presidential
               | election's integrity (yet nobody was banned for
               | speculating on Russian interference and calling Trump
               | illegitimate in 2016), banned for misgendering or
               | deadnaming transgenders. Conveniently all the wrongthink
               | that fall squarely in opposition to progressive ideology.
               | 
               | I don't think anyone believes there's a secret
               | conspiracy, it's more that the type of people who work in
               | programming, and particularly for a Bay Area company like
               | Twitter, tend to be very progressive. It's the same
               | miasma that clouds the mainstream media, academia, and
               | now most corporate PR.
        
           | [deleted]
        
         | [deleted]
        
           | [deleted]
        
         | beardog wrote:
         | Some people use Tor to bypass censorship or mask their traffic
         | metadata from a local adversary
        
         | Traster wrote:
         | I think the point is to evade censorship in Russia, No?
        
           | nonrandomstring wrote:
           | Yes, I'm seeing a relaxing of the general exclusion and
           | abusive stance towards Tor users.
           | 
           | But that gives me a weird feeling to be honest.
           | 
           | We need to be in an international military crisis in order
           | that basic values of privacy prevail at home?
           | 
           | That does not speak well of our quiescent "western values"
        
             | hombre_fatal wrote:
             | Well, sure.
             | 
             | If most Tor traffic to your service is abuse where it may
             | be worthwhile to block it completely, then a catastrophic
             | event that gets more honest people using Tor may make it
             | worthwhile to unblock it.
        
             | adventured wrote:
             | > We need to be in an international military crisis in
             | order that basic values of privacy prevail at home? ...
             | That does not speak well of our quiescent "western values"
             | 
             | It also doesn't speak ill of those values, it says nothing
             | about the values. You're conflating two separate matters:
             | the values, and the effort required to hold/protect them.
             | 
             | Liberty requires a persistent effort to maintain against
             | politicians, malevolent actors generally, that lust after
             | increased power (for themselves and frequently the state as
             | well).
             | 
             | It makes sense that that would be a process of erosion and
             | (hopefully) rejuvination across years, decades,
             | generations, centuries - as the counter forces battle. If
             | you're really fortunate you live in a system that makes it
             | a lot more difficult for the power-seeking politicians to
             | trample on your rights.
             | 
             | Just because something of value requires effort to keep or
             | maintain, that doesn't debase its value or otherwise speak
             | to how great or how little the value is. Very valuable
             | things often require an enormous investment to acquire and
             | keep over time. At all times entropy is trying to destroy
             | well ordered systems (eg democratic, constitutional,
             | rights-protecting governments), it takes a huge amount of
             | resources just to forestall that and you can never stop
             | investing into it for long.
             | 
             | It also takes an enormous investment of resources to
             | maintain authoritarian, anti-rights systems. They can never
             | stop using force to oppress the population, they have to
             | constantly crush the spirit of the population. They have to
             | divert human potential on a persistent basis toward
             | destruction, oppression, violent actions against the
             | citizenship, actions inspiring fear/terror/dread. They can
             | never stop spewing propaganda meant to keep the population
             | in check, docile, in fear, etc.
             | 
             | That systems require active effort and mental attention to
             | maintain, tells you very little about whether they're good
             | or bad, the same goes for values a person holds (which also
             | require effort to maintain), or the values a culture of
             | people broadly holds.
        
               | nonrandomstring wrote:
               | Thanks for a thoughtful reply adventured. As I said, it
               | gives me an uneasy/weird feeling, which is to say I
               | haven't quite unpacked it myself yet. Your response is
               | helping me.
               | 
               | > It also doesn't speak ill of those values
               | 
               | Well actually it does, at least in that it highlights
               | them as inconsistent. Clearly my issue is that values
               | prone to change according to circumstance are weaker, as
               | generally one holds consistent values higher than fickle
               | ones. However, your further points are interesting and
               | deserve thought.
               | 
               | > You're conflating two separate matters, the values, and
               | the effort required to hold/protect them.
               | 
               | Perhaps in a short, pithy comment I'm not taking time to
               | distinguish the values (which I love and live by, and
               | believe most of my countrymen uphold) and the laziness by
               | which some fail to consistently and robustly stand up for
               | them.
               | 
               | > Liberty requires a persistent effort to maintain
               | against politicians, malevolent actors generally
               | 
               | Absolutely, and would you agree that we've slipped
               | dreadfully in that duty in recent years?
               | 
               | > Just because something of value requires effort to keep
               | or maintain, that doesn't debase its value or otherwise
               | speak or how great or how little the value is.
               | 
               | I am glad you think that, and we agree. I am not sure if
               | you thought I said otherwise?
               | 
               | > Very valuable things often require an enormous
               | investment to acquire and keep over time.
               | 
               | Like previous wars in which my family have fought at
               | great cost.
               | 
               | > At all times entropy is trying to destroy well ordered
               | systems
               | 
               | No. Sorry. That's too simplistic a take. I'm not talking
               | about the constant gardening required to maintain
               | structures of value, I am alluding to the malevolent
               | domestic forces who would sell our hard won freedom,
               | democracy and liberal values down the swanny for their
               | own aggrandisement and profit when it suits them, and
               | sing a different song when virtue signalling calls.
               | 
               | Let me try to be clearer what I am attacking here. It is
               | sloppy and selective values. It is a laziness that lies
               | somewhere between "sworn enemies unite against a common
               | foe", and a prejudiced framing effect.
               | 
               | We're all very happy to cheer on Tor, VPNs or other
               | instruments that circumvent tyranny, so long as it's not
               | _our_ tyranny. All of us have benefited hugely from the
               | freedoms immanent therein. We built these tools (US
               | Navy), and the internet itself (DARPA), in pursuit of
               | spreading the same values that we no longer have the
               | stomach to robustly defend here.
               | 
               | Yet when a tyrant goes crazy in Overthereistan we're all
               | sweetness and light and our digital "doors are always
               | open for freedom". Those double standards are not a good
               | look.
               | 
               | I need more time to think about it, but maybe what irks
               | me here is simple hypocrisy.
        
               | KarlKemp wrote:
               | > Liberty requires a persistent effort to maintain
               | against politicians, malevolent actors generally
               | 
               | Politicians do not in general work to abolish democracy.
               | The vast majority, in democratic countries, accepts and
               | supports it. To just label them "malevolent actors"
               | without even feeling the need to explain it is nihilistic
               | cynicism: if all you ever do is scream at the top of your
               | lung that someone is a corrupt scumbag, they will either
               | adapt and become someone like that or quit.
        
             | Shish2k wrote:
             | My site blocks tor nodes not because I hate privacy, but
             | because the overwhelming majority of spammy / abusive
             | content was posted over the tor network, and blocking tor
             | improved the signal:noise ratio better than the best anti-
             | spam tools :/
        
             | webmaven wrote:
             | _> We need to be in an international military crisis in
             | order that basic values of privacy prevail at home?_
             | 
             | Pretty much, yes. The US benefitted hugely from defining
             | itself in opposition to the Soviet bloc during the Cold
             | War. It's a major countervailing force to growing to
             | resemble your opponent.
             | 
             | Arguably, the US hasn't really figured out how to
             | effectively define itself in opposition to China, given how
             | liberally China has been copying parts of the US economic
             | playbook (ie. "Capitalism with Chinese characteristics"),
             | which itself is a trick the Soviets never managed.
        
         | cronix wrote:
         | Use nitter.net to view twitter. Just
         | http://nitter.net/username. It barely uses javascript (except
         | if you want to watch video), no ads, no popups, no login, no
         | "trending" section. Just the content of the person you're
         | trying to read content from. All twitter links are replaced
         | with nitter links, so navigation isn't an issue. Even if I had
         | a Twitter account I'd use Nitter to browse. It's a lighter
         | experience with no extra crap.
        
           | shosca wrote:
           | You can also use https://github.com/SimonBrazell/privacy-
           | redirect to auto redirect from twitter to nitter
        
             | amatecha wrote:
             | Oooh this is great, thank you. I've been wanting to set up
             | something like this for quite a while and haven't really
             | spent the time to figure out how I'd do it. Glad to have an
             | option just land on my screen like this! Cheers :)
             | 
             | Also just realized there are one or two other services they
             | could redirect (e.g. Medium -> scribe.rip). Will see if
             | it's feasible for them to easily add...
        
           | matheusmoreira wrote:
           | I imagine Twitter isn't too happy about this.
        
           | mouzogu wrote:
           | thanks, i really like this. i've been using the ublock zapper
           | to get around twitters obnoxious sign up wall.
           | 
           | i feel like websites like this, and archive.ph are a sign of
           | the future web. very little or now javascript, very light and
           | fast - it inspires me to want to build something again.
        
             | cgb223 wrote:
             | How do I set up uBlock to get around the sign in wall?
             | 
             | Or is zapper a separate add on?
        
             | Akronymus wrote:
             | For me, it just completely breaks scrolling on twitter.com.
             | 
             | Guess I am gonna go for nitter in the future.
        
             | hombre_fatal wrote:
             | That said, hard to feel like it's the future of the web
             | when it's just wrappers around the services that people are
             | actually using.
        
           | MuffinFlavored wrote:
           | How to make this work with private accounts of people you
           | follow? Is there a way to "log into Nitter"?
        
         | Whateverest wrote:
         | I am not a twitter user, but I guess the focus is on
         | circumventing censorship rather than privacy.
        
           | [deleted]
        
           | edgyquant wrote:
           | I don't see how those are exclusive? You need privacy to
           | circumvent censorship
        
             | notatoad wrote:
             | imagine you're living in a country that's currently
             | blocking twitter, but somebody is posting essential
             | information on twitter that you need to read.
             | 
             | twitter on Tor circumvents that censorship. giving twitter
             | your phone number is irrelevant to that.
        
               | pjerem wrote:
               | > but somebody is posting essential information on
               | twitter
               | 
               | Tell that somebody that websites exists.
        
               | sodality2 wrote:
               | Which have terrible discovery compared to social media.
               | Make a website about a hobby and you're unlikely to get
               | many views. Post it on social media and you'll get way
               | more
        
               | pjerem wrote:
               | Ok. But here someone is going to use Tor to reach
               | "essential" information on Twitter.
               | 
               | I don't think there is so essential information on
               | Twitter that anyone would take the hassle to read it
               | through Tor.
        
               | roywiggins wrote:
               | A surprising amount of timely information from public
               | institutions (everything from road conditions to "it's
               | not a real nuclear attack[0]") is often _much_ more
               | accessible via Twitter than anywhere else.
               | 
               | [0] https://www.theatlantic.com/international/archive/201
               | 8/01/wh...
        
               | [deleted]
        
               | micromacrofoot wrote:
               | It's a little relevant. Twitter limits what you can see
               | when you're logged out now, and if Twitter were breached
               | your personally identifying information could leak out
               | and put you in a dangerous situation.
               | 
               | Be careful out there friends!
        
               | notatoad wrote:
               | it's a little relevant if you're the person sharing
               | sensitive information that the government is trying to
               | suppress. And if you're doing that, then yeah, take steps
               | to keep yourself safe.
               | 
               | if you're just trying to read information, like 99% of
               | the people on twitter, then it's not really relevant.
               | it's an unlikely hypothetical in the first place that
               | twitter leaks those phone numbers, but no government is
               | using phone numbers to hunt down consumers of
               | information.
        
               | micromacrofoot wrote:
               | It's not at all unlikely that a major service is hacked,
               | especially at wartime. Twitter has been breached multiple
               | times before.
        
               | thaumasiotes wrote:
               | > Twitter on Tor circumvents that censorship. Giving
               | Twitter your phone number is irrelevant to that.
               | 
               | Until the country you're living in gets your phone number
               | from Twitter...
        
         | mmaunder wrote:
         | Privacy and freedom theater.
        
           | belter wrote:
           | It used to have some use before they started with their dark
           | patterns. Can't stand their mandatory use of a phone
           | number...
        
         | david_draco wrote:
         | Logging in is also annoying via Tor, requiring so many CAPTCHAs
        
       | hereforphone wrote:
       | And they'll still delete tweets they disagree with.
        
         | unixbane wrote:
        
       | samstave wrote:
       | We need a site called "Squitter" ("squatting like twitter")
       | 
       | But instead, you cant comment, interact at all. Its just empty
       | profiles that one browses.
        
         | exikyut wrote:
         | Possibly what you're asking for: https://www.shlinkedin.com/
        
       | sneak wrote:
       | You can't create a usable Twitter account without providing a
       | phone number, however, so this is effectively a meaningless
       | gesture.
       | 
       | Twitter does not want Twitter users to have privacy or
       | pseudonymity from Twitter.
        
         | FDSGSG wrote:
         | You can just use a service like SMSPVA, phone verification
         | doesn't break anonymity. It's a reasonable anti-spam measure,
         | you have to burn a tiny amount of cryptocurrency in order to
         | register.
        
           | Madmallard wrote:
           | cryptocurrency isn't anonymous though?
        
             | FDSGSG wrote:
             | What do you mean? Monero is definitely anonymous. Obviously
             | all cryptocurrencies aren't anonymous, but anyone with half
             | a brain can understand that I'm referring to anonymous
             | cryptocurrencies.
        
           | waffle_ss wrote:
           | Many of these services use a limited pool of phone numbers
           | that have already been used to register accounts on Twitter,
           | and Twitter won't let you use them for fresh signups.
        
             | FDSGSG wrote:
             | SMSPVA has thousands of numbers that haven't been used on
             | twitter, it also wont recycle the same numbers for the same
             | service.
        
               | waffle_ss wrote:
               | Glad to hear they thought of that - I haven't used this
               | particular service before. However, I just looked at it
               | and there are zero United States numbers available to
               | rent for Twitter signups right now.
               | 
               | I could use one of the European numbers but given my
               | experience with how sensitive Twitter is to sketchiness
               | I'm guessing I'd get more random phone number
               | verification requests.
        
               | FDSGSG wrote:
               | IME twitter doesn't care at all about which country your
               | number is from.
        
         | roastedpeacock wrote:
         | Unfortunately I just checked with the new onion service and it
         | appears nothing else has changed in that regard.
        
         | Asraelite wrote:
         | Sometimes you can't even view tweets if you're not logged in
         | (there are workarounds though). Viewing media and threads also
         | has extremely limited functionality in embedded contexts.
         | 
         | This move is actually hilarious considering Twitter's policies.
        
         | dmak wrote:
         | Yeah you can. I created 3 in the last 3 months for different
         | projects without linking a phone number. You just click
         | register with email.
        
           | sneak wrote:
           | The account will be effectively suspended after following
           | more than about ten people until you add a phone number.
        
       | paulpauper wrote:
       | prepare for captchas everywhere, phone verification everywhere
        
         | ComputerGuru wrote:
         | It just requires a regular login, 2fa or otherwise. Once the
         | session cookies are there, it would presumably continue to
         | behave as normal.
        
           | paulpauper wrote:
           | Tor IPs are very low trust and will trigger phone even if you
           | logged in
        
             | bombcar wrote:
             | Hence the .onion, so you never leave tor (for twitter at
             | least).
        
       | Normille wrote:
       | This Ukraine crisis is a goldmine for fans of hypocrisy and cant.
       | 
       | I thought Shell's [0] trying to grab the moral high ground by
       | withdrawing from Russia would take some beating. But "cancel
       | culture central" Twatter spluttering about censorship gives it a
       | run for its money.
       | 
       | [0] https://www.amnesty.org/en/latest/news/2017/06/shell-
       | complic...
        
         | [deleted]
        
       | LWIRVoltage wrote:
       | That is interesting but we run into something that is now
       | prevalent- I don't use it, but Twitter requires a phone number at
       | singup, right?
       | 
       | This is the same issue that is going on really heavily right now
       | with Microsoft Accounts(and they are about to force the entire
       | playerbase of Minecraft to give a phone number by pushing them to
       | Microsoft accounts starting a day or two from now) (Note:This
       | occurs without trying to use TOR during MS account creation, the
       | system will lock you out afterwards- I assume TOR would be even
       | more difficult)
       | 
       | To my understanding, even Protonmail has a odd requirement where
       | you have to verify by making a donation, if you try to initially
       | sign up with TOR- and sure, they might only keep a hash , but
       | this is a risk as someone could generate a hash of all potential
       | phone numbers and them compare.
       | 
       | Logging in via TOR afterwards to protonmail is good and all, but
       | you aren't fully private then and can be compromised with out
       | recourse it appears. [VPN would probably be the way to get around
       | this][Protonmail is still probably the strongest option,
       | especially since they won that court case they sued the Swiss gov
       | in after being made to help the french government in that one
       | case- now they are not able to be coerced at all - nontheless
       | this signup TOR quirk is the only major thorn.]
       | 
       | I get the feeling no one realizes that you have these additional
       | hoops to creating an account on any service- and that data they
       | force you provide, could be subject to a subpoena in a
       | jurisdiction where they don't like something you did, etc ,etc.
       | And no, VOIP numbers and burner numbers are now auto-detected by
       | these services and pre-blocked en masse.
       | 
       | I agree with another poster, Signal is probably okay in needing
       | one, and they are working on removing that and providing unique
       | identifiers at least, along with stripping as much metadata as
       | they can. Other services seem to be going towards a point where
       | you're at the mercy of whoever can compel or read the data they
       | required of you to use services that did not require this.
       | 
       | I wish services would instead turn towards TOTP and other
       | authentication, to avoid spam. The fact that that sort of
       | substitute doesn't allow one to bypass giving up details like
       | Phone numbers- suggests it's about the data, not authentication
       | or anti-spam, since they offer no alternate.
        
         | aww_dang wrote:
         | Another one is Telegram, a service which requires you to
         | install an app on a mobile device and provide a phone number.
         | It markets itself as a privacy app...
        
           | coolspot wrote:
           | It looks like almost all trendy "privacy" apps require a
           | phone number: Signal, Protonmail...
        
         | reflexco wrote:
         | How would you use TOTP to mitigate spam exactly?
        
           | LWIRVoltage wrote:
           | If the idea is to stop some sort of massed emailing or
           | posting or whatnot, using TOTP as a requirement to take those
           | actions would slow that down to once every 30 seconds-
           | 
           | if it's a matter of access and authentic access(as
           | Microsoft's 'message' when they lock you out notes<suspicious
           | activity>)) TOTP on actions a user may do, should cut down on
           | the idea that an account is hacked.
           | 
           | An initial idea -
           | 
           | If they are worried about account creation being too fast, I
           | suppose one idea then would be a TOTP client-side program
           | that generates a unique account-generation code, one would
           | need to create an account on a service to begin with- and
           | time limit that from both sides, if the worry is a lot of
           | accounts being generated in too short a time. This way, one
           | can always kill the client code generator, and reinstall it,
           | but overall that doesn't get around the fact you need that to
           | make a full account on the service, and this would slow down
           | creation from someone while not using phone numbers or other
           | meta-data that would be usable against them from a privacy
           | perspective.
           | 
           | I would also look at how the teams from Signal, etc- are
           | tackling that while reducing meta-data
           | 
           | if the idea is indeed about having some method to track the
           | user in a way you can discover other info about them through
           | subsequent means directly, then that's ...what we'd want to
           | avoid.
        
         | [deleted]
        
         | ectopod wrote:
         | > they are about to force the entire playerbase of Minecraft to
         | give a phone number by pushing them to Microsoft accounts
         | starting a day or two from now
         | 
         | Insisting on phone numbers would be a breach of the GDPR.
         | Having entered into a contract a business cannot then demand
         | additional personal information as a condition of fulfilling
         | the contract.
        
           | LWIRVoltage wrote:
           | ...Does their current method get around this? They let you
           | make the account, then a week or two later at most when you
           | log in, it flags you and tells you due to 'suspicious
           | activity', you now have to enter a phone number to get in
           | specifically- as the account is now locked out otherwise. And
           | VOIP numbers and burner numbers are autodetected and the
           | system says to find a different number...
           | 
           | Since they allow you to initially make the account, i wonder
           | if that lets them 'attempt to' bypass this -
           | 
           | Also, if that became a pain point eventually, they could make
           | it so accounts made with European IP addresses from certain
           | regions avoid this. (I think i've read on Reddit that
           | european players get affected, but after contacting microsoft
           | and citing GDPR with a form, they unlocked it- alas, the US
           | and the rest of the world is forced to give a number then
           | (not counting south korea which is a special case i've read)
        
       | cosmiccatnap wrote:
        
       | CyberRabbi wrote:
       | IMO this is not very useful because any speech for which you'd
       | want anonymity will likely be banned on Twitter anyway.
       | 
       | You can jump through the hoops of procuring anonymous email
       | address and phone numbers but in the end Twitter will ban any
       | real political dissent. Cf. Last two years.
        
         | KarlKemp wrote:
         | Have you seen the news in, like, the last three weeks?
        
           | CyberRabbi wrote:
           | How does the news in the last three weeks refute my comment?
        
         | M2Ys4U wrote:
         | Calling Russia's war against Ukraine a "war" is speech that
         | Russians in Russia _need_ anonymity for _right now_. And that
         | 's not banned by Twitter.
        
           | CyberRabbi wrote:
           | There are certainly examples of political dissent that are
           | not regularly banned by Twitter but that doesn't negate the
           | fact that there are also examples of political dissent that
           | are regularly banned by Twitter, which is the point of the
           | OP.
        
         | mrtranscendence wrote:
         | There's a bunch of political dissent on Twitter. Don't harass
         | people or incite violence and you'll largely be OK.
        
           | hunterb123 wrote:
           | > and you'll _largely_ be OK
           | 
           | As long as you don't talk about a certain lab leak, or a
           | laptop, yup!
           | 
           | Oh wait, they decided those are allowed _now_ , sorry.
        
             | Shared404 wrote:
             | > When the debate is lost slander becomes the tool of the
             | loser
             | 
             | I like that quote from your profile, I think I'll start
             | using it!
        
               | hunterb123 wrote:
               | Thanks, go for it, you'll have lots of opportunities to
               | nowadays.
               | 
               | Fun fact, it's attributed to Socrates often but there's
               | no record of that.
               | 
               | Snopes says they couldn't find any usage earlier than
               | 2008.
               | 
               | But like most Snopes articles that was wrong as there's
               | someone using it from 2006 here:
               | 
               | https://web.archive.org/web/20060529060643/http://freedom
               | key...
        
           | CyberRabbi wrote:
           | Twitter does not permit tweets that question or invalidate
           | the official information coming out about COVID.
           | 
           | "You may not use Twitter's services to share false or
           | misleading information about COVID-19 which may lead to
           | harm."
           | 
           | https://help.twitter.com/en/rules-and-policies/medical-
           | misin...
           | 
           | Only blessed dissent is permitted.
        
             | [deleted]
        
             | hunterb123 wrote:
             | The banning of Dr. R0b3rt MAl0n3 was peak irony of that
             | rule.
             | 
             | (had to use l33tspeak, was insta-flagged for saying his
             | name, bot?)
             | 
             | He invented the initial mRNA platform and performed the
             | first mRNA vaccine experiments in 1989.
             | 
             | That info was removed from wikipedia, but here's an
             | archived version:
             | 
             | https://web.archive.org/web/20210614140319/https://en.wikip
             | e...
             | 
             | There's 9 patents in his name for the platforms and his
             | name is all over the original mRNA experiments.
             | 
             | He was banned for misinformation regarding the Covid-19
             | vaccine...
        
             | Akronymus wrote:
             | So, science as more of a cult than the scientific method?
        
             | [deleted]
        
       | chrisamillions wrote:
        
       | 2Gkashmiri wrote:
       | meh. without the mandatory mobile verification, twitter is simply
       | pointless to use via tor. maybe you are registered via mobile in
       | a different country and you are currently in a hostile nation. if
       | you are registered in the same country you are in, speaking
       | against the government is pointless.
       | 
       | maybe there is a usecase, i dont know. i stopped twitter back in
       | 2013 i think. the signal to noise ratio was difficult back then,
       | i cant imagine what it is now. sorry.
        
         | unixbane wrote:
         | > without the mandatory mobile verification, twitter is simply
         | pointless to use via tor.
         | 
         | i literally cannot understand your post. why would you ever
         | want mobile verification unless for (crappy) 2fa purposes?
        
           | NikolaNovak wrote:
           | It's not well phrased; I _think_ OP is trying to say that if
           | /since you cannot pass Twitter's mandatory mobile
           | verification, you can't do anything on Twitter anyway, so Tor
           | is pointless.
           | 
           | I could be mis-interpreting.
           | 
           | I agree that supporting Tor, but mandating phone, are
           | completely contradictory stances for a platform to take. None
           | of the posts here so far about "circumventing ISP blocks"
           | feel persuasive or even realistic - if ISP is blocking
           | platform such as twitter, they are doing it for a reason, and
           | 9 times out of 10, that reason extends to you not wanting to
           | give up your phone.
        
           | 2Gkashmiri wrote:
           | because twitter is "forcing" you to give them mobile number
           | for saving their asses when governments knock on their doors.
        
         | neilalexander wrote:
         | It's not about accessing Twitter anonymously. It's about being
         | able to access Twitter when ISP-level blocking is in place.
        
           | 2Gkashmiri wrote:
           | i would disagree. ISPs "generally" do not willy nilly
           | restrict access to websites out of pleasure. it is either
           | those anti-piracy shenanigans or other than that almost
           | always government mandated. if a government DOES NOT want you
           | to use twitter, your using it signifies to them you are a
           | person of interest and they can put more efforts into finding
           | you. i know because i have been a subject to those enquiries.
           | They are not fun
        
       | b0mbadilh0le wrote:
       | So you can be censored anonymously?
        
         | warent wrote:
         | This seems like troll bait. The ELI5 version is that rich
         | people and police are scary, so big companies have to please
         | them.
         | 
         | I'm not sure if you live in a communist nation, because people
         | who really don't want to be censored are welcome to host their
         | own Mastodon server or similar
         | 
         | https://joinmastodon.org/
        
         | jliptzin wrote:
         | To all the idiots still complaining about censorship: there is
         | more to the internet than twitter, Facebook, and YouTube. You
         | can even build your own website!
         | 
         | Private individuals have the right to free speech; private
         | companies have the right to not host your speech on their
         | private platforms; you have the right to make your own
         | platform.
        
       | travisgriggs wrote:
       | Now members of the darknet can broadcast themselves. Anyone else
       | see irony here?
        
       | shiado wrote:
       | Everybody should browse the internet on Tor from time to time to
       | get an understanding about how the web works on a second class IP
       | address and a slow connection. On some exit nodes reCAPTCHA
       | actually enters an endless selection where it's impossible to
       | pass.
        
         | blowski wrote:
         | Any specific suggestions for experiencing the difference? I've
         | used Tor a bit, and can't say I noticed a huge amount of
         | difference between that and browsing on a new mobile device.
        
           | dessant wrote:
           | If you're adventurous you could log into Google, PayPal and
           | social media sites. Once you get past captcha challenges and
           | manage to access your account, they may helpfully lock your
           | account and never let you use it again, regardless of how
           | much proof you provide for the ownership of the account to
           | their support staff.
        
             | blowski wrote:
             | I see! That's something I've never done, I've mostly been
             | using it to look at specific sites where I already knew the
             | URL.
        
         | londons_explore wrote:
         | > reCAPTCHA actually enters an endless selection where it's
         | impossible to pass
         | 
         | I believe this is because from the same IP address there are
         | other users who are _failing_ the recaptcha. So in between you
         | starting, and clicking  'submit', there are a bunch of other
         | wrong-answer recaptchas, so, when combined with your correct
         | answer, it looks like you got it correct just by chance, not by
         | being a human.
        
           | dan-robertson wrote:
           | This might be true for massive sites (eg Google) but smaller
           | sites only if the cdn aggregates traffic to many different
           | sites.
        
             | londons_explore wrote:
             | recaptchas logic to check if someone is a bot or not is
             | global and run on googles servers, not site specific.
        
         | matheusmoreira wrote:
         | I wish a new web would form inside Tor instead so we could all
         | leave the old compromised web behind.
        
         | [deleted]
        
           | [deleted]
        
       | agluszak wrote:
       | What an irony, Twitter is available on Tor, but it won't let you
       | browse for longer than 0.3s without forcing to log in.
        
         | nwiswell wrote:
         | Yeah, the intention here is clearly to bypass state censorship.
         | Twitter still wants to serve ads.
         | 
         | Sort of unrelated, but you can bypass the login prompt if you
         | click "login" and then click the X in the upper left of the
         | popover.
        
           | agluszak wrote:
           | Or simply use nitter.net instead :)
        
       | anjbe wrote:
       | One interesting effect of Twitter's onion address: your 2FA
       | options are limited. Any WebAuthn/FIDO/U2F keys you have
       | registered with your Twitter account won't work, because the key
       | registration is tied to the domain name. I have the same problem
       | on Facebook. I can only use these onion sites if I log in with
       | TOTP.
       | 
       | One would think you could re-register the keys while logged in to
       | the onion site, but I've never succeeded with this on Facebook or
       | Twitter. I don't know if there is a technical limitation
       | preventing WebAuthn from being used over onion sites, or just a
       | problem with these particular sites' implementations. Tor itself
       | is not the problem--you can use a registered WebAuthn key over
       | Tor if the domains you're visiting are facebook.com or
       | twitter.com.
        
       | oauea wrote:
       | Is this done to avoid Russian censorship? If so, interesting that
       | Twitter's move is to go out of their way so they can still do
       | business with Russians, while most other companies have decided
       | that the correct choice is to sever all ties.
        
         | yurish wrote:
         | Tor is blocked in Russia.
        
           | kvetching wrote:
        
           | mardifoufs wrote:
           | Im not sure if this has changed since my source was published
           | but according to this article[0], the Tor Blocks in russia
           | are not nation wide and originate from individual ISPs:
           | 
           | >"According to OONI, it wasn't all of Russia blocking Tor; it
           | was 15 out of 65 subnets. Moreover, each censorship instance
           | used a different blocking method"
           | 
           | >"If the censorship was government-sponsored, as the Tor
           | Project suggested, then I would expect it to be much more
           | widespread and consistent. This looks like individual
           | blocking efforts. As OONI noted, the blocks followed a
           | "recent spike in the use of Tor bridges (used for
           | circumventing Tor blocking) in Russia."
           | 
           | Though the situation might be totally different now
           | considering the recent events.
           | 
           | [0] https://www.hackerfactor.com/blog/index.php?/archives/944
           | -To...
        
         | clownbaby wrote:
         | For many companies, the current situation makes it very
         | difficult to continue business operations from a logistical
         | perspective, and because of that they are pulling out of Russia
         | -- they are just using the narrative of boycotting Russia
         | because of atrocities as a PR move which they also are
         | benefiting from.
        
         | pcmoney wrote:
         | Why would you jump to a bad faith conclusion? Why would wanting
         | to keep Twitter accessible to Russian nationals be bad? Twitter
         | doesn't work in many countries such as China. There's just not
         | a whole lot of money in Russia to advertise to either, entire
         | economy is smaller than New York State's.
         | 
         | This is much more aligned with Twitter's push for
         | decentralization.
        
         | atoav wrote:
         | And the BBC is broadcasting their program on shortwave again --
         | I don't think the classical way of thinking about sanctions
         | directly applies to media type organisations.
         | 
         | Of course one could argue russian trolls could use this to
         | influence opinions on twitter as well, but wouldn't the most
         | scary thing for Putin be his Russians getting non-state
         | approved information on the war and the situation in Russia?
         | 
         | If the goal of sanctions is to drive a wedge between the
         | political leadership and it's population, and we assume it
         | works in principle, excluding certain platforms where people
         | can get outside informations might actually be a good thing.
        
         | pigscantfly wrote:
         | I think it is important that normal Russian people have access
         | to outside sources of information to erode popular support of
         | the war; their politicians seem to have no difficulty using
         | Twitter to spread propaganda to the English-speaking world. I
         | doubt the company is making any money from this or accepting
         | Russian advertising, although I admit I don't have evidence to
         | cite.
         | 
         | I'm not affiliated with Twitter, nor do I use it, by the way.
        
           | ashwagary wrote:
           | >I think it is important that normal Russian people have
           | access to outside sources of information
           | 
           | I think this is true regardless of what they do with the
           | information. Malice aside, I don't think freedom of
           | information needs to necessarily serve another group's
           | interest to be a worthy cause.
        
         | w-j-w wrote:
        
         | ComputerGuru wrote:
         | Yes; BBC just made its news available over tor a few days
         | before: https://www.bbc.co.uk/news/technology-50150981 (with
         | the stupid title _BBC News launches 'dark web' Tor mirror_)
        
           | defanor wrote:
           | I wondered why they do it back then, and wondering about
           | Twitter now: when trying to access those from Russia, if you
           | use Tor, it's easy to access the website on its regular
           | address via an exit node. Of course an .onion wouldn't harm,
           | but it doesn't make much difference. On the other hand, the
           | government tries to block Tor in Russia since the last year,
           | the bridges that used to work don't work anymore, and even if
           | you obtain new ones to which you manage to connect, somehow
           | Tor still fails to complete a connection to the network (I
           | didn't investigate further yet). So a regular mirror is
           | likely to be more useful than an .onion one (even though it's
           | also likely to be blacklisted soon).
        
       | defeatcensors wrote:
       | Adding to the thread, there's also a directory of "real-world"
       | onion services at https://www.yellowonion.org
        
       | goodpoint wrote:
       | To all the people who complain that Twitter over Tor is pointless
       | because you have to login: it's not.
       | 
       | A lot of people might have no concerns with identifying
       | themselves with twitter but might be blocked by their ISPs or
       | worried about some governments tracking them down.
       | 
       | In those cases twitter over Tor makes a lot of sense.
       | 
       | (and no, I'm not a fan of twitter myself and I don't use it)
        
         | unixbane wrote:
         | why would it be pointless? everything should be anonymous by
         | default. that's how the internet always worked before corpo
         | scum shat all over it.
         | 
         | now the next question is whether you can actually _do_ anything
         | over Tor on there. do they block you from half the
         | functionality, such as searching, scrolling, etc? do they still
         | pointlessly force a phone number as opposed to it being
         | optional (why did this trend start right after snowden anyway)?
         | can you even write a post? is this article just some PR
         | generated crap and tor is still actually fully blocked? are
         | they able to implement their trivial web application without
         | javascript yet (so tor browser can be run in safe mode)? i made
         | some accounts on tor 10 years ago there and they silently got
         | deleted / shadowbanned (it seems the ones i used to DM a pre
         | existing account got deleted)
        
           | MayeulC wrote:
           | The post you reply to implies that you have to login in order
           | to access it.
           | 
           | That's a good first step IMO, as this should balance out some
           | fears of abuse from them. But I wouldn't be surprised if you
           | can't create an account from Tor.
        
       | randomsearch wrote:
       | Truly incredible that it is not recognised that Twitter is part
       | of the problem and not the solution.
       | 
       | Somehow extensive journalism and investigation by government
       | bodies seems to have been completely lost in the noise.
       | 
       | Twitter and Facebook have been weaponised brilliantly by the
       | Russians. They are a big part of how we got here.
        
         | [deleted]
        
         | Slikey wrote:
         | I believe Twitter is trying to be better though and it appears
         | they do chip away at this. They have also been in a difficult
         | situation between cancel culture and free speech absolutism.
         | Determining the reasonable solution is hard when the extreme
         | edges and vocal minorities are yelling at you. My personal hope
         | is that Twitter will further crack down on the very low hanging
         | bots / trolls / alt accounts - there are many especially young
         | accounts with handles like @Name359345809 which don't
         | contribute to the platform in any way.
        
         | ashwagary wrote:
         | If abuse is dealt with adequately (which is a tall task), this
         | approach allows more worldwide discussions which is a
         | productive mission.
         | 
         | Being able to remove ones self from heavily controlled
         | corporate echo chambers is refreshing to thinkers that strive
         | for objectivity.
        
         | dash2 wrote:
         | Actually I think Twitter has been at its best, at least since
         | the start of the invasion. I've been able to access expertise,
         | military and political; see eye-witness video from Russia and
         | Ukraine; follow the news minute by minute. Bullshit has been
         | called out. People have worked to geolocate war crimes. Russian
         | trolls have completely failed to control the narrative.
         | Ukraine's indomitable tractor drivers have nicked tanks. And
         | the best evidence for this is the Russians shutting it down.
        
           | practice9 wrote:
           | And Twitter is the only platform that actually suspends the
           | reported Russian disinformation bot/troll accounts (Youtube
           | is bad at this)
        
           | WanderPanda wrote:
           | This is exactly my experience as well. Extremely high quality
           | information with bullshit directly being called out (even in
           | the case of pro Unrainian fake news like the ,,ghost of kiev"
           | thing). I was waiting for the russian propaganda bots all the
           | time but they never showed up (except for one youtube video
           | where the whole comment section was full of whataboutism).
           | Compared to what you get from curating a hand full of twitter
           | accounts with a good track record / reputation traditional
           | media and government outlets are pure noise in my experience.
        
           | wolverine876 wrote:
           | > Bullshit has been called out.
           | 
           | Research and, IMHO, reason show that unless you have real
           | domain expertise or direct experience of the event, you can't
           | distinguish well-crafted bullshit from truth.
           | 
           | > I've been able to access expertise, military and political
           | 
           | Those are accessible outside Twitter. Better, the expertise
           | is less diluted by noise, and you get expertise + focused
           | work (papers and articles, with editors, etc.) not hot takes.
           | Just read foreign policy publications like Foriegn Policy or
           | Foreign Affairs.
           | 
           | > Russian trolls have completely failed to control the
           | narrative. ... And the best evidence for this is the Russians
           | shutting it down.
           | 
           | That may be true in this case (I am not so ready to conclude
           | it), but we know well that it hasn't been true in many others
           | and won't be true in yet more, and people can't distinguish.
           | Also, that does't mean others don't control the narrative -
           | people who using the crisis for their own ends or even people
           | you coincidentally support.
        
             | dash2 wrote:
             | It's true that expertise is available outside Twitter, but
             | Twitter has been great at letting me find it. The mechanism
             | is retweets from people I trust. Note, trust also helps
             | distinguish bullshit from truth. I don't know what a
             | Javelin is, or how the war in the south is progressing, but
             | the right journalist can find the right expert who does.
             | 
             | I don't say these problems have been solved perfectly, just
             | that they're better than I expected.
        
         | anonporridge wrote:
         | True, but a conversation about that can't exclude the fact that
         | state sponsored information streams have been weaponized ever
         | since the first states started providing official information.
        
       | ur-whale wrote:
       | Most excellent first step.
       | 
       | Now please get rid of the 'have you signed in yet?' popup, and
       | you'll be back to being an actual useful resource on the
       | internet.
       | 
       | [edit]: and in the meantime, I'll keep on using nitter.net
        
         | [deleted]
        
         | potatoman22 wrote:
         | What's in it for Twitter?
        
           | iszomer wrote:
           | Maybe they want to improve their fingerprinting heuristics by
           | providing an illusion of anonymous communications over Tor?
           | /shrug
        
           | uwuemu wrote:
           | If they want to be a walled garden, they can be a walled
           | garden. But no embeds, no free traffic from all the news
           | sites and blogs. No free traffic from google. You can't have
           | the cake and eat it too. All of this scumbaggery with serving
           | X to google and serving Z to the humans has to go. It's
           | internet cancer. And I don't use that word ligthly. It's not
           | just Twitter that does this, instagram, facebook, etc. all do
           | this. It should have been regulated away a long time ago and
           | harshly fined because THAT is what makes the current internet
           | not open. Internet is about free(ish) access to information,
           | and like it or not, Twitter is the current "breaking news"
           | creator and aggeregator #1 (by orders of magnitude). If an
           | adult voluntarily posts content to twitter, content that is
           | intended to be public, an twitter tries to prevent public
           | access to that information, a reaction to that should be
           | disgust, not saying "what's in in for twitter". What's in it
           | for ME. Me. Me. Me. I. My family. Maybe my friends. My
           | company. Everyone else can go fuck themselves, right?
           | 
           | The situation with Ukraine and a lot of news and media
           | breaking on twitter are a current, glaring representation of
           | how twitter makes money on people's suffering... but it isn't
           | the first and sadly won't be the last, because of people like
           | you.
        
         | tonguez wrote:
         | In order to begin being an actual useful resource on the
         | internet they have to, among other things, get rid of the
         | feature where you have to click "load more" 10 times to read
         | the small fraction of replies to a Tweet that Twitter does not
         | censor completely.
         | 
         | If a tweet has 100 replies, it generally only shows the most
         | pro-neocon/PC response, and you have to click "Load More", then
         | it will show 1 more response, you keep clicking "Load More",
         | and eventually there's no more "Load More" button, and you've
         | only seen 5 responses. Where are the other 95 responses that
         | Twitter deemed to be wrongthink?
         | 
         | Why would anyone use a website like that when you're only
         | getting curated propaganda? It's like sitting in front of the
         | TV and only watching ads with no actual content.
        
           | guelo wrote:
           | That "load more" is extremely annoying. I believe it's an a/b
           | test because I only see it with one of my accounts. It seems
           | to get triggered when the http referer is from another social
           | site. I found you can get rid of it by re-opening the link in
           | another tab by control-clicking on the tweet timestamp.
        
         | FabHK wrote:
         | Plus the "it's better in the App!" popup on mobile, and the
         | requirement for Javascript just to serve 280 characters...
        
           | rplnt wrote:
           | And when I click the "open in the app", it doesn't even work.
        
             | snek_case wrote:
             | Reddit has the same bullshit problem. The website works
             | perfectly fine on mobile, except it keeps trying to force
             | you to use the app for absolutely no reason, and the app
             | often works poorly.
        
               | egberts1 wrote:
               | Not to mention the iPhone App made by Reddit is that one
               | giant sucking sound of your privacy.
        
         | [deleted]
        
         | ChrisArchitect wrote:
         | This is not a real problem as tweets and their replies are all
         | publicly available. Likely brought on yourself by using ad-
         | blocker or something triggering it (which Twitter has every
         | right to try to encourage you to log in or use the site more
         | regularly)
        
         | kilroy123 wrote:
         | This a million times
        
         | NikolaNovak wrote:
         | (and if you DO want me to sign up, do not mandate a telephone
         | number; you don't need it, I don't want to give it to you)
        
           | segmondy wrote:
        
             | NikolaNovak wrote:
             | Yes.
             | 
             | I may be in minority, but yes.
             | 
             | Understanding that "Free" is the only way to grow a
             | platform, once there, I'd happily pay $X/month for
             | Facebook, Twitter, etc that's customizable to the format
             | and amount of tracking that I want.
             | 
             | That is completely unrealistic, of course, but that wasn't
             | your question, so I can happily and honestly answer "Yes"
             | :)
        
               | amatecha wrote:
               | there used to be such a service, App.net[0], which was
               | basically "paid twitter". It was pretty awesome. Not only
               | was there the App.net client which was an analogue to
               | Twitter, devs could make other services which you could
               | log into with your App.net identity, for example there
               | was an excellent Instagram-like app "Favd"[1] that could
               | post to Twitter, FB and App.net.
               | 
               | [0] https://web.archive.org/web/20130116194906/https://ap
               | p.net/a...
               | 
               | [1] https://web.archive.org/web/20140922104251/http://pic
               | .favd.n...
        
               | zeepzeep wrote:
               | > I may be in minority, but yes.
               | 
               | Do you know what's the best thing about that? It's okay
               | if only a part of the population pays for each service.
               | 
               | If enough people have Twitter Blue to make Twitter
               | profitable, and are enjoying the comments and type of
               | content the tons of non-paying users are making, it's
               | win-win.
               | 
               | One person hast Twitter Blue, another one has Facebook
               | Deluxe, and some others don't pay for online services at
               | all. But these who don't pay are creating content people
               | are willing to pay for.
               | 
               | That's how free to play games work, so it's not
               | unrealistic.
        
               | NikolaNovak wrote:
               | Exactly; I'm happy to be a "Whale" on a number of games
               | and services :)
        
             | ComputerGuru wrote:
             | Twitter's financials are public. They aren't making any
             | obvious money from having your phone. It's more likely
             | there to let them stop people from harvesting/selling
             | accounts.
        
             | eatsyourtacos wrote:
             | Hard to use that logic when there are a small monopoly of
             | services out there.
        
           | bena wrote:
           | I agree, but I do find this take funny considering the
           | history of Twitter.
        
             | amatecha wrote:
             | Right, I remember you used to be able to sign up for
             | Twitter solely with a phone number (and post tweets via
             | SMS, a feature which I used every so often). You can see
             | that if you look at an old archive of the site: https://web
             | .archive.org/web/20061203201128/http://twitter.co... (heh,
             | also gotta love that the site was so small they can just
             | show some random recent tweets and users right on the
             | homepage)
             | 
             | This was in the days before legit smartphones so running an
             | actual "twitter client" was out of the question. Of course
             | that all quickly changed with the advent of smartphones
             | like the iPhone.
        
           | car_analogy wrote:
           | Oh they don't - you can sign-up without one, and iirc,
           | Twitter doesn't indicate anywhere that one is needed. But all
           | new accounts just happen to exhibit suspicious activity and
           | are blocked until submitting a phone number. This is all mere
           | coincidence, and certainly not an effort by Twitter to
           | conceal how much personal information they want for an
           | account.
        
       | ed25519FUUU wrote:
       | How much compute power does it take to mine these vanity .onion
       | domains?
        
         | dkarp wrote:
         | according to [1], about a day for the 7 character twitter url
         | on a 1.5GHz machine. So nothing really for a company like
         | twitter.
         | 
         | [1] https://github.com/katmagic/Shallot
        
           | beardog wrote:
           | Shallot (at least that version) is for v2 onions only which
           | are truncated sha1 hashes of RSA keys. v3 onions are
           | base32-encoded ed25519 so 7 characters translates to needing
           | to force 35 bits of ed25519, which according to [2] should be
           | in the same ballpark but does not get specific as far as I
           | read.
           | 
           | [1]https://gitweb.torproject.org/torspec.git/tree/rend-
           | spec-v3....
           | 
           | [2]https://github.com/cathugger/mkp224o
        
             | kevin_thibedeau wrote:
             | EC keys don't require a search for prime numbers so it
             | should be faster.
        
               | beardog wrote:
               | Plus it doesn't use the sha1sum, not to say it is a
               | particularly slow function.
        
           | edm0nd wrote:
           | No one can use a v2 onion address any longer. They do not
           | resolve. V3 .onion vanity urls can be created using
           | https://github.com/cathugger/mkp224o
        
       | smlavine wrote:
       | > JavaScript is not available.
       | 
       | Sure it is.
        
       | mooreds wrote:
       | More details from the thread:
       | 
       | https://help.twitter.com/en/using-twitter/twitter-supported-...
       | lists the Tor network as a supported browser
       | 
       | Implemented using https://github.com/alecmuffett/eotk/
       | 
       | Edit: made URLs clickable as well.
        
         | awb wrote:
         | Making URLs clickable.
         | 
         | More details from the thread:
         | 
         | * https://help.twitter.com/en/using-twitter/twitter-
         | supported-... lists the Tor network as a supported browser
         | 
         | * Implemented using https://github.com/alecmuffett/eotk/
        
           | mooreds wrote:
           | Thanks, sorry about that, updated my comment too.
        
       | jquery wrote:
       | I'm taking off my cynical goggles and giving this a round of
       | applause. Even if I think Twitter could do more, this is a great
       | move on their part.
        
       | noasaservice wrote:
       | Is it still going to require to deanonymize yourself with a real
       | cell phone number? As opposed to a virtual phone# like GVoice,
       | Trello, etc?
        
         | caymanjim wrote:
         | Why require any phone number? I hate Twitter and won't use it
         | either way, but they have no business asking for phone numbers.
        
           | Stevvo wrote:
           | Originally Twitter was over SMS. That's why Tweets were
           | limited to 140 characters; it's all you could fit. So they
           | did have a reason to ask for phone numbers from the
           | beginning.
        
             | barbazoo wrote:
             | Ok but now, what feels like a 100 years later, they don't
             | anymore. It's just another data point to identify users and
             | sell that information eventually.
        
             | maerF0x0 wrote:
             | And today the hard requirement is???
        
           | rhexs wrote:
           | Have you tried making any accounts online these days without
           | a phone number? Good luck -- there are extremely few services
           | left that allow it due to "abuse" and other nonsense.
           | 
           | My favorite case of this is that you used to be able to
           | create a google account through android without a phone
           | number. Assuming this is still possible, if you do this your
           | account will be immediately suspended for "suspicious
           | activity" and require a phone to unlock.
        
             | betwixthewires wrote:
             | I use one service that requires a phone number: Signal. I'm
             | doing alright on the internet. If your service requires a
             | phone number to sign up, I will not use it, period. If more
             | people thought like me this would be a problem, but the
             | majority seems hell bent on spreading their cheeks for
             | peanuts these days.
        
           | noasaservice wrote:
           | If you hate twitter so much, then respectfully, why are you
           | commenting? This post is exclusively about Twitter and Tor.
        
             | NikolaNovak wrote:
             | Not OP but my 2 cents:
             | 
             | "Hate" / "Dislike" / Critical Post / Negative comment, is
             | just as valid as "Love" / "Like" / Positive Comment. Either
             | may be productive (constructive feedback or earned support)
             | or unproductive (pointless criticism as much as baseless
             | love).
             | 
             | In fact, as owner of any service/product/store,
             | constructive negative feedback is valuable. My wife is a
             | store manager and subscribes to "Feedback is a gift"
             | philosophy - is a customer is going to leave, she'd
             | appreciate knowing, in constructive way, why they are
             | leaving.
        
             | hunterb123 wrote:
             | So people are only allowed to be positive on topics? I
             | don't think HN got that memo.
             | 
             | Don't open a Tesla, Facebook, or crypto article, you'll be
             | shocked to see how many people hate those things and are
             | commenting anyway!
        
             | caymanjim wrote:
             | There's a general tone of commentary here that it's good
             | that Twitter is accepting Tor connections. I think that's a
             | good thing. There's also a lot of side-commentary about how
             | Twitter shouldn't be overly-praised for this because they
             | follow plenty of other dark patterns, most notably
             | requiring a login and collecting phone numbers and other
             | personal information. The main reason I hate Twitter is
             | because of their dark patterns (and shitty UI). If they
             | stopped collecting phone numbers, I'd hate them less.
        
         | Minor49er wrote:
         | I tried to create an account a few months ago with virtual
         | phone numbers since I don't want to give it my real one. Every
         | attempt was rejected
        
           | sandeeps_ wrote:
           | It's possible to create a twitter account without a phone
           | number. You'll initially get suspended and get an email
           | stating why. Just reply to that email (open a ticket) and
           | they will approve the account without a phone number.
        
           | paulpauper wrote:
           | use a proxy, a new chrome session, and throwaway email
           | address.
        
             | Minor49er wrote:
             | But what about the phone number?
        
               | paulpauper wrote:
               | most twitter accounts do not have a phone attached to it.
               | you must be doing something to trip up the phone
               | verification thing
        
       ___________________________________________________________________
       (page generated 2022-03-09 23:01 UTC)