[HN Gopher] What's next for Tor and privacy online?
       ___________________________________________________________________
        
       What's next for Tor and privacy online?
        
       Author : fsflover
       Score  : 149 points
       Date   : 2023-12-20 17:19 UTC (5 hours ago)
        
 (HTM) web link (blog.torproject.org)
 (TXT) w3m dump (blog.torproject.org)
        
       | SamuelAdams wrote:
       | Is Tor still considered secure? If a single entity controls
       | enough entry and exit nodes, I thought it was possible to
       | identify users?
       | 
       | Examples:
       | 
       | [1]: https://www.ibtimes.co.uk/fbi-crack-tor-
       | catch-1500-visitors-...
       | 
       | [2]: https://news.ycombinator.com/item?id=34412080
       | 
       | [3]: https://www.wired.com/2013/09/freedom-hosting-fbi/
        
         | pphysch wrote:
         | The Tor Project is primarily funded by the US State Department
         | and DARPA [1], so it is a forgivable error if someone mistook
         | TOR for FBI surveillance software.
         | 
         | [1] - https://www.torproject.org/about/reports/
        
           | nacs wrote:
           | Tor seem pretty open about where that money is coming from
           | and have DARPA and US goverment funds listed here with
           | explanations: https://www.torproject.org/about/sponsors/
           | 
           | "U.S. Department of State Bureau of Democracy, Human Rights,
           | and Labor The Bureau of Democracy, Human Rights and Labor
           | leads the U.S. efforts to promote democracy, protect human
           | rights and international religious freedom, and advance labor
           | rights globally."
           | 
           | "DARPA's Resilient Anonymous Communication for Everyone
           | (RACE) program researches technologies for a distributed
           | messaging system that can: a) exist completely within a given
           | network, b) provide confidentiality, integrity, and
           | availability of messaging"
           | 
           | Both of those seem to align with Tor's goals of privacy and
           | confidentiality.
        
             | pphysch wrote:
             | How does that square with the GP's linked articles that
             | allege the FBI "cracked" TOR on multiple occasions?
             | 
             | It strikes me as cognitive dissonance that someone would
             | simultaneously distrust the USG for obvious reasons (TFA is
             | about Snowden), yet also think they are a perfectly noble
             | arbiter of "secure communications", and look the other way
             | when copious evidence suggests that the USG has means to
             | compromise said "secure communications".
             | 
             | It's a very roundabout way of arguing "if you have nothing
             | to hide, you have nothing to fear". TOR is a fine product
             | _if_ you aren 't doing anything that the USG would
             | realistically prosecute you for.
        
               | kube-system wrote:
               | The USG is not a monolith and doesn't operate like one.
               | It is composed of many entirely different organizations
               | doing different things with different goals.
        
               | pphysch wrote:
               | If it were just one agency, sure, but we have evidence
               | that State, DARPA, and FBI all have their hands in the
               | TOR cookie jar. It would be naive to assume that CIA and
               | NSA aren't there too.
               | 
               | Occam's Razor says that TOR is primarily a tool of the
               | USG for enabling intelligence & influence operations,
               | particularly those involving low-level assets without
               | clearances (e.g. color revolutions), and the stuff about
               | "consumer privacy" is an unreliable side effect.
        
             | nerdbert wrote:
             | Even if they aren't spying on people's TOR traffic, it's
             | still useful for spies. The more people are using TOR, the
             | easier it is for them to hide their own traffic alongside
             | it.
        
         | jstanley wrote:
         | What are you going to do? Not use Tor? That's hardly better.
        
           | ravenstine wrote:
           | There are alternatives to Tor that have different anonymity
           | and routing protocols.
           | 
           | For example, take a look at I2P, which has been around almost
           | as long as Tor. It has a lot in common with Tor, but has some
           | key differences that may be appealing to some people. I2P
           | nodes are capable of implementing something like an exit node
           | (often called an "outproxy"), but there's no distinction
           | between peers in I2P that designates one as an exit node. The
           | project is more oriented towards hidden services,
           | implementing its internal network, than it is in anonymizing
           | connections to the clearweb. I think it's great that Tor
           | exists, but I wish more people would consider I2P or at least
           | simultaneously hosting their hidden services on both Tor and
           | I2P. And if you _really_ don 't like running a Java runtime,
           | Purple I2P exists and is written in C++.
           | 
           | There are also other networks like GNUnet, which slightly
           | predates Tor, which is mostly file-sharing oriented, but with
           | the goal of anonymity. It can do other things too but, from
           | what I can tell, the project never gained much favor
           | anywhere. Nevertheless, it still exists and is being worked
           | on.
           | 
           | And I can't forget Freenet, or what's not referred to as
           | "Hyphanet". I'll just call it Freenet for now because a lot
           | of people still remember it. Freenet's focus is not only on
           | anonymity but providing a distributed data store that is
           | censorship resistant. This at least in part solves the issue
           | of having to be online all the time in order to host a hidden
           | service. It's been a long time since I've used Freenet, but
           | supposedly the community is very good at discouraging crime
           | and other unsavory elements. I haven't used the new iteration
           | called Hyphanet.
           | 
           | All of these projects have significant differences from Tor,
           | and some of these differences are seen by some as fixing
           | significant flaws present in the Tor protocol that Tor can't
           | reconcile. I2P's design of having no peer distinctions, in my
           | opinion, is a vastly superior model for both security and
           | plausible deniability. Its routing protocol also makes DDoS
           | attacks a greater challenge. Having a primitive yet effective
           | implementation of human-readable hostnames is also nice.
           | 
           | All of these projects are available for people to use today.
           | 
           | Tor does have two upsides. The first is that it has a larger
           | community. The second is that it has the Tor Browser, which
           | I2P does not have an equivalent to, although the Tor Browser
           | can be adapted to use I2P.
        
         | mike_hock wrote:
         | Just because the FBI used shitty browser exploits that would
         | have easily been thwarted by sandboxing the browser properly,
         | doesn't mean that Tor is secure.
         | 
         | Running Tor nodes is pocket change for intelligence agencies,
         | and a major legal risk for volunteers. It's virtually
         | guaranteed that the US intelligence agencies own the majority
         | of the network between them. If they were in an arms race with
         | foreign intelligence agencies, the number of Tor nodes would be
         | exploding.
         | 
         | It's just that the NSA won't lend its shiniest toys to the FBI
         | just to bust some CP websites. The lives of children aren't
         | worth the risk of exposing and losing a zero-day exploit.
        
           | rockskon wrote:
           | Is it a major legal risk for volunteers? In most
           | jurisdictions I've only heard of awkward conversations with
           | police not familiar with what Tor is, but beyond that? Not
           | much outside of jurisdictions that already aren't friendly to
           | Tor.
        
         | Syonyk wrote:
         | > _Is Tor still considered secure?_
         | 
         | Define "secure." Secure from what attackers, in what threat
         | model, with what resources devoted to the attack, etc.
         | 
         | There are several categories of attack against Tor, and several
         | ways to mitigate them, depending on who you are and what you
         | use Tor for.
         | 
         | For a typical end user of Tor, the main one to worry about is
         | "browser beaconing" style attacks - where a compromised onion
         | website causes the browser to beacon out, on the clearnet, with
         | something that links the browser's request on the clearnet to
         | the browser's activity on the onion network. If you just use a
         | regular browser proxied to Tor, this is a rather high risk, as
         | browsers leak all sorts of things (I believe WebRTC was a
         | common way of doing it for a while). The solution here is
         | Whonix - a multi-VM setup in which your workstation (with a
         | stripped down browser) is _only_ connected to a Torification VM
         | that routes _all_ inbound traffic over Tor. So, if the browser
         | tries to beacon out, it doesn 't matter. Pop open a command
         | shell and use ping, it still goes out through Tor. Etc. I
         | consider this a reasonable way to use Tor, and any lesser
         | construct is probably a dumb idea unless you're using it for
         | things like sysadmin where beaconing out doesn't matter. Of
         | note, Qubes supports the Whonix configuration as a first party
         | sort of setup, and can route all your traffic through Tor,
         | should you care.
         | 
         | There's also the risk of traffic correlation for end users, but
         | I don't have a sense for the scale of this risk - I wouldn't
         | leave long running connections over Tor, but I don't know if it
         | matters for "casual use."
         | 
         | If you're hosting hidden services, the "guardian nodes" that
         | know your identity are a risk, and given how many nodes seem to
         | be run by three letter agencies, you'll want to deeply
         | understand Tor and how to protect your services if you're going
         | to host something - I believe you can limit guardian nodes to
         | those you trust (and run yourself, perhaps?), but that changes
         | some of the risk equations in ways I don't fully understand how
         | to reason about (not running hidden services that matter - my
         | blog has an .onion address, but it's literally just the same
         | content as the clearnet version).
         | 
         | And then, we get into the problem that "computers in general"
         | could be argued very convincingly to be "not in the slightest
         | bit secure against a high level adversary," which is another
         | can of worms...
        
         | michaelt wrote:
         | Tor is considered as good as anything.
         | 
         | After all, if you suspect the feds control a lot of tor nodes
         | you probably also suspect they've infiltrated or outright own
         | the major VPNs; that they've got special access to the major
         | cloud providers, and that they've got backdoors in things like
         | TPMs and remote management agents.
         | 
         | Of course Tor has its problems - exit nodes with trash IP
         | reputations, unreliable hidden services, evil exit nodes and
         | suchlike. So it's certainly not perfect.
        
           | wolverine876 wrote:
           | > Tor is considered as good as anything.
           | 
           | By who? It's an important question for someone taking this
           | advice.
           | 
           | One drawback of Tor is that it attracts attention to you.
        
           | 127361 wrote:
           | Team Cymru claim to be able to trace through VPNs using
           | widely collected flow records from Internet core routers.
           | ISPs sell these flow records to third parties.
           | 
           | So the whole fabric of the Internet itself is one giant spy
           | machine, in effect. That sounds like is like it's straight
           | out of dystopian fiction, but no, it's for real.
           | 
           | https://www.vice.com/en/article/jg84yy/data-brokers-
           | netflow-...
        
             | AlexandrB wrote:
             | I wonder if stuff like this can be thwarted by having a
             | constant flow of encrypted junk traffic between two parties
             | - only replacing the junk with real data (but not changing
             | the volume) when they're actively communicating.
             | 
             | Obviously, this doesn't scale for something like social
             | media. But metadata regarding one-on-one conversations
             | using something like Signal could be effectively obscured.
        
               | 127361 wrote:
               | Trouble is it's so difficult to know what your adversary
               | is doing, it's better to switch to a different medium
               | i.e. reduce dependence on the Internet (as I detailed in
               | another post).
               | 
               | The fundamental nature of the Internet itself permits
               | this behavior to go unchecked, there is no way for a user
               | to know what is happening behind the scenes with
               | certainty. We send out our private information (search
               | queries, etc.) into this giant black box we have no
               | control over. That's the crux of it.
               | 
               | That was not the case with radio or satellite TV, the
               | ability to determine what people were listening to or
               | watching on a mass scale was nearly impossible due to the
               | laws of physics. As the system was completely receive-
               | only.
        
       | throwoutway wrote:
       | Wasn't expecting to find something amazing from this blog post,
       | but this project looks amazing! and has a few big partners behind
       | it so I hope it does not vaporware https://onionshare.org/
        
         | beeburrt wrote:
         | Micah Lee also made Dangerzone [1] a tool to safely convert
         | untrusted pdf files to safe-to-open pdf files, wrote the book
         | Hacks, Leaks, and Revalations [2] and he made Tor-Browser-
         | Launcher [3] and he's a respected investigative journalist:
         | https://micahflee.com/
         | 
         | [1] https://dangerzone.rocks/
         | 
         | [2] https://hacksandleaks.com/
         | 
         | [3] https://github.com/torproject/torbrowser-launcher
        
         | brnt wrote:
         | I wish hosting a Tor website was as easy as Onionshare though.
         | Start an app, point it at a dir with a rendered static site,
         | and hand out the dot-onion to whomever you wish to show it.
         | 
         | I'm thinking: ephemeral websites like Opera Unite used to
         | provide, to e.g. share a photo album for as long as you're
         | online.
         | 
         | Edit: I should probably say I'm talking about the Android
         | version. Which would be so convenient for an appliancy web
         | server. The desktop version already do this.
        
       | joe_the_user wrote:
       | It seems like there are multiple reactions one can have to
       | Snowden type revelations:
       | 
       | 1) "I have nothing to hide" (which isn't quite as bad as it
       | sounds - "my security is being a nobody")
       | 
       | 2) "The government shouldn't be spying on people"
       | 
       | 3) "The government shouldn't be spying on people but of course
       | they are and you should expect that. Your online privacy is
       | essentially your jobs and you shouldn't use services and expect
       | them to protect your privacy"
       | 
       | 4) "Even if the state is always actually going to spy on people
       | in various fashions, we still don't want to accept and normalize
       | this. Forcing the state to 'parallel construction' is better than
       | letting the just publicly exhibit all its surveillance since
       | normalized surveillance has more of a chilling effect. Moreover,
       | institutions have a limited ability to keep their own secrets so
       | surveillance is itself going to periodically come into the open
       | and when it does, attacking it is useful, again, even if we know
       | it will always be an element of modern society".
       | 
       | 5) And you can go on and on... Should we allow enough explicit
       | machinery of surveillance to make the state not want to use
       | don't-ask-don't-tell third parties (no but..) and so-forth.
        
         | justsomehnguy wrote:
         | > which isn't quite as bad as it sounds
         | 
         |  _It is_ as bad as it sounds: not only the apologists of this
         | rhetoric believe in the false securities of it themselves, but
         | they aggressively try to persuade everyone what if you don 't
         | want to be a nobody or have anything what you don't want to
         | share with a complete strangers, including the government -
         | then you are _doing_ something illegal.
        
           | kube-system wrote:
           | It's not so much that digital security isn't important --
           | it's that if you are not a "nobody", and you have something
           | to hide, digital security is further down your list of your
           | worries.
           | 
           | I think too many people think about "digital security" in
           | isolation, without any human context or considerations of
           | threat profile. Digital security without holistic human
           | security is simply a math exercise.
        
           | rixthefox wrote:
           | As a addendum to this. I think many of the J6 crowd thought
           | the same thing when posts they made online were used in
           | evidence against them. You may have nothing to hide, but like
           | Snowden said: "Saying you have nothing to hide is like saying
           | you don't care about freedom of speech because you have
           | nothing to say"*
           | 
           | In both situations there is a loss of privacy and autonomy.
           | At some point people just shut down, for the same reasons
           | people behave differently when they know they are under
           | surveillance verses when they think they're not.
           | 
           | *paraphrasing
        
         | rockskon wrote:
         | With point #1.....
         | 
         | I've often been concerned that focuses on the most aberrant and
         | rule-breaking of people inevitably broadens the range of the
         | scope of behavior that gets targeted over time. When the most
         | severe of criminality is less prevalent and easier to detect
         | and stop, would law enforcement then not use their remaining
         | resources to go after pettier and pettier crimes? What makes
         | you think your present behavior will always keep you
         | "uninteresting"?
        
       | grammers wrote:
       | It's terrifying that basically nothing has changed since the
       | Snowden leaks. And most people simply don't care so governments
       | can keep scooping up our data, sifting through it for whatever
       | they may deem interesting.
        
         | SamuelAdams wrote:
         | The push for HTTPS everywhere came directly from the Snowden
         | revelations, and that is considered a good thing.
         | 
         | Now people are focused on encrypting metadata, so things like
         | DNSSEC took off.
         | 
         | There was a recent discussion about how state actors are using
         | push notifications to spy on users. Maybe that is the next area
         | of improvement.
         | 
         | https://news.ycombinator.com/item?id=38543155
        
           | ksjskskskkk wrote:
           | https everywhere is literally throwing the baby with the
           | bathwater. yeah we got a little better at hiding content,
           | still leaking ton of metadata, and still vulnerable to all
           | the root CAs in your browser... and lost cache and everything
           | else that http had.
        
             | gruez wrote:
             | >and still vulnerable to all the root CAs in your
             | browser...
             | 
             | certificate transparency makes this very risky to pull off,
             | making it all but useless unless you're trying to catch a
             | international terrorist or something.
        
               | ksjskskskkk wrote:
               | you forget systems have humans in them. most online
               | banking scams hijack bank domains and use CAs for that
               | country gov, which usually have keys leaked or sold on
               | the right (wrong?) places. just look at india or brazil
               | list of small govt CA revocations. those are usually CAs
               | signed by the CAs in your browser.
               | 
               | so, yeah, a gov abusing this is very bad and visible.
               | scammers profiting from the complexity and humans in the
               | machine, is very common.
        
               | gruez wrote:
               | >most online banking scams hijack bank domains and use
               | CAs for that country gov, which usually have keys leaked
               | or sold on the right (wrong?) places. just look at india
               | or brazil list of small govt CA revocations
               | 
               | Source? If true they're grounds for ejection from root
               | certificate programs of various OS/browsers.
        
             | jbotz wrote:
             | > https every[where] is literally[1] throwing [out] the
             | baby with the bathwater[2].
             | 
             | 1) That would be figuratively, not literally, as there's no
             | literal baby in HTTPS-everywhere that I know of.
             | 
             | 2) What is HTTPS-everywhere throwing out? Which part is the
             | baby and which is the bathwater? I don't think this is the
             | right expresion to use here, not even figuratively.
        
               | ksjskskskkk wrote:
               | on 2: caches for one
        
               | dllthomas wrote:
               | > no literal baby in HTTPS-everywhere that I know of
               | 
               | Well not anymore. We threw it out.
        
               | jkubicek wrote:
               | literally
        
             | verisimi wrote:
             | > and lost cache and everything else that http had.
             | 
             | A genuine loss, and also the ability to zip imagery.
        
               | Avamander wrote:
               | Was it a loss? I don't think so. It was either
               | ineffective, stale or a massive privacy issue. We're
               | better off with local caches.
        
               | wizzwizz4 wrote:
               | > _It was either ineffective, stale_
               | 
               | Because people misconfigured their caching headers,
               | didn't use ETags, and wrote buggy caching servers. HTTP's
               | actually got quite good support for proxies and caching
               | servers, all things considered.
               | https://developer.mozilla.org/en-
               | US/docs/Web/HTTP/Headers/Ca...
               | 
               | > _or a massive privacy issue_
               | 
               | Again, people misconfiguring their caching headers, and
               | buggy caching servers caching things that should not be
               | cached. (Though yes, plaintext TCP connections are
               | inherently a massive privacy issue.)
               | 
               | > _We 're better off with local caches._
               | 
               | My main web connection used to sit behind a local caching
               | proxy, shared with a few thousand other users. It worked
               | very well: I never saw anyone else's confidential
               | information, I _assume_ they never saw mine, and HTTPS
               | was in play. So yeah, HTTP hasn 't robbed us of
               | functional caching: it's just opt-in now.
        
           | Syonyk wrote:
           | > _so things like DNSSEC took off._
           | 
           | DNSSEC doesn't encrypt anything - it's all plaintext on the
           | wire. There are some DNS extensions that encrypt the
           | query/response (DNS over HTTPS does this), but DNSSEC is not
           | that.
           | 
           | DNSSEC is simply a way to verify that the response you get
           | has not been meddled with in transit - it's the domain owner
           | signing the DNS records so that you can verify that your DNS
           | responses aren't being modified by a malicious entity (that
           | may very well be your ISP).
        
             | tptacek wrote:
             | Yes, they're probably thinking of DoH, which is much, much
             | more widely deployed than DNSSEC.
        
               | belorn wrote:
               | How are you calculating that?
               | 
               | The number of users of recursive resolvers that support
               | DNSSEC vs users of browsers that use DoH? Number of
               | companies that has infrastructure that supporting DoH
               | compared to number of companies that has infrastructure
               | that supporting DNSSEC? Daily users?
        
               | tptacek wrote:
               | The right figure of merit should be "lookups protected by
               | DoH/DNSSEC" (stipulating that DoH and DNSSEC have
               | different definitions of "protected" and just assuming
               | arguendo they're the same). I don't think it'd even be
               | close; I would assume DoH exceeds DNSSEC by several
               | orders of magnitude.
               | 
               | Note that this isn't lookups that _happen to run through
               | a resolver with DNSSEC enabled_ ; to count, you'd be
               | talking about such a lookup _to a zone that had DNSSEC
               | signatures_. You can see the advantage DoH has here,
               | since it works with all zones.
        
           | begueradj wrote:
           | How Some Governments Eliminate HTTPS/TLS Encryption [1]
           | 
           | [1]: https://www.youtube.com/watch?v=37irG5pKur8
        
           | 127361 wrote:
           | However so many sites are using CloudFlare and other DDoS
           | prevention and CDN services. I'm sure the NSA has fiber taps
           | (beam splitters) at the point where the data travels
           | unencrypted on the internal datacenter network.
           | 
           | CloudFlare itself might not even be aware of the taps. Or
           | maybe only a few select employees know about it.
           | 
           | I think the solution to these problems is to reduce
           | dependence on the Internet. It's now possible to torrent an
           | entire library worth of books and have it all on your
           | personal computer at home. 20TB HDDs are readily available,
           | and constantly getting cheaper. Also check out
           | https://reddit.com/r/DataHoarder. And we have local AI
           | models, again these do not need the Internet to function.
        
         | apapapa wrote:
         | Nothing has changed because we didn't get another leak ... Its
         | likely much worst.
        
         | creer wrote:
         | Something changed: government agencies are now clear that they
         | can carry on, build more of it, and get away with it. Even try
         | and build more of it into law (see EU). It was an expensive
         | test but successful.
        
         | mistrial9 wrote:
         | > And most people simply don't care
         | 
         | this is not true and insulting at the same time. Individual
         | people are powerless against organized commercial activity,
         | and, more than one million people in the USA are on payroll
         | with uniform services, so they cannot object.
         | 
         | in addition, the throw-away word "terrifying" is also useless
         | and annoying.. really
        
         | matheusmoreira wrote:
         | Plenty has changed. In general the technology industry cares a
         | lot more about security these days. Things have gotten better
         | and many services became much more secure by default. WhatsApp
         | is the most widely used messaging platform in the world and it
         | has end-to-end encryption. It's not ideal but the fact is never
         | before have so many people used something this secure. It's
         | foiled my country's courts more than once.
         | 
         | What we need now is to get these governments to accept defeat
         | and stop trying to undermine our security with constant
         | legislative assaults. The fact they keep trying is evidence
         | that it's working.
        
       | aborsy wrote:
       | It seems that there are at most 10000 Tor nodes.
       | 
       | Are the identity of the node operators known? Do known trusted
       | organizations and individuals own the majority of these nodes?
       | 
       | It's indeed expensive and risky for individuals to run Tor notes.
        
         | sdsd wrote:
         | I know that Chaos Computer Club used to run a bunch of them.
         | And Noisebridge did for a while, but I think they stopped. A
         | few universities, too.
         | 
         | I haven't been very active in the space for about a decade, I'd
         | also love a more knowledgeable answer
        
         | dpifke wrote:
         | See https://nusenu.github.io/OrNetStats/
         | 
         | It's up to individual relay operators whether or not to publish
         | contact information. For an example, see one of my relays here:
         | https://nusenu.github.io/OrNetStats/w/relay/375DCBB2DBD94E52...
         | 
         | (If you're not an exit relay, it's neither risky nor
         | expensive.)
        
         | 127361 wrote:
         | Try the I2P anonymous network where by default every user is
         | also a router. You can chain the two together, set I2P to use
         | an outproxy and set the Tor browser to connect through I2P.
         | 
         | I have no clue as to what security this provides nowadays. I
         | predict the NSA or FBI have large scale packet timing
         | correlation in operation now. Or the random number generator
         | has been compromised, or there are a series of bugs in the Tor
         | or I2P implementation itself? I also think there was a human
         | compromise of the Tor Project itself 8-9 years ago as well, it
         | has been significantly weakened.
         | 
         | Personally I tend to like one-way data broadcasting systems,
         | that way the receivers cannot be traced if they are air-gapped,
         | e.g. satellite or radio data broadcasting. However nobody
         | operates any useful service nowadays. Twenty years ago you
         | could receive the whole worldwide Usenet feed with a DVB-S PCI
         | card, unencrypted in the clear from a service called Cidera[1].
         | It was just UDP multicast packets containing Usenet messages,
         | split into fragments with sequence numbers, trivial to reverse
         | engineer.
         | 
         | I had this at service home, we had dial-up and with a 55cm
         | satellite dish in my bedroom window, I had a 45Mb/s data feed.
         | I wrote my own software including a device driver for the DVB-S
         | card running under FreeBSD (4.2-RELEASE I believe). Nearly
         | 1000x faster than dial up, which was mind-blowing back then.
         | 
         | Also archiving Nostr text messages is interesting, you can get
         | the entire worldwide feed of messages from the relays, and then
         | search for whatever topic of interest you want in the messages.
         | Nobody can tell what you are searching for, unless your
         | computer is compromised. I'm thinking about broadcasting these
         | by satellite somehow, but satellite bandwidth is very
         | expensive. It's just a matter of getting the funds for it.
         | 
         | Reception should be possible using a RTL-SDR or AD9364+USB3.0
         | microcontroller[2], and a satellite TV dish. The AD9364 chip
         | can be had from AliExpress[3] for $6 now.
         | 
         | 1.
         | https://web.archive.org/web/20020806064624/http://www.cidera...
         | 
         | 2. https://www.crowdsupply.com/amungo-navigation/stixrf
         | 
         | 3. https://www.aliexpress.com/i/33017832196.html
        
         | rendx wrote:
         | The goal is to _not_ have to trust the node operators, but to
         | have as much diversity as possible. They can only deanonymize
         | you if all three nodes in one cascade collude.
         | 
         | Running a non-exit node carries very little to no risk.
        
           | throwaway89201 wrote:
           | No, you only need to compromise the first node - named the
           | entry guard for that reason [1] - and either the exit node or
           | ideally the endpoint (hidden) service. Deanonymization is
           | then possible by correlating the timing of traffic between
           | those two points, as Tor wants to be low-latency, without
           | randomly delaying traffic.
           | 
           | For this reason not all nodes may be guard nodes, as decided
           | by the directory authorities, and guard nodes are maintained
           | for a longer time by the client to reduce the chance that you
           | pick a compromised guard node because you switch often. This
           | is balanced against the risk that you are unlucky and pick a
           | compromised guard at first (which you then maintain for a
           | longer time).
           | 
           | The exit node is pretty much assumed to be compromised, as
           | it's a role not available to many entities - it requires high
           | bandwidth and much teeth-gritting - and the public internet
           | is intercepted at large anyway.
           | 
           | [1] https://support.torproject.org/about/entry-guards/
        
         | joe_the_user wrote:
         | The reason Tor exists is because of intelligence agencies -
         | they literally created it[1]. It makes perfect sense. Agencies
         | certainly want to be able to surveil the population at large
         | but they want to be able to act anonymously themselves. I mean,
         | any fixed entry-point an agency chooses to the Internet is
         | going to get a lot of attention. Agencies could mix it up in
         | various ways - change entry points, mix their traffic, etc ...
         | and the final result looks a lot like Tor. And so yeah, I'm
         | sure you have idealistic operators who take heat for running
         | nodes but I'd expect the agencies put some resources into
         | making sure one way or another that the exit nodes exist.
         | 
         | [1] https://en.wikipedia.org/wiki/Tor_(network)#History
        
       | badrabbit wrote:
       | Make it a tun interface instead of a socks proxy.
       | 
       | LD_PRELOAD/proxychains for stuff isn't nice or leak proof.
       | 
       | They should also partner with vpn providers so vpn tunnels
       | terminate in Tor and exit from it and Tor exits get hosted more
       | and more by vpn providers (bit harder to block/classify as a tor
       | exit).
       | 
       | Also, a new class of exits that support traffic only to specific
       | subnets for sites that are "good" (low abuse potential like bbc,
       | wikipedia,news sites,archive sites), these exits can be run out
       | of people's residential IPs and phones
        
       | nufonewhodis wrote:
       | Hi,
       | 
       | is it possible to mark the packages that leave your house and
       | flow into the street using your router or some small device in
       | the box that connects the cables from outside going into your
       | house?
       | 
       | And could these boxes on the street do a job like that?
       | 
       | I mean, even if I have a DIY network, hard- and software, at
       | home, wouldn't it be futile because my encrypted packages, while
       | not easily opened, could still be "marked" at any point outside
       | my house?! With a prefix or in between the packets? That's what
       | someone on the internet means, when they say, the more of us use
       | Tor, the better protected the few are and the fewer users surf
       | via tor, the less protected whistleblowers and journalists are.
       | 
       | Also: when our packages are encrypted, wouldn't it be possible
       | for specific software, say, MS Windows, to pack huge amounts of
       | very specific data into some of these packages, that would get
       | encrypted in "reengineerable" ways, that are easier to break?
       | 
       | I have a surface-level understanding of the basics of these
       | things. Forgive me for not reading up on that stuff, first.
       | 
       | Edit 2: could similar things be done via CPU? I always wondered
       | what the disadvantages of Apples way of keeping stuff in RAM
       | were. Can the CPU send or safe data about what's in RAM in ways
       | that can't be easily tracked via the OS?
        
       | Unfrozen0688 wrote:
       | Is the https://snowflake.torproject.org/ still good. I run the
       | extension on everything. My country basically does not block
       | anything.
        
       | aborsy wrote:
       | Two questions on Tor.
       | 
       | 1. Browsers have become complex, and the users' machines could be
       | conceivably compromised through zero days in the browser. How
       | does the security of the Tor browser, Chrome, Firefox, Safari and
       | Brave compare with one another (in terms of chances of zero
       | days)?
       | 
       | 2. Do people here use Tor for everyday use (accessing the
       | clearnet, not onion links)?
        
         | Eisenstein wrote:
         | 1. If one turns the knob to 'safest' then it will exclude all
         | scripting, which leaves few outlets for exploits.
         | 
         | 2. Yes. Everyone should for some portion of their browsing
         | time, if only for the reason that when you do need to use it,
         | your traffic won't look unusual.
         | 
         | Note that you can think 'paranoid' or 'up to no good' all you
         | like, but no one knows the future, and the difference between
         | 'paranoia' and 'being prepared' is 'does it affect you or
         | others around you in a negative or unhealthy way'.
        
         | belorn wrote:
         | > 2. Do people here use Tor for everyday use (accessing the
         | clearnet, not onion links)?
         | 
         | I use it almost daily. It is a great tool for sysadmin work,
         | and a must for a lot of websites with less-than-honorable
         | tracking policy.
        
       ___________________________________________________________________
       (page generated 2023-12-20 23:01 UTC)