Tor’s shadowy reputation will only end if we all use it(engadget.com)
engadget.com
Tor’s shadowy reputation will only end if we all use it
https://www.engadget.com/tor-dark-web-privacy-secure-browser-anonymous-130048839.html
380 comments
I haven't used TOR recently but from my memory one of the biggest issues with is was speed. Yes you get anonymity but websites also load 2-3x slower because they have to go through all the nodes on the network. The people that care about privacy at the expense of speed already use TOR, and for everyone else it's going to be a very hard sell.
I can't decide if it would be easier to convince people of the benefit of extra steps/slow internet/privacy protections, or to reflexively engage their skepticism/critical thinking muscles upon hearing Save-The-Children-and-Stop-The-Terrorists rhetoric.
As it stands, it seems most people (of a certain race and class, anyway) feel more threatened by vague stories of child abductors in white vans at WalMart[1,2] or terrorists (c. 2000's generally) than being randomly victimized by our j̶u̶s̶t̶i̶c̶e̶ legal system.
Nothing to hide, nothing to fear, as they say. Abstract thought and generalization are hard, I guess.
[1] https://www.cnn.com/2019/12/04/tech/facebook-white-vans/inde...
[2] https://www.snopes.com/fact-check/white-van-facebook-hoax/
As it stands, it seems most people (of a certain race and class, anyway) feel more threatened by vague stories of child abductors in white vans at WalMart[1,2] or terrorists (c. 2000's generally) than being randomly victimized by our j̶u̶s̶t̶i̶c̶e̶ legal system.
Nothing to hide, nothing to fear, as they say. Abstract thought and generalization are hard, I guess.
[1] https://www.cnn.com/2019/12/04/tech/facebook-white-vans/inde...
[2] https://www.snopes.com/fact-check/white-van-facebook-hoax/
People who are generally ambivalent on TOR are the ones that we need to convert. I believe the message needs to be that anonymity is not only desirable but mandatory as well, especially because of the rise of platforms that literally track each and every possible metric about your daily life and habits. Besides, even if someone says that TOR is used for illegal purposes, we all need to remind them that legality is distinct from morality and is always defined by those currently in power.
As an exercise, I've been using Tor Browser as a daily driver on my personal laptop, and ended up with a 3-browsers approach:
* Firefox ESR -- For sites that are necessarily linked to my identity, such as HN and shopping. Sometimes this also gets sites that don't have to be linked to me, such as if I'm too lazy to copy&paste a link from HN into Tor Browser. (Keyboard switching/starting: Mod+F)
* Tor Browser -- Almost everything else. This is the bulk of my traffic, and innocuous, not "he just switched to Tor Browser, so must be doing something interesting". (Keyboard switching/starting: Mod+W)
* Chromium -- This is my total subjugation browser, used when more-private&secure options fail for something I really need/want to access. No ad blockers, but some awful DRM enabled. Current used only for one obnoxious video streaming service. I would like to get rid of this browser entirely. (Keyboard starting intentionally discouraging: Mod+P C H R O M Enter)
My vintage laptop can handle all 3 at once, just fine. Though I usually make them short-lived -- to reduce clutter, free compute resources, and clear trackers.
That's the personal laptop. My work laptops will partition browser use differently, such as for whatever the current Web development needs, and keeping all-day corporate SaaSes (e.g., GitLab, and mandated Web apps) open in one browser, while making another browser for short-lived public Web browsing sessions.
There's also a place for Tor Browser on the work laptop, for public browsing about topics that you don't want to hypothetically leak to competitors, but some companies will flip out if they detect Tor on the corporate network.
* Firefox ESR -- For sites that are necessarily linked to my identity, such as HN and shopping. Sometimes this also gets sites that don't have to be linked to me, such as if I'm too lazy to copy&paste a link from HN into Tor Browser. (Keyboard switching/starting: Mod+F)
* Tor Browser -- Almost everything else. This is the bulk of my traffic, and innocuous, not "he just switched to Tor Browser, so must be doing something interesting". (Keyboard switching/starting: Mod+W)
* Chromium -- This is my total subjugation browser, used when more-private&secure options fail for something I really need/want to access. No ad blockers, but some awful DRM enabled. Current used only for one obnoxious video streaming service. I would like to get rid of this browser entirely. (Keyboard starting intentionally discouraging: Mod+P C H R O M Enter)
My vintage laptop can handle all 3 at once, just fine. Though I usually make them short-lived -- to reduce clutter, free compute resources, and clear trackers.
That's the personal laptop. My work laptops will partition browser use differently, such as for whatever the current Web development needs, and keeping all-day corporate SaaSes (e.g., GitLab, and mandated Web apps) open in one browser, while making another browser for short-lived public Web browsing sessions.
There's also a place for Tor Browser on the work laptop, for public browsing about topics that you don't want to hypothetically leak to competitors, but some companies will flip out if they detect Tor on the corporate network.
If we all use it, it will slow to a crawl. Even more than now.
Nobody that’s not halfway suicidal is running exit nodes on their home machines (I won’t, I don’t want police knocking on my door).
And just for the onionspace… yeah I saw some bad stuff there. After what I saw I don’t think anonymity is a good idea. There is darkness inside people that lack of rules, lack of order, lack of accountability brings out.
Nobody that’s not halfway suicidal is running exit nodes on their home machines (I won’t, I don’t want police knocking on my door).
And just for the onionspace… yeah I saw some bad stuff there. After what I saw I don’t think anonymity is a good idea. There is darkness inside people that lack of rules, lack of order, lack of accountability brings out.
I think more people would become interested in Tor if they could see everything advertisers know about you.
I have yet to find something which lets you get a good peek at that data. Does anyone know of anything?
I have yet to find something which lets you get a good peek at that data. Does anyone know of anything?
I was pleasantly surprised to find Tor mode in Brave browser. I was looking for private browsing mode and it was right there. It was pretty darn fast and usable too. I honestly hope this feature and browser get more uptake
I wouldn't be surprised if the author, and a large segment of HNers agreeing with her, did a swift about-face when they realized that Tor also provides an end-run around the internet backbone black-holing of IPs that some Tier 1 ISPs did to KiwiFarms last year, during the height of the campaign to deplatform it. More people using Tor in general means more people having the means and know-how to evade censorship, and we can't have that, can we?
To be honest despite agreeing with many arguments around privacy, they're not quite compelling enough to convince me to adopt Tor's approach to it which in my mind is akin to hiding in a bin.
Sure, you're hidden, but you're also in with a lot of stuff you don't want to be in with and that can come with legal liabilities and ethical issues that I don't feel qualified to mitigate. And as other people have pointed out maybe the government or your least favourite company actually has a camera in the bin you chose to hide in.
Sure, you're hidden, but you're also in with a lot of stuff you don't want to be in with and that can come with legal liabilities and ethical issues that I don't feel qualified to mitigate. And as other people have pointed out maybe the government or your least favourite company actually has a camera in the bin you chose to hide in.
I run a service that scans and documents hidden services. I've actively contributed to the security of the Tor ecosystem by reporting vulnerabilities that would result in de-anonymization. I can say with pretty good authority that most hidden services are deserving of the 'shadowy' label. I agree that the only way to change this is to have other non-shadowy services and uses, but it's a hard sell.
How do you convince a company to intentionally stand up an onion site that provides any real value? You lose the ability to apply some defensive controls to thwart attack, you're associating your brand with something identified as 'shadowy', and most customers won't use Tor or even understand what an onion site is. If a company is unwilling to justify the effort or take the chance on standing up a hidden service, why would they be willing to take a similar risk of abuse by allowing traffic sourced from the Tor network?
How do you convince a company to intentionally stand up an onion site that provides any real value? You lose the ability to apply some defensive controls to thwart attack, you're associating your brand with something identified as 'shadowy', and most customers won't use Tor or even understand what an onion site is. If a company is unwilling to justify the effort or take the chance on standing up a hidden service, why would they be willing to take a similar risk of abuse by allowing traffic sourced from the Tor network?
Try visiting this from incognito and clearing cache/cookies: https://fingerprint.com. This can't be legal, right?
Does anybody use Tor for everything? I'd be interested in hearing their experience if so. There are sites that I have been unable to get working in tor, usually due to the browser. Some services actively block it. There's also a performance hit.
Also, while you should always assume your traffic is open to inspection/modification before it reaches its destination, this is more likely to happen with tor, not less likely. The Tor browser does help here, by not easily allowing obvious mistakes like using http.
Also, while you should always assume your traffic is open to inspection/modification before it reaches its destination, this is more likely to happen with tor, not less likely. The Tor browser does help here, by not easily allowing obvious mistakes like using http.
I use Tor occasionally to see what's going on in the flip side of the net and to contribute to routing, but honestly you aren't going to convince anyone who isn't ideologically inclined to support it. It doesn't help that Tor itself is full of scams and dark markets selling who knows what. It seems to have gotten better over the years, but normal people aren't going to put up with that. Nobody wants to see that stuff.
Are there any app that uses the Tor network and existing hidden protocols to provide anonymous chat?
This could be an alternative to some of the instant messaging systems that provide privacy but not anonymity.
I know that some chat messaging systems can use Tor as the transport, but they have problems of their own.
What I'm thinking about is something along the lines that each user app hosts a hidden service that receives messages through a standard HTTP API. Users need to hand their hidden service address to friends. The protocol itself already handles payload encryption and routing but messages could be further encrypted at the app level before being sent (using the other user's public key once an initial exchange has been done).
Granted, sending a message would require all parties to be online at the same time, but there could be a set of relay servers to hold messages until they get fetched.
I'm sure there are lots of hairy issues to take into account, but I would expect the existing protocol to mitigate some of these compared to a ground-up approach (like Session is doing). Tor is fairly mature and, despite all attacks on its infrastructure and protocol, it is still standing.
I'm also wondering if such a messaging system couldn't be useful for some IoT types of scenarios, as it would protect the location and communication of the source of the data, so the devices could not be easily physically found and hacked.
None of this would be useful for high-bandwidth real-time data, but you can get reasonable latencies and traffic sent this way.
Maybe it's all just a dumb idea...
This could be an alternative to some of the instant messaging systems that provide privacy but not anonymity.
I know that some chat messaging systems can use Tor as the transport, but they have problems of their own.
What I'm thinking about is something along the lines that each user app hosts a hidden service that receives messages through a standard HTTP API. Users need to hand their hidden service address to friends. The protocol itself already handles payload encryption and routing but messages could be further encrypted at the app level before being sent (using the other user's public key once an initial exchange has been done).
Granted, sending a message would require all parties to be online at the same time, but there could be a set of relay servers to hold messages until they get fetched.
I'm sure there are lots of hairy issues to take into account, but I would expect the existing protocol to mitigate some of these compared to a ground-up approach (like Session is doing). Tor is fairly mature and, despite all attacks on its infrastructure and protocol, it is still standing.
I'm also wondering if such a messaging system couldn't be useful for some IoT types of scenarios, as it would protect the location and communication of the source of the data, so the devices could not be easily physically found and hacked.
None of this would be useful for high-bandwidth real-time data, but you can get reasonable latencies and traffic sent this way.
Maybe it's all just a dumb idea...
With i2pd you can set up Web, IRC, Mail and NNTP proxies against retroBBS and chat with people at acceptable speeds. Also, to talk on actual daily lives beyond propaganada with Ukrainians and Russians.
Ironically, anonimity here stops terror and helps innocent people. Any terror.
Ironically, anonimity here stops terror and helps innocent people. Any terror.
I believe Tor is underrated in P2P systems. Many networks consider NAT traversal mostly (or partially) unsolved. Routing between nodes over Tor immediately solves your NAT traversal problems allowing any device to tunnel to any device (at the expense of latency).
[deleted]
Reaction: Sounds nice...but the author seems oblivious to the motivations and technical skill levels of >95% of web users. And to TOR's (in)ability to grow its infrastructure, to support anything resembling the traffic that would result from anything resembling a "we all use it" scenario.
I very rarely use Tor because using Tor without being an exit node just slows it down for everyone else using it and running an exit node means CSAM passing through your router sooner or later which I find unacceptable. Most of my privacy needs are met by a commercial VPN.
> the more people that use it, the more secure it gets, according to Patil. If only certain sensitive groups use it, it’ll be easier to deanonymize and ultimately track down identities.
Tor gained a lot of popularity after the Snowden revelations. We would need several Snowden-like leaks over the coming years to ramp Tor usage up substantially. And then there's no way of knowing how Tor would scale to support a new influx of users, year-on-year.
But I agree with Patil, the more people that use it, the better. If we could just shake the stigma that Tor = crimeware then that would be great.
Tor gained a lot of popularity after the Snowden revelations. We would need several Snowden-like leaks over the coming years to ramp Tor usage up substantially. And then there's no way of knowing how Tor would scale to support a new influx of users, year-on-year.
But I agree with Patil, the more people that use it, the better. If we could just shake the stigma that Tor = crimeware then that would be great.
Please don't. If now suddenly everyone would use TOR then we would get something a lot worse than Google's Web Environment Integrity, let me explain why. As someone being on the other side of things (running different services for years) thank god that all users are not using TOR.
99% of all attacks, spam, password brute forcing etc came from TOR on many services I worked on throughout the years. Eliminating that traffic or adding additional checks and hops for traffic from TOR solves a lot of issues for many services.
I recommend against using Tor, simply because of exit node hostility and targeted intrusions when you use Tor. Intel agencies also run the majority of relays last I heard of this subject. Perhaps if exit node operators were publicly listed and vetted humans and most relay's owners volunteered who they are and validate that with the project, I could trust it more.
IMHO, financial incentives for relay and exit operators is the best way to make sure more people without ulterior motives participate.
IMHO, financial incentives for relay and exit operators is the best way to make sure more people without ulterior motives participate.
Lets not forget personal services! You can setup sshd on a box behind NAT as a hidden service. It'll disconnect more than you like but screen or tmux can help with that.
Adoption is gonna be difficult. Many users don't care that much about privacy in general. So getting them to change their habits is a tall order. Furthermore, a lot of sites see TOR as suspicious and make the effort to block it/put them through captcha hell. I don't see a critical mass of users dropping convenience for the sake of something they don't really care about anytime soon.
I've tried tor a few times, but unless you enjoy solving captchas as a hobby it is only worth using when you actually need some anonymity.
By running a Tor node, one helps dissidents / spy assets in Russia get information / communicate with handlers in Ukraine, USA, etc. -- Which is the reason for Tor's existence in the first place. If one is into supporting that kind of thing of course, but defense of Ukraine seems pretty popular in the US
The internet has become progressively worse with the invention of smartphones and lowering the barrier of access for the common people, I would not like to see the same happen to Tor. If the long winded forum discussions and info sharing turns into Facebook tier posting I'll become depressed.
And we’ll only use it if it comes at nearly zero cost in performance and convenience. It’s as simple as that.
I was using tor the other day and my phone battery went below 10% triggering power saving mode. My fault, I should have had my phone charged before.
When the phone went into power saving mode, tor closed and lost my place. And since it doesn't keep local browsing history, I was back to square one.
When the phone went into power saving mode, tor closed and lost my place. And since it doesn't keep local browsing history, I was back to square one.
* If you’re concerned about the MAANGs of the world hoovering data for targeted adverts I think you’d get far more traction with aggressive privacy legislation and brutal oversight, or (and I recognize this is extreme) straight nationalization of some of their products with a mandate to operate them in the public interest like PBS or the Beeb
* If you’re concerned about an authoritarian state actor Tor was pwned years ago. TBH I think trying to win against ex. US TLAs in straight cryptography or protocol supremacy is kind of a fools errand (you’re ultimately going to get clobbered purely on the resource differential) and that the best bet is security through obscurity.
Just my 2c, maybe overly fatalistic so curious about counter views