4 ms·
Guys, I have a question. If it's this simple to put a server into the onion, why are people not doing this with torrent trackers? I'm thinking specifically abou
by oneloop 10y ago
Guys, I have a question. If it's this simple to put a server into the onion, why are people not doing this with torrent trackers? I'm thinking specifically about thepiratebay.org which is still banned in the UK (at the ISP level, I believe). Then mirrors appear and then the mirrors get banned?
Why not just put it into the onion? Put it there once, problem solved.
- chejazi 10y agoPerhaps the primary reason is accessibility. Onion addresses are not easily memorized. See https://en.wikipedia.org/wiki/Zooko%27s_triangle https://en.wikipedia.org/wiki/Zooko%27s_triangle I believe this inconvenience is minor, however.
- oneloop 10y agoIncidentally, is there any fundamental reason why onion addresses are always so cryptic?
- bradyd 10y agoThey are a hash generated from the service's public key.
- mirimir 10y agoNo, from its private key! The same key that's used to sign outgoing content, authenticating to the Tor network. Edit: I'm wrong. It's based on the hash of the public key.
- ikeboy 10y agoHow can anyone verify a hash of the private key without having it? Anyway, see https://trac.torproject.org/projects/tor/wiki/doc/HiddenServiceNames https://trac.torproject.org/projects/tor/wiki/doc/HiddenServ...
- mirimir 10y agoI don't know the details. But basically, a Tor relay provides some token to the onion server. The onion server signs that token with its private key, and returns the output to the Tor relay. Then the Tor relay verifies that the token was signed by the private key corresponding to the onion hostname.
- chadzawistowski 10y agoThey don't have to be cryptic, but it takes a lot of brute-forcing to get a memorable one. Facebook managed to get https://facebookcorewwwi.onion/ https://facebookcorewwwi.onion/
- oneloop 10y agoI get that, my point is why do they have to be brute forced? Why can't you just pick one?
- DarkLinkXXXX 10y agoThey are cryptographically generated.
- chadzawistowski 10y agoHashes are easy to run forwards and hard to run backwards.
- curiousgal 10y agoCrypto noob here. Why is that? are the hashes generated from an input randomly?
- rzzzt 10y agohttps://en.wikipedia.org/wiki/Cryptographic_hash_function https://en.wikipedia.org/wiki/Cryptographic_hash_function TLDR: they are designed to behave that way. Their alternative name is "one-way hash function".
- falcolas 10y agoA hash verifies an input, but you can not reproduce the input from a hash. A simplified version: X % 2 = H If I give you the formula, and a H of 1, can you, with certainty, tell me that my input was 1029? Cryptographic hashes have a similar property, just with a very large collision space - for Tor only 1 in 36^16 inputs will produce a given hash; yet you still can't guarantee that an input that produces that hash is the original input (and just guessing the possible inputs will take you a very long time). The downside of our hash above is that it gives you a pretty good clue of what the original input was: if you get an H of 1029 from the forumla X % 10000000 = H, you'll have a pretty good idea of what the X was. Cryptographic hashes do not share this weakness - they will stretch the input, and ensure that there are no clues left as to what the original input was.
- devishard 10y agoThe answers are correct, but a less cryptographically-related answer: When you go to a website on the regular internet, the name you type into your URL bar doesn't contain any location information. Instead, you go to a Dynamic Name Server (DNS) server (often run by your ISP) and and get the IP address, which tells your browser where to go. With Tor, the hashes you see are analogous to the IP in regular internet: they tell your browser where to go. But there's no DNS for Tor, so you can't hide address behind a name. Incidentally, this story is about SciHub being blocked at the DNS level, meaning that the domain https://sci-hub.io/ https://sci-hub.io/ was removed from the DNS servers. But it's still available at the IP level at https://31.184.194.81/ https://31.184.194.81/ This story demonstrates the need for DNS to be decentralized. ICANN has far too much control and is now using it for censorship that holds back the progress of all of humanity.
- oneloop 10y agoSo would a sort of decentralized DNS be possible?
- Uw7yTcf36gTc 10y agocheck out namecoin. they are attempting that, afaik.
- collinmanderson 10y agoThough even if we decentralize DNS, ICANN controls all of the underlying IP addresses.
- mariuolo 10y ago> Though even if we decentralize DNS, ICANN controls all of the underlying IP addresses. IANA would have to un-delegate a whole range from RIPE. I don't see that happening unless they want to fracture the network. Perhaps Elsevier will be able to force ISPs to blacklist that particular IP, but nothing more. I also suspect they will move the domain under a ccTLD, not subject to the whims of ICANN.
- 10y ago
- wiml 10y agoThe answer to that is in the Zooko's Triangle link, give it a read. But, in short: for a name to be useful in a global context, it has to be unambiguous or unique. If there isn't a centralized naming authority / registry, then that means that you can't be able to pick an arbitrary name. (If you could, you could just decide to use the same name as someone else, and now there's no way to figure out which one of you the name indicates.)
- deleted 10y ago[deleted]
- gruez 10y agoWhat about blockchain based DNS solutions like namecoin?
- Tiksi 10y agoThey do: http://uj3wazyk5u4hnvtk.onion/ http://uj3wazyk5u4hnvtk.onion/ But most people don't run tor often or at all.
- ultramancool 10y agoIf you're lazy and aren't looking for any strong degree of privacy for this kind of thing, you can run an onion transparent proxy on your router fairly easily, so then you can just navigate to .onion domains in any browser and browse away. Of course, the privacy implications of this are pretty bad if you're just going to load most websites via direct connection. A simple image embed can deanonymize you. But it's probably good enough if you're just going to browse TPB or similar sites and are mostly just looking for a bypass without the privacy concern. https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy https://trac.torproject.org/projects/tor/wiki/doc/Transparen...