3 ms·
What about VPN -> Tor -> VPN?
by drewbug 10y ago
What about VPN -> Tor -> VPN?
- prdonahue 10y agoYeah, because 5,000ms latency is fun.
- shivsta 10y agoTor is already slow - people use it because they want security. The addition of another VPN increases security greatly and only adds a minimal amount of more latency.
- lucb1e 10y ago> Tor is already slow Relatively, sure. But I've found it very usable in recent times actually. Used it almost full-time (besides a normal Firefox instance for the company's intranet) to get around some silly firewall that wouldn't let me download "hack tools" (I was an intern in the cyber security department, security tools were part of my job). There were times where I didn't notice at all that I was using Tor, and most of the time it was comparable to mediocre wifi.
- rycfan 10y agoYou probably should have spent some time fixing that hole in the firewall that let you bypass your company's download restrictions. ;-)
- lucb1e 10y agoTor can and should circumvent any firewall using obfuscation proxies that use AWS, GCS, Azure, etc. You'd need to block most of the internet to kill Tor. And as for monitoring, I guess it might be possible, but if someone thinks to use bridge nodes that's also defeated.
- halfcat 10y agoYou would usually not try to block Tor at the network level. You would lock down your computers so employees can't make changes, and only allow them to run executables from locations which they have no write access to.
- lucb1e 10y agoFor a bomb threat? Or more benignly, uploading a few documents to a whiteblowers platform (some news organizations have one)? No problem I'd say.
- jsmthrowaway 10y agoHave you tried TCP with 5sec latency? It can barely window. Shit, dialup was better, and that would still cost you half a second or so for a full-MTU packet. I see your point, don't worry, it would just be a lot more rough than you're implying, particularly to upload many heavy PDFs. (I kind of want to lab it now that we've discussed it.)
- lucb1e 10y agoI meant a delay of a few seconds, not strictly >=5s, but still I wanted to prove you wrong even about 5 seconds. Turns out Cloudflare deems 5 seconds latency too much. I thought most default timeouts were something like 30 seconds, and when writing applications myself I usually limit them to 8 or 10 seconds (to be able to get back to the user quick enough with an "unable to connect" error, but to also give it a moment). I expected that 5 seconds latency would be slow, but not unbearable. Instead it breaks stuff completely. From my testing, 3.5 seconds latency works fine. Slow, but it consistently works. Adding 5 seconds latency just breaks TLS connections to Cloudflare, though DNS, TCP and HTTP work. I was able to retrieve a webpage (via netcat) from my site, the redirect to HTTPS from http://news.ycombinator.com http://news.ycombinator.com worked, and pinging showed a consistent 5030ms +/- 10ms latency. Adding 3.5 to 5 seconds latency (random variance) makes, as expected, some connections fail. On my second try, I was able to load the Hacker News homepage, consisting of: 1) the homepage; 2) robots.txt (wget retrieves this); 3) css file; 4) javascript file; 5) favicon; 6-10) 4 images. In total 10 resources, taking a minute and 20 seconds. After establishing a TLS connection, it could reuse that connection for multiple requests. I think this is equivalent to hitting reload a few times in a browser. So VPN-TOR-VPN might work still, though it is indeed more on the edge than I expected. Thanks for making me venture here, I learned something!