5 ms·
Tor has suffered a lot of bad PR, FUD, and failures lately. I'm beginning to lose faith in the network itself. I attempted to ask some of the developers if the
by deftnerd 10y ago
Tor has suffered a lot of bad PR, FUD, and failures lately. I'm beginning to lose faith in the network itself.
I attempted to ask some of the developers if there was, or any interest in, a Javascript version of Tor. My thought was that Electron apps or clearnet websites could use the javascript to load resources or data from onion addresses.
The push back I got from the concept made me feel sad. Some of the responses I got varied from "By only having one reference Tor, it keeps the whole network safe" to "Mixing clearnet with Onion access will make people unsafe."
Tor is doing a good job with the mission purpose of providing one software application that allows an individual to communicate with the world, even inside of a nation that practices extreme censorship.
But for the purposes of preventing the US, the largest and most prevalent state actor, from monitoring the entirety of the network? It seems to be failing.
For the purpose of hiding the source of an onion website, the jury is still out. It appears that the US government has enough of a view into the Tor network that they're able to often deanonymize the hosting location of the backend server.
They've been talking about refactoring the hidden service portion of the code for a long time now but I'm worried that all of the hits the project has taken lately will make that too little, too late.
- PeCaN 10y agoTo be honest, that's far from the worst feedback you could get to a “JavaScript version of Tor”.
- ken__m 10y agojesus was crucified because of attempt of tor on javascript
- frauch 10y agojesus was crucified because of attempt of tor on javascript
- mike_hearn 10y agoIf you're thinking about desktop apps, then one way to do it is simply ship a Java app that embeds WebKit (if you insist on using HTML even when a real widget toolkit is available). There is a Java Tor client available that can be embedded called Orchid, and then binding Orchid through to the Javascript world is not very difficult. It'd be a weird way to do things though. May as well just ship all needed data files and resources in the app itself. On the wider issue, I don't know if Tor is really doing such a great job of helping people in censoring states. Whenever I hear about Chinese people crossing the firewall it's always with VPNs and never Tor, which is thoroughly blocked for a long time now. One of the theories of Tor was that if there was lots of legitimate usage, it'd be harder to filter out Tor traffic ("anonymity loves company" they call it), but that goal was clearly better achieved using VPNs which impose minimal performance costs and has left Tor itself largely isolated. This sort of attack on the Tor network by large groups of malicious nodes is inevitable in a borderless community where there is no procedure for vetting or ID verifying new node operators. Tor assumes ideological loyalty from its node operators, that's a fundamental security assumption, but at the same time, a part of the Tor ideology is that there's no vetting procedure for nodes, nor are there any real rules for running them beyond a few trivial ones, and anyway without the former there's no way to enforce the latter. Tor is built on a giant contradiction, essentially. Of course that's not a problem unique to Tor. All communities that make majority trust assumptions without any way to control group membership have that problem. Bitcoin has suffered from this too, as has the British Labour party (which recently changed its rules to allow anyone to become a member by paying just £3, a move which immediately led to Corbyn and may yet lead to ~all existing MPs being fired and replaced by hard-left zealots).
- pdimitar 10y ago> This sort of attack on the Tor network by large groups of malicious nodes is inevitable in a borderless community where there is no procedure for vetting or ID verifying new node operators. Tor assumes ideological loyalty from its node operators, that's a fundamental security assumption, but at the same time, a part of the Tor ideology is that there's no vetting procedure for nodes, nor are there any real rules for running them beyond a few trivial ones, and anyway without the former there's no way to enforce the latter. Tor is built on a giant contradiction, essentially. Yep, exactly. How exactly do you build a strong anonymizing service all the while assuming benevolent nodes? Doesn't make any sense to me. Too much naivete in the programming profession, I feel. It makes for pretty hilarious fails periodically. EDIT: For the downvoters: I apologize if the language is too blunt. But those of us who aren't actively developing Tor have the benefit of being slightly more objective towards it -- that's how I feel. I might be harsh by expressing it, in which case I am sorry; I don't aim to be ungrateful, only skeptical of its current technical design philosophy.
- pdimitar 10y ago> They've been talking about refactoring the hidden service portion of the code for a long time now but I'm worried that all of the hits the project has taken lately will make that too little, too late. That's exactly what I am afraid of. I don't feel confident in their team and if they suddenly come up with a better security theme, from here on and I will simply suspect it'd be an attempt of the FBI to draw more Tor users into their honeypot servers. Simply put, I actually already lost trust in them.