4 ms·
Nice publicity stunt but completely useless from an anonymity perspective. On their website, they mention the following: > Simply, your mobile device can't co
by Rjevski 8y ago
Nice publicity stunt but completely useless from an anonymity perspective.
On their website, they mention the following:
> Simply, your mobile device can't connect to the Internet, it can only communicate with a Tor Bridge within our closed network.
> Configure the Tor daemon on your device to use the bridge at 10.11.12.13:9000 and wait for the network to bootstrap.
This means they are hosting the Tor bridge themselves, but the device's traffic is still going through the carrier's network in plaintext (it's weakly encrypted over the radio link to the tower but unencrypted after that).
Technically the Tor daemon is still running on your device, but is forced to use their bridge with no other options. I'm not too familiar with Tor but surely this can't be good for security right? I can imagine an attacker on the other side of their bridge spinning up a fake Tor network pretending to be the real one (a "sybil attack" with tons of fake nodes).
Basically they're giving you the worst of both worlds. The inconvenience of using Tor with none of the security & anonymity benefits.
I am involved in the mobile industry and this kind of bullshit really makes me sad. They're eroding customer's trust not just in them but in the industry as a whole, making it more difficult for anyone that actually provides a good service.
- NickBusey 8y agoI'm pretty sure this random project isn't what is eroding trust but the fact that cell carriers seem to be completely unconcerned about all the spoofing going on these days. I get calls all the time "Why did you just call me" "I didn't" "I have a missed call from your number" "Ummm wasn't me."
- ryanlol 8y ago> the device's traffic is still going through the carrier's network in plaintext The only traffic moving on this network will be encrypted traffic from the tor daemon. >I'm not too familiar with Tor but surely this can't be good for security right? The whole point of Tor is that this is perfectly fine.
- aunty_helen 8y ago>This means they are hosting the Tor bridge themselves, but the device's traffic is still going through the carrier's network in plaintext The traffic is encrypted using the onion layering scheme on the device. The bridge node is the entry point for this traffic to the tor network. >an attacker on the other side of their bridge spinning up a fake Tor network The client creates the 'circuit', all the bridge node knows is who is connecting to it, it then unwraps its onion layer, finds an encrypted packet and a forwarding address and then sends it on.
- Confiks 8y agoThis must be one of the greatest examples of the Dunning-Kruger effect [1] in action that I've seen on HN in recent times. Pretty much everything in your analysis is misinformed, and you even explicitly mention in an aside that you are "not too familiar with Tor", but still state everything with an almost absolute certainty. You could have made the argument that allowing a single bridge makes it a bit easier to do traffic analysis attacks against users (instead of having to do DPI), but the ISP interception model is pretty much what Tor tries to protect you against, as long as that ISP isn't also (aided by) a global passive adversary. [1] https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
- Rjevski 8y ago> you are "not too familiar with Tor", but still state everything with an almost absolute certainty. When it comes to security I'd rather err on the safe side and call it insecure until proven otherwise. In any case, even if we assume the Tor part is secure, this is still unnecessary at best, since it requires you to run a local Tor daemon. You can run one on a normal SIM, and probably end up better off since you're not putting yourself on a hypothetical watch-list by purchasing such a product.
- saurik 8y agoI can run that on a normal SIM, but then I am not sure that all of the traffic from my phone is going through it at all times: the thing this SIM card does that is interesting is cause the phone to be unable to send any traffic off of the phone other than through Tor.