3 ms·
In general, this isn't the best idea. If you force all your traffic through Tor you increase the chances that you're going to have an opsec fail. Loads of stuff
by irl_ 8y ago
In general, this isn't the best idea. If you force all your traffic through Tor you increase the chances that you're going to have an opsec fail. Loads of stuff talks to loads of other stuff in the background all the time. Checking your email or refreshing your social media feed or whatever.
When you use TAILS, only applications that are aware of Tor will be using Tor and other applications just go nowhere.
Tor Browser is a great example for explaining the separation between application layer and network layer anonymity. The tor client gives you network layer anonymity while Tor Browser gives you scrubbing of cookies and anti-fingerprinting. Using another browser, or other applications in general that do not try to provide application layer anonymity, with Tor wouldn't protect against all the application layer attacks and so you end up with less (or no) protection.
- DyslexicAtheist 8y agoI see where you're coming from but neither tor-browser, tails or a portal is going to protect users that don't rtfm. If you use the tor-browser you still want to avoid checking email or starting services over that same channel that will leak your identity. this are basic tor guidelines and the documentation even warns users of this. the typical users for a portal are people with prior training of opsec (yes you need to train opsec all the time because it's not just the tools but your whole workflow that's gonna trip you up) and a real use-case. I assume if you use this you won't make such rookie mistakes like having services running that will leak identity. It's perfect for journalists, activists or anyone else that already uses hardware based compartmentalization. This is an additional layer - not a silver bullet. I really assume a portal user already knows what things to isolate, which processes may run, what part of their work (during an operation) needs to be airgap'ed and hence shouldn't go through a portal ...
- DyslexicAtheist 8y agoPS: I'd trust hardware based compartmentalization like this any day over the QubesOS nonsense.
- Hello71 8y agoin fact the TransparentProxy documentation now has a large warning on the top saying not to: https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy https://trac.torproject.org/projects/tor/wiki/doc/Transparen...
- DyslexicAtheist 8y agoit says UNLESS YOU KNOW WHAT YOU ARE DOING! ¶ ... as an engineer I think I do know what I'm doing and would have thought most readers of this site are at least interested in peaking under the hood. Anyway this warning explicitly excludes those who do. but yes please don't use that without opsec training, because simply using some tool and assuming you're safe will sooner or later spoil your day.
- deleted 8y ago[deleted]