5 ms·
I use Tor Browser for most of my day to day browsing to foil all the non-governmental corporate botnet spying. Of course I’m under no illusions that it secures
by MintelIE 6y ago
I use Tor Browser for most of my day to day browsing to foil all the non-governmental corporate botnet spying. Of course I’m under no illusions that it secures you against the government. But I don’t do anything naughty so I’m not worried.
- shadowprofile77 6y agoWhy do you think it fails as basic security against the government? Honestly curious. And what would you suggest instead. To my knowledge many dissidents and activists around the world are specifically using TOR because it supposedly does indeed provide protection against government tracking.
- MintelIE 6y agoIt’s literally funded and made by the NSA. Dissidents and activists have been busted using Tor and there’s always a friendly government damage control agent ready to pop up (any forum, any time of day) to remind people that Tor couldn’t possibly be backdoored or owned, it was always some other type of thing they used in parallel construction. Over-shilling is what clued next in. You don’t get this kind of response without a massive panopticon dispatching reputation managers. Why the heck would the NSA write NSA proof software? LOL. EDIT: this is in reply to mapgrep and his crew: Did I say I won't use Tor Browser? Is it really necessary to put words into my mouth to make your point? I've noticed this a lot with people who are very very lightning fast, almost unbelievably fast, to defend Tor on any forum or platform on the Internet. The speed at which it occurs, and the typical over-the-top, rude, and unnecessary attempts to make people seem to say things they 100% have not. You should apologize. Obviously the NSA has broken Tor, they made it. Forget about current funding, where'd it originate? And why does the Tor Project publish a list of exit nodes?
- NikolaeVarius 6y agoWhy do you trust literally any secure comms code?
- MintelIE 6y agoDid you stop beating your girlfriend yet? Same question, different pose.
- mapgrep 6y agoThe fact that the US government, largely through Open Technology Fund, originally an arm off the State Department (via Radio Free Asia!), has arguably done more to fund core internet privacy technologies than the private sector is an indictment of the private sector, not of the U.S. government. We should absolutely be aware of funding sources, skeptical of code written by other people, etc, but if you were to actually enforce in your life a position that you won’t use any security or privacy technology with funding ties to the USG you will quickly find yourself in quite an untenable position.
- pfundstein 6y agoAES which is the encryption standard for asymmetric crypto and used everywhere (including by the gubment) was designed by the NSA. So what's your point?
- dependenttypes 6y ago> is the encryption standard Some others (such as chacha20) are pretty popular too. This is the only cipher used by wireguard and one of the ciphers used by ssh and tls. > was designed by the NSA No it was not. It was designed by two Belgian cryptographers (the same ones that did SHA3). > for asymmetric crypto Symmetric No offence but you seem quite clueless.
- pfundstein 6y agoFair enough, but my point against the tinfoil hattery still stands; Just because the gubment was involved with it's inception doesn't mean it has backdoors.
- komali2 6y agoRumors abound that the NSA runs a bunch of Tor exit nodes
- insertnickname 6y agoIt would be unreasonable to assume that they aren't. It's a cheap, easy, and low-risk way to soak up lots of interesting traffic.
- teddyh 6y agoEven if this was true, it should not change anyone’s behavior; a malicious exit node should be assumed when using Tor. I.e. either always use HTTPS sites, or .onion sites. No HTTP unencrypted sites.
- deleted 6y ago[deleted]
- dependenttypes 6y ago> Why do you think it fails as basic security against the government? Tor connections against normal sites use 3 hops while they use 6 hops against onion sites. Controlling or potentially even analysing the traffic from 2 of the hops is enough to know where the user connects to (it might be 4 hops for the onion case but I am not sure). I am pretty sure that NSA has enough resources for their own nodes. I2P has a better architecture in general but it still does not solve the issue. I am looking into evaluating lokinet at the moment. In general tor does not have a great track record. For example they took ages to upgrade from an 80-bit sha-1 truncated address scheme with dh1024 and aes128 into something more modern.
- pfundstein 6y agoYou could've just said that you have a hunch.
- dependenttypes 6y agoAre you kidding? What part of "Tor connections against normal sites use 3 hops while they use 6 hops against onion sites. Controlling or potentially even analysing the traffic from 2 of the hops is enough to know where the user connects to (it might be 4 hops for the onion case but I am not sure). I am pretty sure that NSA has enough resources for their own nodes" seems like a hunch? Do you have something that you disagree with? If so just say it.
- shadowprofile77 6y agoOkay, definitely a bit less practical, but what about using TOR with TAILS on a laptop that's dedicated to nothing else (laptops for TAILS use generally shouldn't run over top of a Windows or regular OS installation). Furthermore, using said machines or TOR alone from an IP address that isn't one's own identifiable address. That aside, what do you concretely propose as alternatives to TOR for the seriously privacy-conscious (and those, such as activists and dissidents, who need anonymity in a life-or-death way.
- dependenttypes 6y ago
- taftster 6y agoRight, this is important to understand. The use of Tor isn't just about subverting government information gathering. But it's just as important in the fight against corporate collection, maybe even more so. I'm (personally) less concerned about government spying on me than I am about corporations. That's not to justify government overreach, but I don't like the prospects of corporations like google, facebook, twitter holding as much (or more) of my information as the government does.
- kanox 6y agoThis seems very risky. * Exit nodes might be run by malicious actors and unless you enforce always https they might snoop credentials. * If you login to platforms like google/facebook/twitter/stock overflow it might still be possible to track you. If you're worried that your employer is spying on you then tor can't help because they already have administrative access on your computer. I personally have a rule to never log into personal accounts from corporate devices.
- MintelIE 6y agoListen I'm not some Antifa here bombing the hell out of the next city over. I'm merely avoiding the botnet. How is it risky? What's the worst that could happen, I get tracked by the same people who would 100% track me without Tor Browser?
- black_puppydog 6y agowell, if you open non-HTTPS links you're trusting the exit node operator not not fuck with your data and to not snoop on it. So... don't do anything important without HTTPS. Same as always. As for the corporate spying... totally agree, worst case you didn't gain nor lose
- staycoolboy 6y agoSometimes I can't log into HN with Tor. Do you have that problem?
- youwouldntcar 6y agoYes, I do, and they also shadowban Tor accounts here, which is depressing.
- staycoolboy 6y agoReally? I don't think that's true: I use Tor (well, not right now, d'oh!) and people respond to my posts.
- youwouldntcar 6y agoYes, really. It’s not that hard to check, just log off, create a new account through Tor and try to comment.