4 ms·
There is no legitimate use for it in this context, and as such, every single instance of it has been associated with a crime, mostly CSAM.
by lexicon0 6y ago
There is no legitimate use for it in this context, and as such, every single instance of it has been associated with a crime, mostly CSAM.
- danShumway 6y ago> There is no legitimate use for it in this context There's no legitimate usage for World of Warcraft on a work computer, and I'd happily ban that from work computers. But I also wouldn't hop onto an unrelated article for new players and imply that all of them were criminals. The linked article never mentions work computers, it's talking to website operators. If your objection here is that you think Tor is inappropriate at this moment in one specific work setting, then fine, but that's not really adding anything to the conversation about whether or not general websites should be made available over Tor. It's just unrelated FUD. I want to be clear, the goal of Tor proponents is for everyone to be running Tor (or something similar), and for most websites to be available over Tor by default. People should be running Tor on their smartphones, on their home laptops. Tor should be the default way that people share files with each other, and the default way that people set up technical blogs, or even just quick websites that show off pictures of their cat. The vision of the Tor project is a world where Tor is normal and ubiquitous for regular, non-technical people. So unless your work policy bans all personal devices from your network, creating an expectation that any smartphone that joins and boots up a Tor browser automatically belongs to a criminal is contrary to the goals of the privacy movement. Our goal is that every device and every website should be private by default. Your network should be the exception, and it should only have company-owned devices on it. And of course it's fine if you disagree with that, you don't have to be a privacy proponent. Lots of smart, reasonable people disagree with us about what the balance is between security and privacy. But demonizing Tor users in ordinary, everyday contexts is anti-Tor. > or primarily available on onion routing, all workplaces will immediately block access and look at anyone who accesses with great incredulity To go a step farther and suggest that making a website available over Tor should automatically mean that people who visit it are suspicious -- that is also anti-Tor and (I would argue) anti-privacy in general. If I went into an interview for any company in any field offhandedly mentioning that I ran a Tor website, and then had to field a bunch of questions about whether or not I was a criminal, that would be a major red flag to me to avoid that company.
- lexicon0 6y agoI'm adding my thought that hosting a website on Tor primarily, will make it totally unavailable from many workplaces. Currently, Tor is not the place for a site that doesn't _require_ an extremely high level of anonymity of access. The network policy does ban all personal devices, in order to control what connections originate from inside the network. To be clear, I'm not demonizing Tor or Tor users. I like what the Tor project wants to do, and I support it, but believing it will be allowed in many corporate settings, in July 2020, is extremely naive. As I already mentioned, there's no legitimate use case to allow this in a corporate setting.
- Reelin 6y ago> There is no legitimate use for it in this context Do concerns about being tracked between websites suddenly disappear at work? Is it no longer legitimate for an employee to log in to a personal account for non-work purposes via the corporate network on (for example) their lunch break? Etc, etc. Also I'm a bit confused by your stance given the realities of encryption. Does your network strictly block all outbound traffic that it can't actively MITM? If not, a nefarious employee could proxy their criminal (Tor or other) traffic through an external machine that they controlled. In fact this would be the obvious thing to do as visiting an HTTPS (apparently) website on a personal device would seem much less likely to arouse suspicion.
- lexicon0 6y ago> Also I'm a bit confused by your stance given the realities of encryption. Does your network strictly block all outbound traffic that it can't actively MITM? If not, a nefarious employee could proxy their criminal (Tor or other) traffic through an external machine that they controlled. In fact this would be the obvious thing to do as visiting an HTTPS (apparently) website on a personal device would seem much less likely to arouse suspicion. Yes - with some exceptions (lunch break facebook/youtube etc)