10 ms·
Tor Snowflake Proxy
- i67vw3 5y agoCool, I believe russia recently blocked tor project main website, to prevent users from downloading tor bowser from clearnet. https://www.rt.com/russia/542552-russia-bans-tor-project/ https://www.rt.com/russia/542552-russia-bans-tor-project/
- londons_explore 5y agoEven the linked domain is blocked in the UK (on some ISP's)
- jevoten 5y agoWhich domain do you mean? https://snowflake.torproject.org/ https://snowflake.torproject.org/ ?
- EwanToo 5y agohttps://blog.torproject.org/tale-new-censors-vodafone-uk-t-mobile-uk-o2-uk-and-t-mobile-usa/ https://blog.torproject.org/tale-new-censors-vodafone-uk-t-m... has more info on this, it's not new Most residential ISPs in the UK default to have filtering enabled, which can be removed by contacting the ISP or via a web form
- aaronsdevera 5y agoReminds me of the residential proxy services known for fraud and hacking... Google cache of TrendMicro report https://webcache.googleusercontent.com/search?q=cache:RUzFCaCXGiEJ:https://www.trendmicro.com/vinfo/de/security/news/cybercrime-and-digital-threats/shining-a-light-on-the-risks-of-holavpn-and-luminati+&cd=1&hl=en&ct=clnk&gl=us https://webcache.googleusercontent.com/search?q=cache:RUzFCa... Looks like Tor Project is operating with a similar model, using Snowflake proxy users as a sort of broker onto the network. Clever, but will be interesting to watch how this gets used. My testing so far of the Snowflake broker seems to have attracted less than benign hosts https://twitter.com/aaronsdevera/status/1473354766965035013 https://twitter.com/aaronsdevera/status/1473354766965035013
- prisout64 5y agoAnyone running a proxy? I definitely want to give back and it would not be a problem to run one, are there any security implications I need to consider? looking at their Faq it seems safe enough...
- WelcomeShorty 5y agoWhen you consider running an exit on your home IP: you will be blocked by Netflix.
- angularbot77 5y agoSnowflake is not an exit node though, just an intermediary
- thejosh 5y agoI ran a bridge for a while, had no problems with anything as I was just a bridge. Had a decent connection when I did.
- samhw 5y agoI'm running one. It seems totally fine, and I'd really strongly recommend doing it. Remember you have to leave a tab open for it to work. The website doesn't emphasise this enough, in my view. If you simply pin the tab, it'll be (a) very persistent and hard to accidentally close, and (b) totally inconspicuous, so I recommend doing that. I'd also strongly recommend running a full Tor node. The best way we can support Tor is to flood the zone with proxies, so it's no longer possible for intelligence agencies to control quora of Tor entry and exit nodes, as they very likely do. If you live in the developed world and have a good internet connection, I think it's a civic duty to redistribute your bandwidth - to socialise the means of conduction. Edit: 'Quora' was probably a poor choice of word, since a quorum implies consensus between nodes, as in a distributed system. It's really about intelligence agencies controlling _majorities_ of nodes - or even a large number - so as to make it more statistically likely that any given Tor circuit will begin and end with a node under one's control.
- 5y ago
- gnfargbl 5y agoHow does this cope with the case where the NAT hole-punching fails and both WebRTC clients are unable to accept an incoming connection? A TURN relay seems like it would get blocked. Edit: I should have just read the documentation [1]. It relies on the STUN/TURN servers being public and commonly used so that blocking them will break many other applications. Unfortunately, I don't know if the regimes where this is needed will care about that. [1] https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/wikis/Technical%20Overview#caveats-for-stun-and-turn https://gitlab.torproject.org/tpo/anti-censorship/pluggable-...
- tootahe45 5y agoJust a reminder if you're being censored in any serious way then don't use TOR, as the network is largely controlled by a few actors and the devs don't seem to care / or don't have the proper resources to deal with it. https://nusenu.medium.com/is-kax17-performing-de-anonymization-attacks-against-tor-users-42e566defce8 https://nusenu.medium.com/is-kax17-performing-de-anonymizati...
- alufers 5y agoIs there any alternative, though?
- bbqbbqbbq 5y agoOutline (getoutline.org) is a super easy to use you run on a cloud server. No logging and it works everywhere there's censorship, and it's easy to share access to your server with as many or as few people as you like. The only cost is the cost of running the cloud server, a few dollars a month if you use LightSail or DigitalOcean. Disclaimer: I used to work on it.
- i-848181-neev 5y agoI’m a fan of Outline and I ran my own DO droplet when the criticism around ProtonVPN and mail was happening, few minor pain points for me were the deprecated warnings that showed when booting the Linux client and it unfortunately presented me with the most connectivity issues. It would show connected but after doing IP lookups would reveal true IP. It’s seamless and easy to maintain but seemed unreliable at least on ZorinOS.
- throwaway77384 5y agoWhat would one use when one is being censored in any serious way?
- Santosh83 5y agoSymmetric encryption with physical key exchange.
- orborde 5y agoThis uses domain fronting, which both Google and Amazon forced Signal to stop using in 2018: https://signal.org/blog/looking-back-on-the-front/ https://signal.org/blog/looking-back-on-the-front/ Did cloud providers get more permissive since then? EDIT: Tor also got hit by some shutdowns in 2018 due to its use of domain fronting: https://blog.torproject.org/domain-fronting-critical-open-web/ https://blog.torproject.org/domain-fronting-critical-open-we... https://gitlab.torproject.org/tpo/applications/tor-launcher/-/issues/40007 https://gitlab.torproject.org/tpo/applications/tor-launcher/... From the second link, looks like the plan is that Snowflake will annoy cloud providers less by only using the domain-fronting channel to propagate routing info: > sending Tor traffic directly through domain fronting (rather than using it only to distribute bridges and snowflakes) enables these platforms to claim that this technique is used by malware and therefore harmful to users, justifying shutting it down. > Snowflake is a more sustainable way for us to use the expensive but high censorship-resistance features of domain fronting as a low bandwidth bootstrapping channel.
- jerheinze 5y agoFWIW there's another method for bootstrapping Snowflake that uses Google's AMP cache: https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/issues/25985 https://gitlab.torproject.org/tpo/anti-censorship/pluggable-...
- nirui 5y agoIf I'm allowed to guess, Tor Browser has Meek built in and it includes a few services hosted on Microsoft cloud. As far as I understand it, it can be quite expensive consider the total amount of traffic those Meek server must relay. However, I wouldn't consider it "censorship-resistance". From reading their Technical Overview document, I got the impression that they put a lot of faith on Domain Fronting which might not be a good thing > ... the censor cannot block the broker without blocking all of Google, or all of Amazon, hence collateral freedom. Yeah, true ... true ...
- xvector 5y agoDevil's advocate - VPN might be better than Tor. Hear me out: A VPN provider's business is keeping your connection private. They have no incentive to log because the leakage of such logs would be catastrophic. Thus, a reputable VPN provider is unlikely to be a front for a nation-state actor. There is a strong financial incentive for a VPN provider to do their job, as stated, no conspiracies, and do it well. Tor, on the other hand, has frequently had bad actors comprise a significant portion of running nodes, to the point where being the victim of a correlation attack wouldn't be unlikely for a regular user. Intelligence agencies and bad actors alike have immense incentive to saturate the Tor network with bad nodes. Finally, Tor has been plagued with issues and vulnerabilities, that they seemingly do not have the manpower or technical ability to fix: https://www.hackerfactor.com/blog/index.php?/archives/906-Tor-0day-The-Management-Vulnerability.html https://www.hackerfactor.com/blog/index.php?/archives/906-To... I suspect that the future of anonymous communication will be a mixnet resistant to correlation attacks (unlike Tor.) An example - https://nymtech.net/ https://nymtech.net/
- elsjaako 5y agoThe major VPNs log, this has been shown in court cases. If they say they don't they're either using a limited definition of log, straight up lying, or about to run into problems with the government. My source isn't an open one, but here is one (that sites different cases than I saw): https://restoreprivacy.com/vpn-logs-lies/ https://restoreprivacy.com/vpn-logs-lies/
- schleck8 5y agoRelevant: recently it was discovered that 10 % of tor nodes of any role have been run by a single actor, which most likely was a deanonymization effort https://therecord.media/a-mysterious-threat-actor-is-running-hundreds-of-malicious-tor-relays/ https://therecord.media/a-mysterious-threat-actor-is-running...
- angularbot77 5y agoHow difficult would it be to make this extension android-for-firefox compatible? What about a standalone client?
- jerheinze 5y agoA mobile browser addon would be less than ideal since you'd want the client to stay running in the background and since not everyone uses Firefox. The Guardian Project is working on implementing that standalone proxy server approach directly into Orbot: https://github.com/guardianproject/orbot/issues?q=is%3Aissue+snowflake+label%3Asnowflake https://github.com/guardianproject/orbot/issues?q=is%3Aissue...
- tapper 5y agoI tryed out the Firefox pluggin, how do you know that it's working?
- fsflover 5y agohttps://addons.mozilla.org/en-US/firefox/addon/torproject-snowflake/reviews/1432746/ https://addons.mozilla.org/en-US/firefox/addon/torproject-sn...
- marcodiego 5y agoWhat I really want: to be able to open a port on my computer behind a NAT and have a way for people outside it to connect without using special software. Is there a solution yet?
- KarlKemp 5y agoCloudflare used to have a service that would allow you to connect any local port to your cloudflare-managed domain. But I can’t find it just now.
- erulabs 5y agoWell, without using any special software is tricky, but I’m building a startup that offers this sort of tunneling for home-hosting purposes. As for “special”-software-less, you might have to wait for IPV6 and a hosting-friendly ISP.
- wwn_se 5y agoJust forward the port?
- marcodiego 5y agoI think that is only possible if a have control of the NAT/router, right?
- npteljes 5y agoUPnP has a protocol to handle that, but the router needs to support it and have it enabled.
- marcodiego 5y agoThat allows only outgoing connections, right? I there a way for me, behind a NAT, to pass an address for someone to connect to a port open on my machine?
- 5y ago