8 ms·
I'm using Tor to access my local network services through hidden services. Since I don't need to hide my IP address I'm going to follow your advice gratefully.
by ycuser2 5y ago
I'm using Tor to access my local network services through hidden services. Since I don't need to hide my IP address I'm going to follow your advice gratefully. Didn't know that's possible.
- steerablesafe 5y agoAny reason you don't use some kind of VPN solution for that instead?
- ycuser2 5y agoHidden services are very easy to configure (the basic config, if you want to be as anonym as possible you have to do more). Install tor, add a few lines to config, done. And: You don't have to change your firewall settings at all. Nothing is exposed to the clearnet. You can also make your service be accessible only to certain clients which have a certificate. I consider this very secure.
- steerablesafe 5y agoI guess I can understand that from an ease of configuration standpoint. Having said that I had no trouble with setting up zerotier VPN, which is also very easy to configure.
- Karrot_Kream 5y agoI do the same but you still need to be careful when running Zerotier to listen only on IP addresses that the ZT link is assigned. I run a private mailserver and I've made sure that there are no sockets listening on any non-ZT externally routable IP address. (I guess for good measure I could have nftables drop traffic coming in on those ports on my WAN link.) But with Tor you just point it to a service listening on 127.0.0.1 or [::1] and you're in business. For me ZT is fine, but for folks who want to muck around a bit less, I can see the appeal of Tor.
- heavyset_go 5y ago> You can also make your service be accessible only to certain clients which have a certificate. I consider this very secure. Are you talking about this? https://community.torproject.org/onion-services/advanced/client-auth/ https://community.torproject.org/onion-services/advanced/cli...
- ycuser2 5y agoYes, client authentification it is called.
- heavyset_go 5y agoThanks for mentioning it, I would have overlooked that feature entirely, otherwise.
- conradev 5y agoOnly recently has there been an easy to setup and secure alternative with the same properties – Tailscale It is centralized, yes, but it is way, way faster if you care about latency https://tailscale.com/ https://tailscale.com/ (you can also self-host it with the open source “headscale” project)
- rattlesnakedave 5y ago+1 for tailscale, it is an absolute joy to use.
- goodpoint 5y agoNot only it's easier to configure, but it provides better security. The onion address works as a server certificate. 1) You don't have to pay or trust a VPN provider 2) It works on dynamic IP addresses and without relying on DNS 3) It exposes only one TCP service
- _wldu 5y agoThat's sort of like having backdoor access to your internal network (similar to teredo). Others may use it to gain access to that network. If it's your home, that may be OK to you, but if it is an employer, you may want to obtain approval to do that and be sure all of your hidden services use keys or strong passwords for access.
- c0wb0yc0d3r 5y agoCould you explain this a bit more? How would this be more open than port forwarding? I don't see how someone could leverage this without exploiting whatever app is hosted as the hidden service?
- jstanley 5y agoYes, it's exactly like port forwarding.
- ycuser2 5y agoAre you sure? Don't an attacker need knowledge of the onion address, which is almost unguessable? But with client authentification that wouldn't be a problem anyways because only chosen clients get access.
- chatmasta 5y agoOnion address is not unguessable, it's stored on a DHT shared by relays with the HSDir flag (which they earn after ~7 days IIRC). I think this changed slightly with v3 addresses, so my comment might be out of date, but I think the general premise remains the same. (EDIT: Apparently with V3 addresses, there is still a DHT, but client uses key derivation so that the HSDir only stores a daily-rotated identifier known as a "blinded public key." [0]) Although your hidden service address is not hidden, you can require that any client connecting to it present a valid authorization key (I think this is also new in V3?). Also, it obviously depends which service you're exposing — if you are exposing an SSH server that only allows key-based authentication, then it shouldn't matter if people can simply connect to it — assuming you trust the SSHD software, and your threat model doesn't depend on avoiding detection completely. [0] https://blog.torproject.org/v3-onion-services-usage/ https://blog.torproject.org/v3-onion-services-usage/