14 ms·
Arti – An implementation of Tor in Rust
- panick21_ 5y agoIs this possible to run on no_std systems or systems like XousOS (has its own std)? Would be cool to run on Precursor. https://www.crowdsupply.com/sutajio-kosagi/precursor/updates/the-platform https://www.crowdsupply.com/sutajio-kosagi/precursor/updates...
- trinity-1686a 5y agoRight now it's not possible, but you could open an issue and maybe someday it will be! If you want to open an issue, it's here https://gitlab.torproject.org/tpo/core/arti/-/issues https://gitlab.torproject.org/tpo/core/arti/-/issues . If you don't want to create an account, say it and I'll create the issue for you. Edit: corrected typo in link
- seumars 5y agoCouldn't find any introduction to the project on the blog but the official repo has more info on the background for the project: >Rust is more secure than C. Despite our efforts, it's all too simple to mess up when using a language that does not enforce memory safety. We estimate that at least half of our tracked security vulnerabilities would have been impossible in Rust, and many of the others would have been very unlikely. >Arti is cleaner than our C tor implementation. Although we've tried to develop C tor well, we've learned a lot since we started it back in 2002. There are lots of places in the current C codebase where complicated "spaghetti" relationships between different pieces of code make our software needlessly hard to understand and improve. https://gitlab.torproject.org/tpo/core/arti https://gitlab.torproject.org/tpo/core/arti
- bobbyskelton41 5y agoThe introduction was here: https://blog.torproject.org/announcing-arti/ https://blog.torproject.org/announcing-arti/
- nonrandomstring 5y agoWell done and thank you to all involved. You are making a real difference on the side of democracy, human rights and the values of the free world at an uncertain time when so much is under threat.
- iamnotarobotman 5y ago
- jokethrowaway 5y agoYou can't prevent criminals from using math to conceal their activities (they can just use other solutions), you can just prevent law abiding citizens from having privacy.
- ajconway 5y agoNot really. TOR is specifically not safe against a global passive observer, which the (supposedly) good guys are.
- andai 5y agoI've been wondering about this. Afaik Ross Ulbricht was caught due to shitty opsec. Was that a case of the NSA having that capability and not sharing it with the FBI?
- gzer0 5y agoUlbricht was first connected to "Dread Pirate Roberts" by Gary Alford, an Internal Revenue Service investigator working with the U.S. Drug Enforcement Administration on the Silk Road case, in mid-2013.The connection was made by linking the username "altoid", used during Silk Road's early days to announce the website, and a forum post in which Ulbricht, posting under the nickname "altoid", asked for programming help and gave his email address, which contained his full name. [1] https://en.wikipedia.org/wiki/Ross_Ulbricht#Arrest https://en.wikipedia.org/wiki/Ross_Ulbricht#Arrest
- dtx1 5y agoEvery time a piece of legacy c/c++ code get's replaced with something written in a sane language i smile a little!
- pjmlp 5y agoUnfortunely there are tons of domains that it will never happen, given the existing ecosystem We as society basically have to undo 50 years of going into the wrong direction, without the economical incentives to fix them, rather mitigate their faults.
- dtx1 5y agoWhile that is true and for some extreme cases might stay true for a long time (> 100 years) most software has a lifetime, even if it's damn long and as long as we start writing new software in better languages we will see progress over time, simply by old software dying or no one being able to deal with the legacy codebase anymore
- zozbot234 5y agoThere are millions of lines of code written in COBOL in production use, pretty much all of them addressing business-critical needs. FORTRAN scientific codes are not far behind, either. Better get crackin'.
- pjmlp 5y agoYet COBOL and Fortran standards are way more modern than WG14 will ever bother doing to C.
- qersist3nce 5y agoSo at this point it is ready for passing traffic through a SOCKS proxy. Meaning we can `cargo run --release -- proxy` and redirect applications to use port `9150` for their network connections. Couple of related questions: - Does anyone know, in a Linux distro, how to pass all system traffic through a SOCKS proxy port? I'm not looking for intermediary proxy handlers but an official method to force all user and system apps to use an arbitrary port. - If it is not possible to do so, does `NetworkManager` have a setting for this? - Is it possible to at least change Chrome/Firefox ports via CLI to an arbitrary port?
- koblas 5y agoIsn't that just NAT through a SOCKS proxy as transport. Never would have imaged that use case.
- qersist3nce 5y ago>Never would have imaged that use case. circumventing censorship and geo-restrictions?
- koblas 5y agoLet me clarify -- I never would have imagined SOCKS being used for this use case. There was no such thing as geo-restrictions or censorship at the time on the internet.
- guerby 5y agoThe way it's done is described here: https://unix.stackexchange.com/questions/166692/how-does-a-transparent-socks-proxy-know-which-destination-ip-to-use https://unix.stackexchange.com/questions/166692/how-does-a-t... A part from tor I don't know if there's a generic tool packaging this.
- guerby 5y agoFound one here: https://hev.cc/3033.html https://hev.cc/3033.html https://github.com/heiher/hev-socks5-tproxy https://github.com/heiher/hev-socks5-tproxy
- DeathArrow 5y ago
- freemint 5y agoWould it matter?
- michaelcampbell 5y agoTo many, yes.
- pjmlp 5y agoDo those same people also use SELinux?
- michaelcampbell 5y agoDunno, is that relevant? Are any among us completely devoid of any inconsistencies or hypocrisy?
- pjmlp 5y agoGiven it was developed by NSA, completely relevant.
- edgyquant 5y agoBut Tor wasn’t, so it’s a derail to begin with
- dragonwriter 5y agoTor was developed by the US Naval Research Laboratory to protect communications of the US intelligence community, so while it wasn't strictly developed by the NSA, if one considers products of the NSA contaminated by their connection to the US intelligence community, it's pretty hard not to see Tor as tainted in the same way.
- colesantiago 5y ago
- WesternWind 5y agoI mean I urge folks who have the ability to direct some of their company's money towards Tor. It's directly helping both Ukranian and Russian citizens right now.
- colesantiago 5y agoSure Tor helps Ukrainian and Russian citizens, but I urge the Tor foundation to question themselves and to stop accepting crypto token donations and grants. It acts as an endorsement and emboldens the cryptobros, enthusiasts and fans to pump the price of the token.
- krater23 5y agoWhen you know a better solution just name it. It's easy to criticice a decision when you don't need to find a better way. Who's interested in some crypto bros and some idiots that lose their money when you don't have another working possibility?
- colesantiago 5y agoI already did. They can go for the Rust Foundation Grants Program or perhaps the Mozilla Foundation grants program. I am sure there are other grants that I have missed out but the solution is there.
- DoItToMe81 5y agoWhy should they forgo an opportunity for funding that allows people to donate in countries where direct bank transfers to the Tor project would be logged and marked as suspicious, and which is resistant to payment processors deciding not to process the donations? Because you personally don't like cryptocurrency? That is ridiculously childish.
- solanav 5y agoI'm so happy we are finally getting an easy to use library to use Tor. I've wanted to use Tor in some of my projects but I didn't like having to install it or expecting the user to have it installed already. Time to re-learn rust...
- hexo 5y agoThe title. Omg. It is incorrect. Misleading. And infuriating.
- fastball 5y agoHow so?
- hexo 5y agoBecause it is just a library for rust programs. Not even close to reimplementation of Tor for general use. edit: yea, downvoters, show your own inability to process truth. I love this grown up behavior here on HN.
- pitaj 5y agoIt's also a binary that supports a SOCKS proxy. FYI, complaining about downvotes violates the HN guidelines.
- cassepipe 5y agoI think the downvotes were for an very emotional claim ("infuriating") backed up by 0 arguments. Although it is weird to me that the actual explanation got downvoted instead of the original claim
- neilalexander 5y agoI’m not in the slightest bit surprised you are being downvoted — your comment is overly dramatic and not a remotely useful contribution. The title of the post of “An implementation of Tor in Rust”. The project claims to be an implementation of Tor, which it is, and it claims to be written in Rust, which it is. It doesn’t claim to be a standalone replacement, it doesn’t claim to be finished and it doesn’t claim to be not-a-library.
- wolrah 5y agoIt's also a SOCKS proxy, which at least the last time I used Tor standalone (where I'd have to configure it myself, as opposed to as part of TBB or TAILS where it's set up for me) was the main way a client would access the network.
- anthk 5y agoI2P should be preferred. IP2D it's a nice daemon.
- ravenstine 5y agoYeah I hate to always be that guy, but while I think Tor is great in that it exists at all and has inspired other projects, I think I2P is an overall better design. Not having a history with the US military or funding from DARPA is a plus, IMO. Tor isn't necessarily flawed for that reason, but I trust less anything the US government takes an interest in. For anyone wondering what we're talking about: https://geti2p.net https://geti2p.net (Official Java implementation) https://github.com/PurpleI2P/i2pd https://github.com/PurpleI2P/i2pd (C++ implementation) The unfortunate thing is that, as far as I'm aware, I2P doesn't have a "Tor Browser" of sorts, and most people would want to use I2P as a clearnet proxy; the audience for I2P may always be significantly less than that of Tor even if it was revealed that Tor was totally flawed. I think that I2P could benefit from selling itself less as a means of anonymity and more as decentralized, censorship-resistant web hosting. The clearnet should then have inproxies to expose I2P sites rather than the other way around, as is the typical use case for Tor. That way you can spin up an I2P instance anywhere, instantly have a web server on a unique address, and have it be available on any number of clearnet inproxy nodes as well as to anyone connected directly to the network. Having played a lot with I2P recently, I find it more "fun" than using Tor. It lacks in content, but its focus on hidden services (eepsites) and the relatively small number of users is reminiscent of he web back when I first started using it in the 90s. I like that it has a sort of DNS system that is only as centralized as you want it, and that it has a built in way of assigning your own domain aliases. Even if you (the reader) aren't interested in anonymous decentralized networking for any practical reason, I'd say it's worth testing out I2P just to get a kick out of how novel it is.
- hda2 5y agoAn enticing UVP for Arti would be that it allows rust services to easily have cheap built-in network redundancy via tor integration. This would make it trivial for administrators to set up alternative access to their services if their services can reach tor. This would allow global access to services in case of DNS outages, superfluous takedown requests, or anything in between. Onion service support seems to be TBD, unfortunately.