6 ms·
Thanks for doing this. Early 2010s, I provided free wifi when I lived across the street from a subsidized housing block. I tunneled all their traffic through
by sillystuff 4y ago
Thanks for doing this. Early 2010s, I provided free wifi when I lived across the street from a subsidized housing block. I tunneled all their traffic through Tor (including DNS via a hacky script).
I was too much of a coward to take the risk of the police breaking down my door because of something done by some random person using the free wifi. Thanks to others like you who were braver than I was, a bunch of folks had free Internet access.
- crtasm 4y agoBut then weren't you leaking all their HTTP traffic to a possibly malicious exit node?
- gary_0 4y agoThese are people who connected to a random open wifi network. Tor exit nodes were probably the least of their worries.
- crtasm 4y agoThat's no justification for adding a known-malicious network to the list.
- sillystuff 4y agoGood point. I considered adding more details, but felt they were off-topic to the purpose of my post, and didn't want to have the "thank you, brave soul for running an exit node. Your actions might enable other good things that you might not have expected" message lost in noise. There was a captive portal page (another hacky script running as a CGI) where the user had to agree to, "not be a dick" to continue. And, the user also had to agree that they were aware that others, who were dicks, could be accessing their data if it was not encrypted and gave the example of http vs. https in the address bar of the browser. There was also a picture of an onion on the captive portal page, and a link to a FAQ which talked about open wifi and Tor. Exit nodes were not geo restricted, so if nothing else, the warnings and explanations allowed the users to understand why sites often seemed to think they were in a different country. There is a limit to what people are able to digest about a subject that is not one they focus on. But, the warnings (right on the main captive portal page; without having to navigate to the FAQ) were sufficiently scary to encourage caution. The most likely available alternative would have been public access terminals in the library, or other open wifi for those with portable devices. Public access terminals could be running keyloggers and worse. Even if the public terminal is free of malware, the non-technical user might just close a logged in browser tab/window, not realizing that is not sufficient to log them out. Yes, even with users being careful about looking for https in the URL bar, some websites are broken and use https for their login page, but use http for their session cookies. But, trying to protect from these incompetent websites would require shutting down all public wifi everywhere (OWE [opportunistic wifi encryption without authentication] did not exist yet). I think my open wifi (and open wifi generally, as well as Tor) were/are a net good. If, after this additional detail you still disagree, then we will just have to disagree.
- crtasm 4y agoYou went above and beyond with it all, yes I was mainly concerned how informed the users were and agree open wifi and Tor are a net good. Appreciate the writeup!