11 ms·
Tor is not just for anonymity (2022)
- 1vuio0pswjnm7 3y agoThe internet is no longer as peer-to-peer friendly as it once was. Hence the existence of commercially-motivated hacks run by third parties such as hosting, e.g., Cloudflare, etc., including tunneling, e.g., ngrok, etc. Alternatively, Tor relies on third parties but AFAIK it's not so centralised and it's not commercially-motivated. That is what differentiates it from all the other options. There is no company behind it trying to make money by exploiting internet subscribers trying to connect with each other (not the so-called "tech" company). Tor can have uses other than the ones normally discussed such as anonymity and evading censorship. Tor can provide reachability without use of commercial eavesdropping third party intermediaries. For example, one can use Onion Services for advertising open IP:port information that is needed for peer-to-peer connections over other, faster peer-to-peer overlay networks, not the Tor network. The Onion Service can function as the "rendezvous" server for making peer-to-peer connection outside of Tor. Tor's Onion Services can be used to exchange IP:port information for making direct connections over the internet without using Tor. No need to use commercial third parties. Ngrok, Tailscale, etc. all require use of servers run by a commercial third party. Tor does not. There is ample free software that can establish peer-to-peer connections over the internet but in every case it requires some reachable server running this software on the internet, and for most users that means they have to run a server and pay a commercial third party for hosting. Tor has no such requirement. Imagine being able to share content with family, friends, colleagues without the need for so-called "tech" companies^1 acting as intermediaries ("middlemen"). With a reachable IPv4 address this becomes possible. It would be nice if every home internet access subscriber received a reachable IPv4 address from their ISP. No doubt, some do. But on today's internet most do not. The so-called "tech" companies all have reachable IPv4 addresses. Hence they assume the roles of middlemen and use this position to exploit internet subscribers for profit. Something like Tor provides a solution. Again, it is not always necessary to route all traffic over Tor. Tor can have other uses. When the goal is simply peer-to-peer connections, Onion Services can be used to bootstrap peer-to-peer overlay connections using the user's choice of software by providing a secure, reliable way to exchange IP:port information. Goal here when using Tor is not anonymity nor censorship evasion, it's reachability. Similarly, goal of peer-to-peer is not necessarily anonymity nor evading censorship either, it's bypassing commercially-motivated, eavesdropping middlemen known as "tech" companies, and avoiding the annoyances of advertising. A possible additional benefot of using Tor in this way is elevated privacy. Google, for example, cannot easily discover Onion Services. No one can discover Onion Services using ICANN DNS. 1. The term "tech" as in "tech company" means a company, usually a website, that collects data from and about people to support the sale of advertising services because advertising services are the only services the company can sell on a scale large enough to sustain a profitable business. More reading/viewing: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling Tor Hidden Services (now called "Onion Services") https://jamielittle.org/2016/08/28/hidden.html https://jamielittle.org/2016/08/28/hidden.html As one author wrote on Github: "onion-expose is a utility that allows one to easily create and control temporary Tor onion services. onion-expose can be used for any sort of TCP traffic, from simple HTTP to Internet radio to Minecraft to SSH servers. It can also be used to expose individual files and allow you to request them from another computer. Why not just use ngrok? ngrok is nice. But it requires everything to go through a central authority (a potential security issue), and imposes artificial restrictions, such as a limit of one TCP tunnel per user. It also doesn't allow you to expose files easily (you have to set it up yourself)." https://github.com/ethan2-0/onion-expose https://github.com/ethan2-0/onion-expose As another Github contributor put it: "With onionpipe, that service doesn't need a public IPv4 or IPv6 ingress. You can publish services with a globally-unique persistent onion address, and share access securely and privately to your own allowlist of authorized keys. You don't need to rely on, and share your personal data with for-profit services (like Tailscale, ZeroTier, etc.) to get to it." https://github.com/cmars/onionpipe https://github.com/cmars/onionpipe https://news.ycombinator.com/item?id=36734956 https://news.ycombinator.com/item?id=36734956 https://news.ycombinator.com/item?id=30445421 https://news.ycombinator.com/item?id=30445421 https://news.ycombinator.com/item?id=29929399 https://news.ycombinator.com/item?id=29929399 "Finally, onion services are private by default, meaning that users must discover these sites organically, rather than with a search engine." [Small websites with small audiences get buried by advertising-supported search engines anyway.] https://nymity.ch/onion-services/pdf/sec18-onion-services.pdf https://nymity.ch/onion-services/pdf/sec18-onion-services.pd... https://media.ccc.de/v/31c3_-_6112_-_en_-_saal_2_-_201412301715_-_tor_hidden_services_and_deanonymisation_-_dr_gareth_owen https://media.ccc.de/v/31c3_-_6112_-_en_-_saal_2_-_201412301... https://wiki.termux.com/wiki/Bypassing_NAT https://wiki.termux.com/wiki/Bypassing_NAT (Termux recommends Tor over Ngrok) https://github.com/ajvb/awesome-tor https://github.com/ajvb/awesome-tor
- john_the_writer 3y agoThe problem with TOR is CloudFlare and the likes. Many exit nodes are blocked, so you cannot reasonably get to a heap of sites. If I can't get to sites because they're blocked, then I'm not really on the internet. Not TOR's fault, but it is something holding it back. Sadly.
- goodpoint 3y agoIt's written "Tor", not "TOR".
- Fred34 3y agoYea I mostly use LibreWolf now as Tor is too slow and too many services block it and just use it to read (many news sites have tor addresses now). But another reason to support the project is that a lot of the anti-fingerprinting innovations developed by the Tor project eventually makes their way to more usable browsers. The Tor project gets a large bit of funding to find and patch privacy holes in their Firefox-based browser ― the solutions they come up with can often be implemented in other Firefox browsers.
- LeoPanthera 3y agoTor's ability to use exit nodes is much less interesting to me than Tor-hosted Onion sites. I wish more sites also offered an onion.
- chungy 3y agoSometimes Tor hidden services are just convenient if you're behind a NAT you can't control (be it corporate or carrier).
- system33- 3y agoI think this is where most people’s minds would jump when reading the title. When it’s actually about Tor providing security in general, not just anonymity specifically. It was written in response to someone claiming something like “Tor provides no benefit over TLS unless you want anonymity” and strives to demonstrate it provides non-anonymity security benefits beyond what TLS can do. It discusses a very specific scenario because that’s what I was arguing about with someone. The title could’ve been better.
- pinkcan 3y agotailscale got a mini at home serving as an exit node set this up one time the it dep was being obtuse about fw rules, and locked us out of ssh, so we couldn't push to gh - amateur hour; add more shadow it
- superkuh 3y agoJust don't mistake tor onion service addresses for permanent things. The .onions are much less of a priority than the clear web "anonymous" proxy. If onion support gets in the way of clear web proxy security it will be removed. Any particular version of Onion addresses will simply cease to exist and stop working in the tor project's software every 10 years or so; completely wiping out the entire tor ecosystem and all links. It's happened before and it will happen again. So yeah, .onion services are secure but they're also transient. Don't try to build a community that relies on .onion links continuing to work over years.
- Fred34 3y agoOr Tor will release another address system. I remember when the Tor team released their v3 onion address a few years back they killed access to the old v2 sites on the network by not making the new browser versions backwards compatible.
- jtvjan 3y agoIt's not like support for v2 was removed immediately after v3 was released. v2 and v3 coëxisted for over three years, giving 16 months advance warning of the deprecation, ending in a four month period where support was removed from the server but the client could still connect to it. Operators had plenty of time to upgrade their services.
- mike_hock 3y agoYet, the clear-web DNS entries of major websites haven't changed in 15 years or more. It's not like you can just google an old Onion bookmark that's gone stale to get the current address. Address longevity is especially important if you're trying to re-democratize the internet and give everyone equal opportunity to host content, not just a handful of mega corporations. In that ecosystem, it wouldn't be out of the ordinary to have 5+ year old bookmarks laying around that you haven't visited in a while but want to check out again. It's a pre-Google internet.
- 3y ago
- collsni 3y agoI liked the CA MITM call out.. we just trust these organizations to not deploy wildcard malicious certificates. Kinda messed up devices come preloaded with unchangeable trusted CAs Guy knows his stuff, also works for dod.
- yjftsjthsd-h 3y ago> we just trust these organizations to not deploy wildcard malicious certificates. Don't we have transparency logs to check that now?
- judge2020 3y agoYes, Chrome and Safari will not load a site if the cert is not in CT. https://no-sct.badssl.com/ https://no-sct.badssl.com/
- sedatk 3y agoalso Edge. It's an open issue on Firefox: https://bugzilla.mozilla.org/show_bug.cgi?id=1281469 https://bugzilla.mozilla.org/show_bug.cgi?id=1281469
- ignoramous 3y agoWow. Firefox should really prioritize this if all major browsers are doing it already.
- sedatk 3y agoThere is a theory which states that if ever anyone discovers exactly which decade old bug should be fixed in Firefox, it will instantly disappear and be replaced by some obscure web service by Mozilla Foundation. There is another theory which states that this has already happened. (in memory of Douglas Adams)
- 3y ago
- SLWW 3y agoOne very important thing that TOR provides is additional routes when international routing between ISPs is blocked/broken for whatever reason. Several websites (that are legal, legitimate in nature) get censored by tier-1 ISPs (for whatever reason) however even though they are clearnet websites, you can still view them out of country, since with TOR you can keep refreshing your routes until you get access.
- goodpoint 3y agoIt's written "Tor", not "TOR".
- toastal 3y agoGood example: I needed to get voter information abroad in order to get a mail-in ballot, but the government website blocked all foreign origin connections.
- Dah00n 3y agoHow awful. Which country?
- toastal 3y agoUnited States of America an eagle screeches in the distance
- ghgr 3y agoFun fact: the bald eagle scream heard in most movies and television shows is actually the call of a red-tailed hawk. https://www.clickondetroit.com/news/local/2023/03/28/do-you-really-know-what-a-bald-eagle-sounds-like/ https://www.clickondetroit.com/news/local/2023/03/28/do-you-...
- heywoodlh 3y agoThis should be considered unconstitutional...
- aaomidi 3y agoAlso keep in mind TLS leaks what website you’re connecting to using SNI.
- sedatk 3y agoNot with ECH. https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/
- aaomidi 3y agoYeah except nothing supports it
- jeroenhd 3y agoDoes anything even support ECH yet? It's still in a draft stage and all I see when it comes to normal web servere is low priority feature request issues that have been open for a few years. I've checked Apache, nginx, and Caddy, but all of them have open issues. Chrome has the feature locked behind a flag and so does Firefox. When it finally comes out, ECH will be great, but for now it's practically useless.
- vbezhenar 3y agoI'm not sure it'll be great. Right now censors can selectively block offending websites. With ECH they'd just block entire CDNs so large chunks of Internet will become inaccessible. At this point it's obvious that censorship in the Internet is inevitable. So I'd prefer to reduce blast radius.
- sedatk 3y ago> ith ECH they'd just block entire CDNs so large chunks of Internet will become inaccessible They would've effectively made Internet inaccessible. That has political consequences, and they would have to live with that, or revise their policies around content censorship such as finding a common ground with content providers so there would be no need to block the web site.
- Nezteb 3y agoBoth the original post and root pastly.net timeout for me. Is this just a funny coincidence? Is the site only accessible via Tor? Has something nefarious happened to the site? Either way, the original has fortunately been archived: https://archive.is/tRo73 https://archive.is/tRo73 https://web.archive.org/web/20230715011947/https://blog.pastly.net/posts/2022-11-09-tor-is-not-just-for-anonymity/ https://web.archive.org/web/20230715011947/https://blog.past...
- bawolff 3y agoWhile i do think the threat model of web-pki TLS is different from TOR, with sone of the problems in 1 not present in the other and vice versa, I'm generally unconvinced it is the pancea that this article presents it as. > DNS hijacking is impossible. DNS is simply not used. Sure, but now you have a new problem that tor hidden service identifiers are not really human identifiers. This makes attacks where you trick the user into going to the wrong site much easier. Which is more likely - DNS hijacking + no TLS (or at least no HSTS) or a user being tricked into typing the wrong incomprehensible string of letters. Personally i find the latter to be the more realistic threat to the average user. > BGP hijacking is impossible. Every interaction a Tor client has with a relay or onion service is authenticated such that you are guaranteed to be interacting with the relay/onion that you intend to be. I dont understand. BGP attacks in order to do passive monitoring seem just as do-able for TOR, although i guess now you need to do it in two places. Isn't bgp hijacking (if you can do it arbitrarily, which is unrealistic) basically a global passive adversary - the main thing tor famously doesn't defend against. > There are zero places a corporate firewall can inject itself to decrypt the traffic. There are zero places and zero parties between the Tor clients that a MITM attack can be performed. They could be the bridge. They could just spy on the client directly (usually the assumption is the corporate firewall can install stuff on your computer like custom CA certs. If push comes to shove just install spyware directly) The main benefit tor has against corporate firewalls is it is to obscure for anyone to care. > Do you assume the CT lookup process is secure? Are the parties you're communicating with misbehaving? Are your lookups in CT logs being logged and associated with you? Admittedly im not super familiar with CT validation, but i was under the impression that certificates contained the SCT, which is a signature that is validated on the client and that there is no (online) CT lookup . So i dont understand - how can the CT lookup process be insecure or privacy violating if it essentially doesn't exist. All that is happening on the browser is a signature validation - no additional network requests needed.
- forgotmypw17 3y ago> Sure, but now you have a new problem that tor hidden service identifiers are not really human identifiers. This makes attacks where you trick the user into going to the wrong site much easier. Tor promised to address v3 addresses being much less human-readable before deactivating v2, and I look forward to them doing it.
- sedatk 3y agoIt's a game of tradeoffs, and Tor is losing in the fast transfer speeds and responsiveness department. That's what a typical user cares about the most.
- 1vuio0pswjnm7 3y agoBest part is not having to pay for a domain name or hosting just to be reachable. We already pay enough just for internet access. Tor is not just for anonymity. It's also for reachability.
- Santosh83 3y agoClearnet also works for this particular use case, disregarding anonymity. And an IPv4 address is much more readable/usable than an onion one.
- PathfinderBot 3y agoI believe GP was referring to the NAT-busting abilities of onion services, as well as the ability to get domain names you control via a private key. Of course, another solution would be IPv6. If you're referring to private IPv4 addresses, I can't see how that's relevant.
- AmirJavar 3y agogreat
- cookiengineer 3y agoIn order to prevent websites from fingerprinting with network traffic recordings (of single servers and/or exit nodes), there have to be a bunch of more implementations on network-protocol level. In my opinion, TLS itself is not secure enough to preserve anonymity because of the threat actor (ISP/gov) being able to have recordings of "when and what" is being requested in which Browser Engine on their tracked websites. They tend to scrape websites and have recordings of time differences when which assets of a website is requested, and there's differences between WebKit, Chromium, Edge, Firefox etc. in regards to CSS, HTML, images etc. also in terms of TLS fingerprints and how their TCP/UDP stack behaves. I wish that Tor would have support for a couple more things that are necessary to really preserve privacy from the god's eye perspective of an ISP: - Randomization of TLS fingerprint, in the sense that the order of offered ciphers in the handshake, the TCP window size etc is randomized. - Traffic scattering (e.g. have multiple exit nodes that are selected via a ronin to request the resources from each website) - Traffic "trailing", which inserts random amount of NULL bytes at the end (with randomized encodings, e.g. chunked encoding, gzip Transfer Encoding, etc) - Offline cache for both HTTP/S, DNS and WS/WebRTC in the Browser, so that websites continue to work when they've been requested already. A lot of the Browser cache mechanics are useless because webservers are implementing stupid understandings of ETags which won't work with Tor due to them being connection-specific - Cache headers have to be modified by the Tor proxy, because they can be abused for fingerprinting. ETag and Last-Modified date headers in combination with the Pragma/Cache headers can be used to uniquely re-identify Browser clients on the other end (e.g. by using a fixed datetime in the past for each new client like 1970-01-02 03:04:05). - User-Agent headers have to be randomized and sticky to Tabs and what the website in those Tabs request, even when they're seemingly foreign domains; but even more so when those domains have a CNAME entry. In the past I implemented a lot of the mentioned concepts into the Stealth prototype [1] which aimed to solve this by offering a local Proxy which routes/modifies/cleans network traffic and can be used by a webview that points to it (no matter whether it's a mobile or desktop one); but I had to shift focus with my efforts to cyber defense because we Europeans are getting hit by a lot of "Kremlin-loving hacker groups". At some point I wanted to revisit these ideas again, but who knows what the future holds. [1] https://github.com/tholian-network/stealth https://github.com/tholian-network/stealth
- WeylandYutani 3y agoI use it to rout around censorship. They've blocked torrent sites over here luckily there's 1337.to
- jeroenhd 3y agoAnother nice thing Tor provides is free NAT busting. If you're behind two layers of NAT and want to expose a service elsewhere, you can use Tor as an alternative for ngrok and other services. It even comes with basic authentication support through public keys, so you can expose any service you want without worrying about someone else finding and accessing it. I wouldn't call Tor a secure alternative to DNS, though. First of all, DNSSEC is easy to set up on a domain or in your DNS resolver settings if you care about such things (even if the underlying protocol is kinda shit), and second of all there's no way to know if hackernewsfjsushfoufbeldufbfof.onion is the real service or if you need to go to hackernewsfkfhfofusnsodifnekdj.onion; you can bookmark one and hope it's the official source, but it's basically TOFU for domains. You could use the special onion location header to specify the real onion address, but then you're back to trusting DNS again.
- judge2020 3y agoI would like to imagine an org could get their SSL certificate issued to both news.ycombinator.com and hackernewsfjsushfoufbeldufbfof.onion (since you can get those now), and you (or your tor client) could show authenticity by showing "this site is also the authority for: news.ycombinator.com".
- jeroenhd 3y agoThat will work, but it doesn't work for your standard, cheap, DV certificates. HTTPS over Tor works and is actually done by a few domains. Again, you'll be trusting the clearweb authentication mechanisms (and Tor isn't going to submit the sites you visit for certificate transparency checks) so the advantages quickly go away.
- davidguetta 3y agoI have understood literally nothing. ELI5 ?
- mike_hock 3y agoThe acronyms are googleable and a basic exposition on how Tor works is available on the Tor website. That should get you to a point where you can at least ask for a particular clarification.
- ajsnigrutin 3y agoSadly the anonymity part (at tleast as meant a few years ago) is not true anymore... Live in a shitty country, want to tweet the truth without your government finding out and treating you like Assange? Just use tor, make a social network account and publish the truth! And the reality? Every cloudflare based site first gives you a long and hard captcha. Then you try to register an account, and again, one of thoss arkose labs[0] captchas. Then after rotating the 7th image in the right orientation, you finally get your twitter/facebook/instagram/whatever account... you try make a first tweet/..., bam, your account closed, you need to verify with a phone number. You buy a disposable prepaid sim card, risk exposing yourself, and again get banned. A bunch of services even block tor exit nodes directly by IP. Yeah, sure, you can run a hidden service, and all three users, that know how to use tor and find that address will see your writings, but reaching wide audiences is impossible. yeah, i know it's just a rant, but it's a pain still [0] https://old.reddit.com/r/ArkoseLabs/comments/o4ab5r/minecraft_account_reset_blocked_by_arkoselabs/ https://old.reddit.com/r/ArkoseLabs/comments/o4ab5r/minecraf...
- RockRobotRock 3y agogood luck using anything with recaptcha.
- 1vuio0pswjnm7 3y ago"Yeah, sure, you can run a hidden service, and all three users, that know how to use tor and find that address will see your writings, but reaching wide audiences is impossible." That's actually exactly what some folks want. To communicate privately with a small network of family/friends/colleagues. Tor does not have to be for everybody. If onion services only appeal to those people who bother to learn how to use them, then that's fine. What's important is that onion services work. The silver lining of it being impossible to reach wide, i.e., large, audiences with onion services is that this means there is no incentive for advertising and thus no incentive for so-called "tech" companies to act as eavesdropping, centralised intermediaries under the guise of providing "free services". Some folks might not want Google to snarf their content and try to profit from it in some way, or have Facebook offer them up as a highly specific demographic ad target.
- 3y ago
- nameuponthis 3y agoInteresting take. And perhaps correct from a technical and individual viewpoint. E.g. in the sense of reducing technical risk, such as reducing attack vectors (MITM, blindly trusting certificates), avoiding vulnerable protocols (DNS, TLS). However, the definition of security seems a little narrow. Security is more than just technical personal risk. And the view that TOR increases security does not sit right. Does TOR increase security for a single individual browsing the internet? Perhaps. Does TOR increase security in an enterprise system? Perhaps not. The value and need for non-repudiation might be greater than the need for individual session security. Does TOR increase security in the view of a nation? E.g. national security interests? Quite the opposite. The need for traceability might be vital, even for your individual personal security and safety (counter-terrorism and whatnot). The blog-title is great. "Tor Is Not Just for Anonymity"! The author points out that security is a wide umbrella term. I agree! To the point that the term must be defined even wider than what is presented. And true to this: I am not stating that traceability, the need for control and non-repudiation increases security one-to-one. What is "secure" is relative.
- goodpoint 3y agoIt's written "Tor", not "TOR".
- initplus 3y agoI am really becoming more and more skeptical of the security of Tor as time goes on. If it's no longer safe for buying drugs (or crypto) on the internet https://blog.torproject.org/bad-exit-relays-may-june-2020/ https://blog.torproject.org/bad-exit-relays-may-june-2020/ what makes you think it's safe for things intelligence agencies take more seriously? Tor has received significant funding from the US intelligence community through it's entire existence. If you are US aligned is Tor safe? Advocating for democracy in some war torn dictatorship? Probably. On the other hand if you are doing something that upsets US intelligence how much would you really trust Tor?
- hkt 3y agoIt makes sense that Tor would be funded at a level that allows it to defend against the intelligence gathering capabilities of most countries, but not so well funded that it can exceed the intelligence gathering capabilities of the US. However, just because something makes sense, doesn't mean it is actually true. It is incredibly difficult to determine whether or not this stuff can be effective, even with a detailed use case. At the periphery of society, there is nothing but uncertainty.
- Aerbil313 3y agoThis. The three letter agencies has every incentive to host a lot of Tor nodes to catch whom they don't like. Tor CANNOT defense against this, the protocol just can't.