3 ms·
On iOS, Tor used to recommend using the Onion browser (they probably still do, I haven't checked). Some time ago, the onion browser changed how it connects to t
by dilippkumar 3y ago
On iOS, Tor used to recommend using the Onion browser (they probably still do, I haven't checked). Some time ago, the onion browser changed how it connects to the Tor network to use Orbot instead of connecting directly.
I can not help but see this as a malicious change.
Orbot directs all traffic from my phone through the Tor network. If an iPhone is secretly pinging some backend server for telemetry / looking for automatic updates / etc, then all those pings will now happen from the Tor exit node, effectively completely deanonymizing the user.
It's a trivial matter for an adversarial agent to ask apple for lists of all hits from a specifc tor exit node and identifying information from that user, and cross check that against whatever traffic they are trying to deanonymize.
I might be misinformed here, but I would love to be corrected about why anyone should trust Tor enough to access it from an iPhone anymore.
- zolbrek 3y agoIf you're the kind of guy who worries about the kind of entities who can ask Apple for information and get it, you probably should not be using an iPhone to begin with.
- noman-land 3y agoI hate this response. Not wanting your belongings to leak private information about you is not a desire only elite global hackers have. It should be the norm, especially when law enforcement routinely abuses their authority, double especially when the third party doctrine lets them get the data without a warrant, and triple especially in the age of global mass surveillance.
- zolbrek 3y agoIt should be the norm, but it is what it is. I hate to have to give a response like this.
- aaomidi 3y agoTBH your response ignored the actual inquiry. And the actual inquiry annoying assumed malice instead of doing a few minutes of research of why this change was made.
- ajvs 3y agoThis is all true, but then if that's your desire then why are you using an iPhone? The only reason this is an issue is because you can't control what random data an iPhone might send out.
- aaomidi 3y agoThis is a legitimate concern because this has actually nothing to do with Apple itself. Any app updating in the background can be impacted by this. Unfortunately, this is due to API limitations.
- notjoemama 3y agoAnd you know the criteria used for data requests? Do you know whether by virtue of a piece of metadata whether I (an innocent) would be included in a data request? If you can’t protect non-Tor users from wrongful classification by the government, then you dang well better protect the privacy of everyone, whether you like it or not.
- aaomidi 3y agoFYI: This change happened because iOS API changes did not leave another choice. The new non-deprecated iOS APIs does not allow per-webview proxying/vpning. https://github.com/OnionBrowser/OnionBrowser/issues/47 https://github.com/OnionBrowser/OnionBrowser/issues/47 Also, you can disable Orbot for non onion traffic, or enable it for all traffic. Either way, not a good situation on iOS world at all.
- chatmasta 3y agobtw, note that certain Apple services (like App Store and OS telemetry) bypass any VPN that's enabled on the iPhone.
- rfoo 3y ago> If an iPhone is secretly pinging some backend server for telemetry / looking for automatic updates / etc, then all those pings will now happen from the Tor exit node, effectively completely deanonymizing the user. Tor picks different exit nodes for different destination servers.