5 ms·
As knowledgeable users of the Internet in 2024, we would do well to assume that nothing is 100% “safe” (I.e. there’s no such thing as perfect security/privacy).
by flufluflufluffy 2y ago
As knowledgeable users of the Internet in 2024, we would do well to assume that nothing is 100% “safe” (I.e. there’s no such thing as perfect security/privacy).
However, some things, like Tor, can make your use of the Internet safer.
If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.
- deleted 2y ago[deleted]
- toby- 2y agoAgreed – you can never truly be completely "safe", but Tor remains the most privacy-preserving tool we've got. When people say they're distrustful of Tor (for various reasons) to the extent they refuse to use it, they seldom suggest alternative tools/measures that provide anywhere near the level of safety offered by Tor.
- dev1ycan 2y agoThe argument is that using "privacy" tools makes it easier for a party to single you out, and they do have a point.
- AnthonyMouse 2y agoThey have the opposite of a point. The logical conclusion of that line of reasoning is that everyone should use privacy tools so no one can be singled out. And that ordinary users with "nothing to hide" should be the first to start using them.
- horsawlarway 2y agoI mean, sure. And while we're at it pigs should fly. Functional security means understanding your risks, and using privacy tools is a risk - in the sense that it does single you out in the current environment. Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough. Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.
- AnthonyMouse 2y ago> I mean, sure. And while we're at it pigs should fly. Pigs have significantly higher density than birds and lack wings. Getting them to fly under their own power would be quite a challenge. By contrast, installing Tor Browser is actually pretty easy. > Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough. In general this is not what happens in e.g. the United States. The act of installing or using Tor doesn't in and of itself cause anyone to beat you with a wrench. Try it. Visit HN using Tor Browser. No one comes in the night to put a bag over your head. > Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in. If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage. If you live in a country that has a modicum of respect for fundamental rights like privacy and due process, then you can use Tor when you're not breaking any laws and are just trying to avoid being tracked across the internet by Google and Facebook, because using Tor isn't in itself illegal. And doing this not only benefits you, it benefits the people in the first group who need it even more than you do, because it makes them stand out less. So who are the people who shouldn't be using it?
- roofoos 2y ago> Visit HN using Tor Browser. No one comes in the night to put a bag over your head. HN used to often not create new user accounts when connecting from Tor. Twitter doesn't let a new user account to pass the prove you're human AI challenge. It says it passes but then shows an error message that there was a technical issue. By using Tor I'm cut off from Twitter. Twitter is my social media of choice. By using Tor I'm cut off from social media.
- TylerE 2y agoWhy should ordinary users do something that provides no meaningful benefit and makes their experience substantially worse?
- belorn 2y agoAnyone who search for medical information online should always use a VPN and a browser that cleans itself before and afterward. Health status is one of the most valuable user data available to data brokers and is heavily collected and sought after. I also use tor in my work in order to get a third-party perspective on a website, or when inspecting suspicious links.
- friendzis 2y agoBut that's half the point. If someone has an intention to undergo some illegal activities with full intention not to be caught, only 100% "safe" solution works for them. Normally we talk about risk tolerance, but this particular use case is a bit special.
- GunlogAlm 2y agoThere are no "100% safe" solutions. There will always be weaknesses and vulnerabilities in any system. The sort of criminal who requires or expects 100% safety is quickly going to be caught due to being a dullard. Knowing you're never truly "safe" is what good criminals are keenly aware of at all times: you can plan and prepare for certain eventualities. Once you think you're "safe", it's the beginning of the end.
- red-iron-pine 2y agoSecurity is a process, not a "state". You don't do something, once, and then are good to go forever. Banks don't just put cash in a safe and forget about it; they have audits, security guards, cameras, threat intelligence profiling criminal gangs, etc.
- deleted 2y ago[deleted]
- ziddoap 2y agoThe entire conversation has to be about risk tolerance, because that's all there is. There never has been, and never will be, a 100% safe solution.
- mtlmtlmtlmtl 2y agoAs someone who's actually used Tor for illegal activities(buying drugs) this is completely missing the point. Criminals generally are not thinking about doing something completely risk free. The dumb ones don't consider risk at all, because they're desperate/addicted, and just hope/assume they won't get caught. More clever ones assume they'll be caught and try to make conviction less likely. For instance, for buying drugs, the ordering isn't the risky bit. Receiving it in the mail is. Even if tor was magically "100% safe" the crime overall wouldn't be. The point of using tor is not to eliminate all risk, it's just to decouple payment from reception. I had my drugs intercepted by customs once, but they couldn't prove I ordered them, so they dropped the case. I'm sure it might've been possible for them to prove it if they spent a lot of resources trying to trace crypto transfers and so on, but police only do that if the fish is big enough because they're resource constrained. Tor is just another tool criminals can use to reduce risk. It's not perfect, but for most things it's the best thing available.
- jandrese 2y agoI wish the people back in the 90s understood this when trying to set up encrypted email.
- takeda 2y agoAs someone who used Internet in the 90s I don't follow. There was almost nothing encrypted. SSL/TLS was introduced for POP3/IMAP, but I don't think that was bad.
- jboy55 2y agoI remember reading on here years ago that people were concerned that the government was reading their "private" emails. I've always just considered email to be sent in plain text. Just 10 years ago only 30% of emails from Gmail were encrypted. Even though now its 99% of outgoing email is encrypted, but all those emails sent before are probably sitting in a database somewhere. And it still reverts to unencrypted if the recipient doesn't support TLS.
- jandrese 2y agoThe 90s had the opportunity to deploy something like PGP widely, but because there was no perfectly safe way to distribute the keys it never went anywhere. The most practical solution the crypto nerds could accept was the web of trust, where you were supposed to physically meet everyone you wanted to communicate with so you could physically exchange the keys, which was never going to scale. Email to this day is unencrypted at rest and completely transparent to whomever is running your mail server. You don't think Google runs GMail out of the goodness of their heart do you?
- takeda 2y agoThere is S/MIME, but probably biggest thing that stopped its adoption was popularity of web mail (so yes, Google and others).
- kreims 2y agoWell, for the sake of clarity I would say Tor is safer only if it’s not a honey trap. That is not knowable as a user, but I think that suspicion is well-deserved. I think the Middle East gave us a very clear example of how state actors may target channels in unexpected ways.
- glenstein 2y ago>If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all. Exactly, and this same form of spurious argument came up in an hn post yesterday about cavity prevention, centering on an argument that a new advance in cavity treatment "cannot guarantee" to end cavities forever. [0] I feel as though I've never been fooled by these arguments, although surely I have different types of weaknesses that are unique to me. But it seems to stand out as a form of argument that somehow has persuasive power among intelligent types whom I would never expect to fall for other forms of obviously fallacious arguments. 0. https://news.ycombinator.com/item?id=41573550 https://news.ycombinator.com/item?id=41573550
- halJordan 2y agoThis misses the point, the user in question was fully deanonymized. This blog post is saying that those successful techniques are no longer usable. It's entirely appropriate to pursue a defense in depth strategy while questioning any particular layer.