6 ms·
Oniux: Kernel-level Tor isolation for any Linux app
- ericfrederich 1y agoThey use hexchat as an example but do these processes run with the users configuration? Wouldn't this leak IRC usernames if you forget to change it. ... Or leak cookies if you launch a browser?
- charcircuit 1y agoWhat do you mean by leak usernames? It would leaks that a username uses tor. It would still leak that all of the usernames connecting to the same IRC host would be the same person. IRC seems pretty dangerous if you want to remaining anonymous considering how many people are logging disconnection times allowing them to be correlated with other network disruption events.
- 01HNNWZ0MV43FF 1y agoIrssi iirc used to default your username to your system username, so noobs would leak their given name by accident. After seeing that I changed my username in Linux to always be the most common username
- SV_BubbleTime 1y agoWhat is the most common Linux username though? Obviously you don’t want to do your regular work as root. And guest has its own issues. Is there a “common name”?
- tbrownaw 1y agoNot sure about "most common", but I have some vms that use `user` as the username.
- Xevion 1y agoadmin
- romnon 1y agoubuntu
- Fnoord 1y agoroot
- user32489318 1y agoRobert'); DROP TABLE Students;-- Roberts
- PaulDavisThe1st 1y agoroot?
- ericfrederich 1y agoI was talking more about you using HexChat with your preferred username "FooBar", but then when on Tor you want to be "SpamEggs". If you launch HexChat through oniux and it reads your config file, you might hit the login button before changing your name from FooBar to SpamEggs.
- 47282847 1y agoTor is anonymizing you primarily from the network. There are many use cases where you do want to be authenticated/known to whoever you are talking to. You just want observers to not know. In your example of correlation of connection times, it may not be your goal to remain anonymous from the network and its participants, you may be interested in the location-hiding properties, and/or adversarial networks (like local government or corporate networks) and firewalls.
- alfiedotwtf 1y agoSeparation of concerns - although Tor goes to great lengths to prevent fingerprinting, Tor and Oniux’s main aim IMHO is to make the source IP untraceable. Same thing could have been said about using Tor to login to Gmail (if it were not HTTPS).
- alfiedotwtf 1y agoThe DevEx is beautifully done here i.e it’s idiot-proof! Nice work to the people behind this <3
- brians 1y agoIt’s really, really not. Idiots are ingenious. The operational care to use this in ways that preserve anonymity is beyond most users.
- ahmedfromtunis 1y agoDoes this mean one can now access tor websites using chrome?
- _k2vp 1y agoYou always could by just setting the proxy environment variables (or in settings). The standard port for the tor daemon is 9050. In fact, it's relatively easy to write a socks proxy that lets you route traffic through a arbitrary protocols. For example, I can serve/visit websites on syncthing with a socks5 proxy as a translation layer: https://github.com/acheong08/syndicate https://github.com/acheong08/syndicate
- stepupmakeup 1y agoChrome has zero user-facing proxy controls of its own on Windows, nor PAC support. But the --proxy-server command line argument works.
- kyguy23 1y agoYou can, but please don’t do this, you’ll stick out even more! Tor browser has a series of anti fingerprinting strategies that chrome doesn’t
- OsrsNeedsf2P 1y agoDoes Brave attempt to mimic any of these anti fingerprinting strategies? Asking because it has a "Private tab with Tor" feature
- fatchan 1y agoNo. First of all, just check for `navigator.brave`. If it exists, it's Brave. When I ran a .onion site I added a JavaScript check and if navigator.brave was present, it redirected users to a specific page saying: > Hey, there's something funny about your Tor Browser. When browsing Tor hidden services (.onion), you should be using Tor Browser. Are you using an outdated version, or perhaps something else entirely? Brave is chrome. Tor browser is firefox, has a bunch of tweaks, different default settings, and a different fingerprint. Also when browsing on Tor, you should disable JavaScript as it's a source of many vulnerabilities.
- mjg59 1y agoHuh. I had a conversation with a Tor developer on this topic about a decade ago, when network namespaces were still kind of a new hotness - the feedback I got was that it would be an easy way for people to think they were being secure while still leaking a bunch of identifiable information, so I didn't push that any further.
- computerfriend 1y agoStrange, because torsock and torify do the same thing, but less robustly.
- gobip 1y agoWhen you have torsocks or torify for everything, you're gonna leave your footprint through tor, whereas something like Tor Browser is designed specifically not to leave any print on the web. Using tor directly on the kernel level means that your DNS is gonna leak. Your OS telemetry is gonna leak etc. It's still a good idea but it should be implemented top to bottom and nothing left in between, otherwise you're de-anonymized quickly.
- ajb 1y agoI think the tor folks made a fundamental strategic error by pushing that line. Yes, people who face a serious threat need to use tor browser and still pay attention to other ways to leak etc. But if we'd got 'tor everywhere' it would still make mass surveillance a lot harder. For one thing, today mass surveillance can detect who is using tor. If everyone was using it that wouldn't matter.
- natmaka 1y agoIsn't all this reserved to TCP, in other words in which way may it protect non-TCP activity?
- charcircuit 1y agoNon-TCP activity wouldn't route and will fail to send.
- izhak 1y agoUDP wouldn't route?..
- charcircuit 1y agoYes.
- c0balt 1y agoThe TOR protocol does not natively support UDP, though there are workarounds[0] [0]: https://www.whonix.org/wiki/Tunnel_UDP_over_Tor https://www.whonix.org/wiki/Tunnel_UDP_over_Tor
- natmaka 1y agoThank you, therefore my first impression seems right: without any provision for UDP this isn't an easy-to-setup and transparent way for any user to preserve his/her privacy.
- HappMacDonald 1y agoAs always this will depend on your definition for "any user". Users who try to do a lot of UDP traffic will have to change their habits, yes. But a majority of users who don't know a lot about computers rarely do anything on a PC that isn't driven by the browser anyway. But at least the users who try to use UDP won't wind up specifically leaking info, just wind up slightly confused why certain things aren't working.
- 1y ago
- tobias2014 1y agoOniux seems like an "officially" supported tool similar to orjail (which hasn't received a commit in four years, but still works great as a shell script with iptables/iproute tools [1]). Orjail has also an option to run with firejail for further isolation, which seems to be still a feature that Oniux doesn't have. [1] https://github.com/orjail/orjail/blob/master/usr/sbin/orjail https://github.com/orjail/orjail/blob/master/usr/sbin/orjail
- 1vuio0pswjnm7 1y agoNo Javascript URL: https://raw.githubusercontent.com/orjail/orjail/master/usr/sbin/orjail https://raw.githubusercontent.com/orjail/orjail/master/usr/s...
- hexo 1y agoNice, now please rewrite the prototype in C and will happily use it.
- jsiepkes 1y agoIt's written in Rust. What would you need a C version for?
- matt3210 1y agoSo I can read it to make sure it's not doing bad things.
- saagarjha 1y agoConsider learning Rust.
- glowiefedposter 1y ago[flagged]
- jsiepkes 1y ago"make sure it's not doing bad things" is never going to happen. Just look at the XZ attack (which is written in C) or the "The International Obfuscated C Code Contest" [1]. Also you might want to read "Reflections on Trusting Trust" [2]. [1] https://www.ioccc.org/ https://www.ioccc.org/ [2] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
- mike-cardwell 1y agoInstructions on front page for install don't work. Need to change the version number from 0.4.0 to 0.5.0 cargo install --git https://gitlab.torproject.org/tpo/core/oniux oniux@0.5.0
- mike-cardwell 1y agoHmm. I assumed this worked like torsocks in that it would direct traffic through the locally running tor daemon. However, I've noticed that if I stop the locally running tor daemon, oniux still works whilst torify and torsocks do not. [edit] The documentation does actually say this. Pretty neat. It works inside docker as well, but I needed to use --privileged. Just copied the binary into a debian:12 container and it works there: docker run -it --rm --privileged -v "$PWD/oniux:/usr/bin/oniux" debian:12
- yencabulator 1y agoI would assume this uses the Rust rewrite as a library, not the older C daemon. https://tpo.pages.torproject.net/core/arti/ https://tpo.pages.torproject.net/core/arti/
- Aissen 1y agoFun fact, this has been broken with curl for 5 years (and so are the blog examples), because Tor developers previously insisted that apps shouldn't attempt to resolve .onion domain names: https://daniel.haxx.se/blog/2025/05/16/leeks-and-leaks/ https://daniel.haxx.se/blog/2025/05/16/leeks-and-leaks/ I hope they can find a resolution.