4 ms·
If one uses Tor, the article states that the person will not be treated as a United States person unless "proven" otherwise. If that's the case, all the traffic
by pavanred 13y ago
If one uses Tor, the article states that the person will not be treated as a United States person unless "proven" otherwise. If that's the case, all the traffic from a Tor exit node will be considered as traffic from non U.S. persons and all data will be stored. Doesn't make sense to me because if you are using Tor right, then requests cannot be traced back to you. How does that help?
- bigiain 13y agoIt depends on what you mean by "using TOR right" - and that depends on who/where you are and what you're trying to protect yourself against. A Chinese/Egyptian/Turkish dissident might consider it perfectly sensible to use TOR to access their gmail account - that's a perfectly valid way of hiding from your local (non-US) government and spy agencies.
- pavanred 13y agoWhat I mean by using Tor right, for instance, is avoiding use of certain browser plugins that can potentially give away your location.
- bigiain 13y agoYeah - fair enough. On oft-hear piece of advice is to never use an identity you ever use elsewhere over TOR - for me, as a "non US person", even if I can trust TOR and TLS/SSL to ensure the privacy of my data in transit, it doesn't matter if the far end of my connection through TOR ends up at my gmail/apple/facebook/linkedin/twitter/dropbox/yahoo/amazon/any-other-US-affiliated-corporation. Being "non US" and located outside the US means the bar for any "legal requests" those companies receive is _very_ low. (Hmmm, I wonder if proxying all my web traffic through a vpn with a definitely-in-the-US endpoint might be a worthwhile bit of civil protest? I wonder if tcp connections originating from my Digital Ocean vps in New York and heading to US datacenters have slightly better legal protection or "presumtion of domestic provenance" than tcp connections originating here in Australia? Maybe I should be doing this anyway for all the analytics/ad-tracking web-bugs...)
- jlgaddis 13y agoIf they can see the bits coming out of your VPS in NYC and heading to other data centers, surely they can see the bits coming from .au into your VPS and correlate them?
- trothamel 13y agoI'd assume there's some chance that the person will screw up - even a little. The NSA is very good at exploiting very small mistakes. In the Venona project, http://en.wikipedia.org/wiki/Venona http://en.wikipedia.org/wiki/Venona, they NSA realized that the soviets were re-using one time pads. By knowing A xor C and B xor C, they were able to get A xor B - and from that, they were able to decode the messages. I could imagine things like looking at the tor traffic, and trying to match up things like writing patterns. And of course, there's the very good chance some people aren't using tor right. I don't think that what the NSA is doing is legal - but think there's a good chance it's somewhat effective.