8 ms·
Deploying Tor Relays
- dangerlibrary 12y agoNeat. Obviously apples and oranges, but between this and Facebook's Tor Hidden Service we're starting to see adoption of real privacy tools among major companies.
- yclept 12y ago> facebook > privacy
- dangerlibrary 12y agoI don't think that Facebook has responded to many demands for data from the Syrian/Burmese/Saudi governments. Feel free to correct me if I'm wrong.
- DonnyV 12y agoProbably not from any foreign countries but I would bet 110% that they are an open book to the US government.
- dangerlibrary 12y agoA problem that is not exclusive to Facebook. In fact, all U.S. companies are open books to U.S. Government employees wielding the right documents. My point was that a Tor Hidden Service provides anonymity to users in countries whose _links_ to Facebook's servers are policed.
- dublinben 12y agoTor also provides censorship-resistance, through bridges. It is one of the only consistent ways to access the open internet from Iran or China.
- yclept 12y agoHow about the United States / China / Russia / Great Britain?
- rmc 12y agoOh they're on the right side, so it's OK /s
- ddeck 12y agoAccording to their report, they haven't received any data requests from Saudi Arabia, Syria or Burma, but they did hand over data to the governments of 57 countries in the first half of 2014 alone [1]. It appears content was also censored at the request of the Saudi government. [1] https://govtrequests.facebook.com/ https://govtrequests.facebook.com/
- nickik 12y agoThere is a diffrence between mostly voluntaryly pushing your own data into facebook and wanting to not be detected when organising political rally.
- yclept 12y agoA great deal of the data Facebook has must be derived outside of things you have posted yourself. They build and hold a lot of data you do not explicitly consent to share. Facebook really wants your activity to be based on your real identity, and making associations between you and other people. Facebook shouldn't be used as a tool for organizing political rallies if there is concern for privacy. Connecting to FB via Tor does not isolate you from much.
- Igglyboo 12y agoI hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.
- frozenport 12y agoIts much easier to raid a big company because they have a clear physical prescence and a strong interest to focus on their core buisness. For example, some people in the company may defend their tor node, but managers will look to the interests of the company as a whole, concluding that the loss of dozens of jobs is not worth risking over something that is not a core competancy.
- AnthonyMouse 12y agoIt seems like you're arguing from a pure realpolitik perspective. The FBI is going to raid your Tor node because they know it will make your boss unhappy. Even under that assumption, what is the FBI's motivation for doing this supposed to be? They can obviously only do this for Tor nodes within their jurisdiction, but that's where they want them to be because it's easier to capture their traffic. It's not like exit node operators have any actual connection to the crimes the government may be investigating. The main thrust of the other Tor article on the front page[1] is that the primary source of criminality on Tor is hidden services that don't use exit nodes. [1] https://news.ycombinator.com/item?id=8959621 https://news.ycombinator.com/item?id=8959621
- frozenport 12y agoIndeed, but this perspective comes from the large number of people that make up an enterprise and the interwoven net of responsibility. One person can choose to fight for liberty and risk ruin, but its much harder to justify risking the other hundred people in your company.
- chisleu 12y agoIt is plenty safe to run exit nodes. If your host complains, there is even form letters to send. The government knows that seizing an exit node will not help them in anyway (one can go online immediately.) Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.
- folta 12y agoMissing an L in "Mozilla" in the title - "Mozila deploying tor relays"
- leo2urlevan 12y agoThanks, fixed.
- thecatspaw 12y agoIm not sure if mozilla should get into such a political field.
- fwn 12y agoFunny. I always thought it is only politicians who think that this field is political.
- tosseraccount 12y agoProp 8? NSA ? Patents? Can't be avoided these days.
- vertex-four 12y agoMozilla is a political organisation. Aside from the fact that developing free, privacy-focused software is an inherently political thing to do, they have the Mozilla Manifesto[0], which states (the relevant bits here being singled out): > The Internet is a global public resource that must remain open and accessible. > Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional. > We will [...] use the Mozilla assets (intellectual property such as copyrights and trademarks, infrastructure, funds, and reputation) to keep the Internet an open platform [and] promote the Mozilla Manifesto principles in public discourse and within the Internet industry. [0] https://www.mozilla.org/en-US/about/manifesto/details/ https://www.mozilla.org/en-US/about/manifesto/details/
- rmc 12y agoMozilla and free software / "the open web" has always been political.
- mbrubeck 12y agoThe Mozilla Foundation regularly leads or joins in political action relevant to its mission. For example we campaigned against SOPA/PIPA and CISPA [1], submitted a Net Neutrality proposal to the U.S. FCC [2], and have testified multiple times to the Librarian of Congress and elsewhere in favor of DMCA exemptions and DMCA reform [3]. [1]: https://blog.mozilla.org/blog/2012/01/17/mozilla-to-join-tomorrows-virtual-protests-of-pipasopa/ https://blog.mozilla.org/blog/2012/01/17/mozilla-to-join-tom... [2]: http://arstechnica.com/tech-policy/2014/05/mozilla-offers-fcc-a-net-neutrality-plan-with-a-twist/ http://arstechnica.com/tech-policy/2014/05/mozilla-offers-fc... [3]: http://www.cnet.com/news/growing-pressure-in-congress-to-fix-flaws-in-dmca-law/ http://www.cnet.com/news/growing-pressure-in-congress-to-fix...
- jstalin 12y agoCan we donate to support this specific initiative?
- dublinben 12y agoDonate to the Tor Project. They currently rely on mostly government grants for funding their important work. TorServers.net has also been mentioned already.
- droopyEyelids 12y agoThey better tell their employees not to buy any drugs or use TOR for illegal stuff, because now they'll be representing the whole TOR project and The Free Web. So it's like, they don't just represent themselves anymore, and an arrest will be a political tool to smash everything into corporate/government control.
- mbrubeck 12y agoAny government agency that wants to trash-talk Tor is already doing so, and already has plenty of ammo for the propaganda machine. They're not going to wait for some Mozilla employee to download a movie torrent, especially since that wouldn't actually change anything.
- middleclick 12y agoWhat does the word "illegal" encompass here?
- justcommenting 12y agobandwidth & other info on mozilla's relays: https://atlas.torproject.org/#search/mozilla https://atlas.torproject.org/#search/mozilla kudos to mozilla for getting involved!
- mirimir 12y agoThis is, of course, great news. However, it's my impression that there is a surplus of entry and middle nodes, and a serious shortage of exit nodes, especially fast ones. Also, I've read that the geographic diversity of exit nodes is inadequate. I base these comments on discussions on the tor-talk and tor-relays lists, and from posts on the Tor Project blog.
- sp332 12y agoWould it help if an ISP ran a couple of exit nodes plugged into core routers?
- AnthonyMouse 12y agoIt's actually better if 1000 different people each run a 40Mbps exit node than if one ISP runs a single 40Gbps one. You don't want to centralize control over the exit nodes because it increases the chance that party could control every node in a circuit.
- sp332 12y agoIf they're only running exit nodes, they're not going to control every node in a circuit.
- AnthonyMouse 12y agoIf you know which nodes they control you can easily avoid using them in the same circuit. But how are you supposed to know that? There is a configuration option to list other nodes you operate for exactly this purpose, but someone staging an attack is obviously not going to use it.
- cottonseed 12y agoThis is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)
- driverdan 12y ago> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is. To anyone who is thinking of running a relay, here are the basic steps: 1. Add the Tor repo to your package manager [1] 2. Install Tor 3. Edit the config file to set a name, your contact info, bandwidth limit, and exit policy. This is all pretty well documented in the config file. 4. Start Tor (eg `sudo service tor start`) If you want to run an exit node you should read the Tor docs about the topic and decide which ports to open.[2][3] 1: https://www.torproject.org/download/download-unix.html.en https://www.torproject.org/download/download-unix.html.en 2: https://trac.torproject.org/projects/tor/wiki//doc/TorExitGuidelines https://trac.torproject.org/projects/tor/wiki//doc/TorExitGu... 3: https://blog.torproject.org/blog/tips-running-exit-node-minimal-harassment https://blog.torproject.org/blog/tips-running-exit-node-mini...
- blacksmith_tb 12y agoI see also that there are some tor relay Docker containers out there, e.g. https://github.com/vpetersson/docker-torrelay https://github.com/vpetersson/docker-torrelay I also quite like Tor Arm if you are running a relay, for an nice eye-candy dashboard: https://www.torproject.org/projects/arm.html.en https://www.torproject.org/projects/arm.html.en
- mirimir 12y agoIt's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.
- ecaron 12y ago> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2Xeon L5640, 21Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...
- Implicated 12y agoSilicon Valley problems
- gcb0 12y agoi think in most countries the pipe is always more expensive than the server
- IgorPartola 12y agoWell, if they were in any way savvy (which I believe they are), they would sell a machine like that or donate it to another project. In this instance, I imagine, instead of selling/donating they repurposed.
- evilpie 12y agoFor instance a while back Mozilla was giving away old Mac minis: http://armenzg.blogspot.de/2014/05/do-you-need-used-mac-mini-for-your.html http://armenzg.blogspot.de/2014/05/do-you-need-used-mac-mini...
- dublinben 12y agoThat's a five year old server. That's worthlessly depreciated in just about any organization.
- DanBC 12y agoAre there tax advantages of donating old equipment to certain good causes? It seems easier than the alternative of selling the hardware on ebay.
- ascorbic 12y ago
- politician 12y agoThis reads like a progress report from a temporary experiment rather than an announcement of a supported capability. I wouldn't get too excited.
- ryanthejuggler 12y agoIs Tor broken? I've heard that its anonymity was proven to be broken, but I'm not sure how reliable my source was. I'm interested in getting involved but hesitant to do so until I have some solid info one way or the other.
- d23 12y agoThere's something like 2k-8k exit nodes, and all that is needed to compromise it is 51% of those. Given that the CIA started tor and the government has significant interest in breaking it, I would find it harder to believe that they didn't have a few thousand computers lying around. Also all of this is from memory, but I hope none of it is wrong. Feel free to correct me if so.