HN user

RonMarken

27 karma
    pub   rsa4096/0xA6D8C811594901DD 2024-04-11 [SC] [expires: 2025-04-11]
          A85566159EA0890DC4A34074A6D8C811594901DD
    uid                              Ron Marken <RonaldMarken@protonmail.com>
    sub   rsa4096/0x0DD06D9873F3FA98 2024-04-11 [E] [expires: 2025-04-11]
Posts0
Comments23
View on HN
No posts found.
Tor Browser 12.0 4 years ago

While supporting funding more nodes is a noble goal another concern I consider overlooked is the potential 'centralisation' of nodes e.g how a large number of Tor nodes are hosted in Germany and near countries and the implications for network surveillance.

As a related topic the NY Times .onion site likes to refuse loading articles thinking a normal visitor with Tor Browser is a robot.

If anyone has any contact with the NYTimes ops' team perhaps this issue could be raised with them.

Satoshi must be an expert in hiding.

There are allegations that Satoshi may have accidentally slipped up and leaked IP address that was not a Tor exit-node or other anonymous-proxy.

Could either be Satoshi fucking up and not using Tor all the time (has happened to other 'anonymous' entities) or perhaps they needed a clearnet connection for some reason and managed to use another internet connection not attached to any identifiers that would lead back to them despite that.

Perhaps Twitter needs to make it easier to create accounts anonymously and stop virtue signaling (i.e suspend accounts created over Tor onion-service)

With pseudonymous usage of public services information minimisation to maintain operational-security against private user-data being disclosed by external hackers or rogue insiders is a mantra that needs to be followed religiously.

Conclusion. Some random person created a bunch of Tor exit nodes doing some internal routing fuckery for :80 traffic. Anyone should assume their plain-text traffic is fine-pickings when over Tor (and probably any of the VPN providers anyway)

(If you are more concerned about traffic correlation perhaps be more careful where you are entering the Tor network)

Realistically you cannot win against a resourceful adversary every time. But merely painting the situation through the lens of premature surrender is also a disservice.

It will be interesting to see what third-party researchers discover about these new protections. Might remember something about Apple rewriting format parsers for iMessage in memory-safe language with sandboxing as Blastdoor and it was discovered there was still plenty of attack-surface in the unprotected parsers.

One cannot remain private or anonymous from a state-level adversary indefinitely but throwing your hands up and dismissing it as impossible is also a fallacy. Details are sporadic for easy reasons but quite a few whistle-blowers and other controversial figures have managed to keep themselves anonymous and disappear in a controlled-exit without any obvious retribution. Probably the best case outcome.

No comment on the prospect of owning a company anonymously or publishing apps through Apple but in certain communities it is accustomed to be anonymous, particularly in those which knowledge of real-life identities could be used to gain items of value.

One omen of advice is that if you are not taking measures preemptively to actively remain anonymous that itself could be a means of exposure and makes this entire exercise futile. For longer-term anonymous identities merely picking a pseudonym and casually using it makes it easy to slip-up and potentially lead to correlation. Slightly dated now but suggest you read-up on 'OPSEC for hackers' and other publications by The Grugq as a starting point.

This appears to be good however recent events showing the deconstruction of prior precedents and other policies not directly implemented by laws raise a tangible concern.

It would not be surprising if some bored prosecutor with a grudge attempts to throw this out the window. In addition litigation by private-companies using the same laws could attempt to win by the virtue of having better funding and/or lawyers than the defendant.

Too cynical? Maybe.

it doesn't help that the current owner of freenode is notoriously litigious.

Yawn. All I have seen is some angry techbro who can dish out an hour of time for an attorney to write angry letter when he does not have things his way. That is not to say this is a criticism of victims but rather a damn shame more people do not stand up to this nonsense.

Incidentally this 'notoriously litigious' individual is also being sued over alleged sexual-harassment committed by him at his previous company London Trust Media[1]. However not sure of the latest status given the sale(s) of certain companies.

[1] http://web.archive.org/web/corrupt.tech/1708590130-ocr-compr...

America seems to have a blase culture about actually preventing these mass-shootings after they occur outside of virtue-signaling (see the popular Onion trope "No Way to Prevent This") but at the same time one could have the concern of certain entities unfairly targeting certain otherwise benign platforms that may have been used by individuals encouraging certain criminal acts with liability thus leading to concerns like the stripping of Section 230 publisher protections and the resulting chilling effects on free-speech.

Not everyone needs to be a 10x engineer that does everything all the time. It is good to take a step back and realise what you want to do.

In a technical sense one skill that can help realise these 'big daunting ideas' is to break the goals of a project into many 'micro-projects' that may seem more attainable in the short-term (ie. "I want to write some client/server application to do $X". Start by sketching out what APIs need to coexist in both sides, mock-up the business logic on paper, etcetera).