HN user

swapfile

76 karma
Posts2
Comments28
View on HN

Tor itself is full of scams and dark markets selling who knows what.

Did you forget to read the article? They make the point that this is not the case. Tor Browser can be used to access most of the web besides aggressively anti-privacy platforms like Meta.

If you choose to go on a "Dark Web Search Engine" and that's what you find, that's entirely your decision and not something you would stumble upon.

but normal people aren't going to put up with that. Nobody wants to see that stuff.

They would never see that stuff by accident, as they never do right now.

I use Tor for everything that doesn't require identification, and I use very few of those services. For example, this HN account and the email for it have never been used without connecting through Tor. Feel free to ask me anything.

There are sites that I have been unable to get working

This happens, most of the time because of Cloudflare. A solution is to get a new Tor circuit 3-5 times, and then the page will load. If a site simply won't work, like Meta platforms I won't use them. Using alternative front-ends[1] makes most sites that usually wouldn't work, work as well.

The Tor browser does help here, by not easily allowing obvious mistakes like using http.

This is false, HTTPS only is enabled by default in Tor Browser. It's common knowledge for everyone including users of Google Chrome and Firefox to not use HTTP sites.

[1] https://github.com/mendel5/alternative-front-ends

Whonix builds on much stronger concepts than Tails, as malware with root privileges cannot discover the users real IP address since it simply is not aware of it. It uses an internal VLAN to connect to Tor on a separate virtual machine. This design has proven to be far less vulnerable to leaks, with a track record of 10+ years.[1] However it is not a live system, and you have to trust the host operating system that you run it on as opposed to Tails where you boot into a secure environment where ever, as long as you trust the hardware.

Whonix consists of two VMs: the Whonix-Gateway and the Whonix-Workstation. The former runs Tor processes and acts as a gateway, while the latter runs user applications on a completely isolated network.

only connections through Tor are permitted.

DNS leaks are impossible.

Malware with root privileges cannot discover the user's real IP address.

See also technical introduction: https://whonix.org/wiki/Dev/Technical_Introduction

[1] https://whonix.org/wiki/Whonix_against_Real_Attacks

Whonix: A High Security Method of Surfing the Internet

Whonix is a desktop operating system designed for advanced security and privacy. Whonix mitigates the threat of common attack vectors while maintaining usability. Online anonymity is realized via fail-safe, automatic, and desktop-wide use of the Tor network. A heavily reconfigured Debian base is run inside multiple virtual machines, providing a substantial layer of protection from malware and IP address leaks. Commonly used applications are pre-installed and safely pre-configured for immediate use. The user is not jeopardized by installing additional applications or personalizing the desktop. Whonix is under active development and is the only operating system designed to be run inside a VM and paired with Tor.

and submitted to 4chan via Tor or a VPN.

4chan blocks both Tor and VPNs. It's a terrible place to leak things, but a hacker can most probably find innocuous IPs.

If you think your traffic is not being monitored over Tor, then you have thought incorrectly.

Tor exit nodes can only monitor traffic for a very short period of time, you create a new circuit and pick an entirely new path through the network very often.

This does not happen by default, meaning all of your traffic is mixed together. It doesn't matter that it migrates routes every so often.

Absolutely true, a solution to this is to use Whonix or Tails which automatically stream isolates all pre-installed programs, therefore correlation by circuit sharing is impossible. Unfortunately that does not work on a phone, but in the end, using Tor for this is no worse than a VPN.

Exit nodes don't know where the traffic is coming from, until, of course, you accidentally access your personal domain name over HTTPS

This seems like a straw man. There's not many options to Tor. A VPN will know where you're coming from by default.

Otherwise even if we (HN audience) switch

This is a problem. Even the HN audience seems to struggle greatly in choosing non-proprietary and privacy friendly solutions. While the amount of privacy advocates are certainly greater here than in many other places, the general sentiment I get from reading a lot of these threads is that "If you have nothing to fear, you have nothing to hide".

Why do you think that is? Certainly a community like this shouldn't be bothered by the slight obstacles you would be challenged with.

It probably goes along the lines of:

"It is impossible to download and examine iOS's source code, which means that it is impossible to prove that iOS is not spyware. Any program which does not make its source code available is potential spyware."

Which I agree with. I'm not going to trust and put as much personal data as a smartphone usually contains into a proprietary black box.

WTF is a KDF? 3 years ago

This is why you let a computer choose. By doing that you end up forcing the attacker to brute force, which we all know is mathematically unfeasible given enough entropy.

Chainalysis says little publicly about the techniques it uses to combat technologies like Monero

Very disappointing. The entire world's population of cryptographers vs the power of an $8.6 billion company, who comes out on top?