The Tor Blog - Comments https://blog.torproject.org Comments en "4. Things I'd like to see https://blog.torproject.org/blog/technical-summary-usenix-fingerprinting-paper#comment-100759 <p>In reply to <a href="https://blog.torproject.org/blog/technical-summary-usenix-fingerprinting-paper">A technical summary of the Usenix fingerprinting paper</a>:</p> <p>"4. Things I'd like to see in Tails include utilities such as steghide, ..., twofish, and some other encryption utilities as a back-up if AES is broken tomorrow."</p> <p>XKEYSCORE has steganography detection and it would be very interesting to read how .Maybe like the silly special dschihad crypto tools.... .<br /> Twofish is integrated in gpg. A modern, more sophisticated crypto algoritm like THREEFISH or better would be.... very nice. If Virgina would allowing that.</p> Tue, 11 Aug 2015 11:12:36 +0000 Anonymous comment 100759 at https://blog.torproject.org It is written clearly , https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100702 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>It is written clearly , anonymity &amp; security are not a tor concept and has been applied on gaming lan &amp; private chat _as secure service &amp; anonymous service_since a long time (support is great) .<br /> Tor is not an opening toward a new frontier.</p> Tue, 11 Aug 2015 02:41:24 +0000 Anonymous comment 100702 at https://blog.torproject.org well, i was not speaking https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100681 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>well, i was not speaking about tor and i replied about the precedent post which the terms were confusing : anonymity &amp; security ...<br /> I said that another solutions well known existed ; e.g. Lan &amp; Private chat.<br /> you are in security because no one else can interfere in your Lan &amp; in the Chat ; it is protected (strict rules) .<br /> Your choice is respected ; you choose your correspondent.<br /> You are in anonymity because no one wish to meet you in the real life.<br /> And you can say all that you want whom you wish and share that you want.<br /> The mode is clearly "without none responsibility, fun, personalized" . </p> <p>But tor open a door where every body must be involved , concerned (... without rules ... ? almost together walking in the same way ... ?).<br /> Is it this responsibility the worst of tor , the hidden evidence where a lot of users must be present for the benefit of happy few ?<br /> Will hidden service not be the future of tor ?<br /> Do i need as user a special morality fingerprint approved from who ?<br /> Do i need as user a special immorality fingerprint approved from who ?</p> <p>I still not understand the reason why so many people are so afraid about hidden service , bad rumors, reputation , misinformation or negative connotations, etc.</p> <p>I am happy you wrote this " they are mutual and not independent. Tor by it's very nature seeks to achieve both anonymity and security " and that " The words anonymous and secure are qualifiers that denote the nature of the protocol not a representation of the services provided." even if most of people had yet understood that since a long time.</p> Tue, 11 Aug 2015 00:21:52 +0000 Anonymous comment 100681 at https://blog.torproject.org "Otherwise, packages should https://blog.torproject.org/blog/tor-02610-released#comment-100669 <p>In reply to <a href="https://blog.torproject.org/blog/tor-02610-released">Tor 0.2.6.10 is released</a>:</p> <p>"Otherwise, packages should be available reasonably soon.". What is reasonable? Couple of months?</p> Mon, 10 Aug 2015 21:53:42 +0000 Anonymous comment 100669 at https://blog.torproject.org I understand but as I said https://blog.torproject.org/blog/tor-browser-50a4-released#comment-100665 <p>In reply to <a href="https://blog.torproject.org/blog/tor-browser-50a4-released">Tor Browser 5.0a4 is released</a>:</p> <p>I understand but as I said in my first comment I make this choice deliberately for convenience instead of security because I use it as my main browser. I only use it to sync bookmarks and plugins between Torbrowsers. Sync is supposed to be end-to-end encrypted and I trust the Mozilla developers that they can deliver on this.<br /> This is also why the Tor developers themselves still haven't the sync code, see [Review and audit sync](https://trac.torproject.org/projects/tor/ticket/10368) and https://trac.torproject.org/projects/tor/ticket/7188.</p> Mon, 10 Aug 2015 20:30:01 +0000 Anonymous comment 100665 at https://blog.torproject.org I'm unsure of what is meant https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100657 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>I'm unsure of what is meant by all of this as most of what you said was not written clearly.</p> <p>As for 1, LAN is a poor example. The anonymity is achieved by the locality, but all those involved are clearly not anonymous. Security can also be more easily undermined by local peers with malicious intent. First example == doesn't seem to work.</p> <p>For number 2, I can almost see a clear argument forming based on what follows it. </p> <p>When the two terms are applied to current Tor hidden services they are mutual and not independent. Tor by it's very nature seeks to achieve both anonymity and security. The words anonymous and secure are qualifiers that denote the nature of the protocol not a representation of the services provided. Upcoming protocols aim to provide security independently of anonymity. Having clear labels that are easily interpreted without negative connotations is IMHO the goal. </p> <p>Tor is proudly open source and not proprietary. Trust isn't needed and therefore not a requirement for the aforementioned qualities to be achieved (only it's proper use). </p> <p>Contextualizing is indeed necessary. Tor doesn't just pop into peoples mind with all of it's relevant information. It is instead discovered by various means and like all tools, prospective users must learn of it's capabilities and use cases. Without that, mass adoption would likely not rapidly occur, op sec errors would be far more prevalent, and a larger number of people would assume only the worst of Tor and it's hidden services capabilities. Contextualizing also helps the casual thinker and quells misinformation. </p> Mon, 10 Aug 2015 19:55:17 +0000 Anonymous comment 100657 at https://blog.torproject.org that is a clear & neat https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100651 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>that is a clear &amp; neat explanation : thx.<br /> ;)</p> Mon, 10 Aug 2015 19:09:52 +0000 Anonymous comment 100651 at https://blog.torproject.org It's all because onion URLs https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100632 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>It's all because onion URLs (like duskgytldkxiuqc6.onion) are <i>self-authenticating</i>.</p> <p>That's because this weird <i>duskgytldkxiuqc6</i> name is not just a simple name, it's a cryptographic identity. It corresponds to a specific private key, in the same way that an SSL certificate corresponds to a specific SSL private key.</p> <p>Hence, when you visit `duskgytldkxiuqc6.onion` over Tor, <b>the Tor client ensures</b> that you will only speak with the hidden service that knows the correct private key.</p> <p>That saves you from the man-in-the-middle attacks of SSL like sslstrip (see alleged attacks on blockchain.info), or from DNS spoofing attacks that someone can do over WiFi.</p> <p>Hope that helps.</p> Mon, 10 Aug 2015 17:05:43 +0000 asn comment 100632 at https://blog.torproject.org Hm, I'm not sure what you https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100629 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>Hm, I'm not sure what you mean here.</p> <p>The <i>security of the client is the same</i> regardless of whether the hidden service is a direct onion service or not.</p> <p>Here is how a hidden service circuit looks like now:<br /> <b>client -&gt; c_hop1 - c_hop2 - c_hop3 (RP) - s_hop3 - s_hop2 - s_hop1 - HS</b><br /> (where c_hop1 is the first hop of the client, and s_hop2 is the second hop of the HS)</p> <p>And here is how it's going to look like with direct onion services:<br /> <b>client -&gt; c_hop1 - c_hop2 - c_hop3 - HS</b></p> <p>As you can see, in both cases the client is using a 3 hop Tor circuit, hence the client's anonymity is protected. In this sense it's as anonymous as "visiting a regular clearnet website".</p> <p>Hope that cleared it up. </p> Mon, 10 Aug 2015 16:55:54 +0000 asn comment 100629 at https://blog.torproject.org * This is all too much https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords#comment-100586 <p>In reply to <a href="https://blog.torproject.org/blog/hidden-service-hackfest-arlington-accords">A Hidden Service Hackfest: The Arlington Accords</a>:</p> <p>* This is all too much really.</p> <p>I disagree : it is not about tor or hidden service ; it is irrelevant.<br /> let's take two examples ; gaming on line &amp; private chat.<br /> 1° take a gaming craphic card on private Lan and you have both (anonymity &amp; security) without to be connected at the net but the protocol most of time is proprietary and you can be hacked/recorded.<br /> 2° go to a paying service private chat and you have both (anonymity &amp; security) but you are /protected/censored under survey and you can be infiltrated/banned.<br /> Anonymity and security are not a "service" and both are independent ... or linked together according on the will of the dev_admin : it is not always a matter of conception or idea or coding but also an compromising option for a paying service.<br /> Usage of such service is at your own, reporting crime or using as a fun tool.</p> <p>Tor &amp; hidden service does not (afaik) need "the necessary contextual data" ... every body can use it like they wish without to be concerned by the war/crime/news/underground or your private life ... but it is true that the user must be educated and learn by himself how to use it correctly for not be exposed at a real danger.</p> Mon, 10 Aug 2015 11:45:35 +0000 Anonymous comment 100586 at https://blog.torproject.org