Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One major challenge:

Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked documents say that use of security services, including VPNs and I think Tor also, causes the data to be retained by the NSA for future decryption.

How can Mozilla and their partners provide confidentiality in a way that increases end-user security, rather than attracting further scrutiny or, far worse, providing dangerously false assurances? The answer cannot depend on end users understanding the technology or subtle tradeoffs; the vast majority will never understand.

One thought: Route all Firefox users through Tor relays by default, creating some security-through-obscurity. There are problems with that, of course, including the blacklisting of Tor relays from many sites.



Routing all Firefox users through Tor relays by default would be madness.

* It would make Firefox slow.

* It would place a tremendous load on the Tor network.

* It would defeat content filtering (which includes blocking malware) on enterprise networks.

* It would expose users to traffic interception and manipulation who wouldn't otherwise be so exposed.


Here's what could help - turning all users into (exit) relays. That strategy has worked for torrents very well - all downloaders are also seeders (I think it's a similar situation).

This solves multiple things:

1) makes it much harder to do traffic analysis

2) makes it almost impossible to "go after relays". Sure, they'll still try to arrest some here and there, just like they try to arrest people who torrent movies, and even with the mass copyright laws they couldn't stop piracy. There were just many more who did it, making the hunted down but a tiny percentage.

3) should make the legal defense case even stronger than it is now for relays. You can say today that "you don't know what's happening through your relay", however you still have to choose to become a relay. I think that says something. It may not be a huge case in the prosecutor's favor, but it may convince the judge to be against you in some cases. But if everyone is a relay and you can use the defense that "this is just how Tor/Firefox works", I think that would work a little better

4) should improve speed since relays can't be choked anymore

5) I'm not sure about this one, but I think it should make it much harder to DDoS Tor users/hidden services as well?

I think having the way Tor works currently is a design flaw in Tor. Tor should be "fully distributed" in a way.

As for the argument "but then no one will use Tor if they are forced to be relays!" - I just don't buy it. I think there may be some that will get scared in the short term, but then see Tor actually gets more secure this way in the long term, and will return. I also believe Tor will get more new users in the long term this way.

EDIT: What I'm referring to is turning everyone into exit relays/nodes. My arguments remain the same. If it's not illegal for people to have an exit node in US (as Tor claims [1]), then it shouldn't be illegal for millions to do it either. In fact it could be a sort of stronger civil disobedience thing.

Plus, even if it is illegal, so is piracy. That hasn't stopped millions from doing it. Just like "being gay", what's legal and what's illegal is a matter of how we shape our laws. To change those laws, first you need someone to break them and change the society in a different direction. If you didn't have anyone to break a law in a certain direction, then laws would never need to be changed.

[1] - https://www.torproject.org/eff/tor-legal-faq.html.en


The problem is that you do not make the distinction between a regular relay and an exit node. There are enough regular relays in the tor network, but people hesitate running exit nodes because of the legal liabilities: many ISPs do not want you to run a tor exit node, because of the nature of some traffic coming through the tor network (illegal marketplaces, child porn, etc -- as you can read in the article, even Mozilla doesn't want to host exit relays).

If you make this the default, you're opening a can of worms legal-wise. If you make only non-exit relays the default, your whole plan defeats its purpose, because then exit nodes remain the weakest link (as they are now).


I agree that it's too crazy for Mozilla to seriously consider it.

But, assuming Tor did receive widespread adoption of exit nodes at this scale, the internet would have to adapt to accommodate this many people rerouting other people's traffic. ISPs would encounter the same backlash for throttling or blocking users who run exit nodes as they currently face when doing it to users running Netflix.

Unfortunately, it takes mass adoption to force this kind of adaptation, and it's generally an easier fight to maintain venues of freedom than to open new ones. So we have a chicken and egg problem essentially; Mass adoption is necessary to force regulatory and infrastructural accommodation, and that accommodation is necessary to foster mass adoption.


"The law just has to change to adapt to our new technical ways" ist a common fallacy with techies. And has been working /splendidly/ for decades now.

More importantly, letting every of your users out in the rain with his legal problems until you have finally been successful in changing the law is not a recommended way to treat your users.


FWIW, I _intentionally_ de-anonymize myself over TOR as often as I remember to. I make a point of browsing things like local council and government websites using TOR, including logging in or providing details in contact forms, while doing mundane and ordinary stuff like booking extra garbage collections.


Interesting - care to elaborate on the reasons?


I'm not bigiain, but an obvious motivation would be that the more people use Tor for obviously mundane reasons, the more plausible deniability exists for all Tor users. After all, the fact that you're using Tor cannot be hidden, and you don't want people to fall under suspicion merely for being Tor users. In other words, there is probably no direct benefit to bigiain for doing this, but she/he is doing everybody a service.


Exactly this. Since Facebook has a .onion, I sometimes use instead of the .com, and even if I don't use my real name on Facebook, I'm not at all anonymous there.

I also have my personal web page accessible as a Tor Hidden Service [1] and as an EepSite [2], even if a personal web page is the least anonymous thing you can think of.

[1] http://pablo6zbxiijn5hd.onion/

[2] http://p4bl0.i2p/


Hmmm. Wouldn't trying to remain anonymous be better? I mean, if most of the people on Tor are not anonymous (because they "disclose" themselves voluntarily), the rest of them might be in the spotlight...


The important part is that the anonymity set - the amount of traffic among which those with a need for anonymity can hide - becomes larger no matter what the people without a need for anonymity do.

Consider the extreme case where Tor is only used by dissidents in a single country X. As soon as country X's secret police observes your home internet connection connect to Tor relays, they know that you are a dissident.

Now consider the case where only 1% of the traffic on Tor is by dissidents in country X. When your home internet connection is observed to carry Tor traffic, it is impossible to tell whether you're among the 1% of dissidents or the 99% of non-dissidents. So they have some reason to suspect you, but it's already a clear win, because rounding up and terrorizing 100x as many people takes more effort and is more likely to result in pushback.

The only place in the Tor network where the "trying to remain anonymous" makes a difference is when the secret police collects exit relay traffic. However, if all they see is that 1% of exit traffic is TLS sessions to dissidents.xx and the other 99% is unencrypted sessions to facebook.com (hypothetically), that still doesn't help them figure out which Tor clients are sending those 1% of traffic that they want to chase down.

Of course, all of the above is subject to the inherent limitations of Tor (e.g., somebody who is able to observe all relays can do statistical timing-based attacks to correlate relay input-streams with relay output-streams; they can then trace back the Tor circuits and figure out which user is responsible for which exit traffic; somebody who is able to observe a fraction of relays will be able to do such correlation attacks with a certain probability of success; the secret police might observe dissidents.xx as well as the home connections of everybody using Tor, and might be able to sieve out the 1% of dissidents using timing correlation, etc. [0]). The point is that the nature of the 99% of non-targeted traffic doesn't matter; the important thing is that it's there, and the more, the better.

[0] This seems to suggest that if you want to hide some of your traffic via Tor, it actually makes sense to tunnel everything via Tor. However, this also has problems: for example, if you use the same browser to access both facebook.com and dissidents.xx, browser fingerprinting might kill you. I don't actually know what the best practices recommendation is. Given an adversary with sufficiently tight control over the communications infrastructure, you're basically screwed.


The Tor Browser Bundle already comes with a bunch of hacks to make users more difficult to track. I suppose they could improve on that until you're no longer identifiable on something like EFF's Panopticlick [1] or Samy Kamkar's Evercookie [2].

For example, isolate each tab, nuke all tracking cookies by default, clear all local storage at a regular interval, access different sites using different circuits, and only allow JS to access a minimum of information about the system. Even better, expose fake, generic, but slightly varying lists of system fonts, plugins, and other information. (Fake information is better than disallowing access altogether, because the latter looks too suspicious.)

Of course, none of this will keep you anonymous if you log into Facebook using Tor... but at least the browser could make it extremely difficult for anyone to find out that the person who is visiting unrelated-website.com is the same person who just logged into Facebook. Automatically switching circuits when you visit a new site would probably do wonders in this regard, though I'm not sure how well Tor can handle that.

[1] https://panopticlick.eff.org/

[2] http://samy.pl/evercookie/


The Tor Browser developers have all of this as an explicit goal:

https://www.torproject.org/projects/torbrowser/design/

They still have more work to do to get there, of course -- it's a challenging target!


How about just allowing all firefox users to access .onion sites securely by default?


I'd also like to see Firefox support .bit domains or similar in the future. I don't blame them for not doing it right now, though. Namecoin and such are still very experimental technologies, but maybe in a few years.


It is a tricky issue, but I can see a good argument for increasing the amount of traffic going through TOR, even if much of it was from users without proper OPSEC.

As with all security, it is an education issue; just as "Private Mode" warns users that they might be tracked by ISPs or other agents, "Super-private mode" would have to warn users that supplying identifying information would jeopardize their privacy.


> it is an education issue; just as "Private Mode" warns users that they might be tracked by ISPs or other agents

I wonder what percentage of users understand that. How many read the fine print, grasp its meaning, and act on it?

It would be interesting if Mozilla has studied this security training in particular or if someone has studied security training in general. That is, test how many users read the information, retain it, understand it, and act on it? What works and what doesn't?


If we compare with the current private window that users are already using in Firefox, the steps to more security is likely to start with technical transparent solutions rather than large changes to user behavior.

The question I ask: Is tor browser better than the current private window? I think it is easier for a user to disclose private information by using private window, than using a tor browser. I would also claim that traffic generated by a private window is stored and analyzed in a much greater extent than traffic sent through tor or VPNs.

We already got the problem of false assurances thanks to private window. I have a hard time seeing how it can get worse by incorporating privacy tools.


>One thought: Route all Firefox users through Tor relays by default, creating some security-through-obscurity. There are problems with that, of course, including the blacklisting of Tor relays from many sites.

Sure this would accomplish that goal, but it's extremely unpractical. The Tor network is slow enough as it is, add millions more people and it'll grind to a halt. Plus all the issues of sites that rely on IP addresses for fraud detection and moderation (banning spammers, for example).


I don't think Firefox will route through Tor by default, doesn't make sense.

I don't want to be routed through Tor by default, as not everything I do is privacy sensitive. But I do use Private Mode and it would be awesome to have a Private Mode that connects through Tor or maybe fast switching to a Tor-enabled profile.

This announcement is actually exciting.


I think this solves itself: How is the NSA going to keep track of ever increasing piles of data-to-be-decrypted? They will be swamped, eventually red-flagging so many people that the red flag becomes meaningless.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: