Hacker Newsnew | past | comments | ask | show | jobs | submit | Prometheu5's commentslogin

If you are technologically savvy (as one may assume, since you are here after all) and you feel uncomfortable with this change (as I do), I would suggest looking in to some of the other projects around that offer somewhat similar (albeit not as feature complete) self-hosted solutions: https://github.com/philcryer/lipsync http://sparkleshare.org/


If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html


Addressing his points one by one (quotation marks should in no way be thought of as referring to a quote):

"The Navy made it, why'd they release it?"

-They released it because it's entirely useless if the military are the only ones using it.

"It's not theoretically effective. There's lots of ways to break it."

-Sure, there have been papers written about ways to break TOR. I've yet to see someone actually do it. That doesn't mean the NSA or whoever isn't doing it, but you'd think if someone had compromised the system you'd see some story about it. Somebody who was using TOR would have been tracked down and they would have thought, "hey, wait a minute..."

"Project Vigilant"

-Meh. Again, if they compromised TOR, you'd hear about it. They'd have given the IPs of hidden wiki visitors to the feds, and some pedo would have been arrested. If PV don't care about pedos, they would have given the feds some information about somebody that would have led to some sort of action. The fact that none of this has come to light is pretty strong evidence that PV has not compromised TOR.

"Wikileaks uses TOR"

-So the fuck what? They have a pretty clear use case, and the fact that ioerror is a contributor means he's concerned about anonymity (for obvious reasons), not that Wikileaks has hatched a plot to snoop on anonymized traffic and leak details. Why the hell would they bother? They've got more than enough stuff to leak handed to them. What are the chances that someone using TOR would be transmitting data that WL would care about?

This is just stream-of-consciousness FUD from Zed, of the type we're used to seeing from him. He throws out a bunch of what ifs and pretends it's an argument. Show me the evidence. Show me some indication that TOR has been breached and I'll be the first one to question whether it should be used. In the meantime, TOR is only getting more secure as more people talk about it and use it.


There's a lot to be said about super-node pattern analysis with TOR, as well as the flaws in the exit nodes with regard to unencrypted communications, but I couldn't get past the fact that Zed's entire post was a massive Godwin.


Zed will be Zed.


"P.S. I have a long bet that SELinux is an NSA backdoor. Any takers?" Really? Zed Shaw lost the credibility to talk about anything security related with that one sentence ...


Yeah -- as if the NSA would be unable to crack software if it were not for SELinux.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: