Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As knowledgeable users of the Internet in 2024, we would do well to assume that nothing is 100% “safe” (I.e. there’s no such thing as perfect security/privacy).

However, some things, like Tor, can make your use of the Internet safer.

If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.



Agreed – you can never truly be completely "safe", but Tor remains the most privacy-preserving tool we've got.

When people say they're distrustful of Tor (for various reasons) to the extent they refuse to use it, they seldom suggest alternative tools/measures that provide anywhere near the level of safety offered by Tor.


The argument is that using "privacy" tools makes it easier for a party to single you out, and they do have a point.


They have the opposite of a point. The logical conclusion of that line of reasoning is that everyone should use privacy tools so no one can be singled out. And that ordinary users with "nothing to hide" should be the first to start using them.


I mean, sure. And while we're at it pigs should fly.

Functional security means understanding your risks, and using privacy tools is a risk - in the sense that it does single you out in the current environment.

Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.

Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.


> I mean, sure. And while we're at it pigs should fly.

Pigs have significantly higher density than birds and lack wings. Getting them to fly under their own power would be quite a challenge. By contrast, installing Tor Browser is actually pretty easy.

> Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.

In general this is not what happens in e.g. the United States. The act of installing or using Tor doesn't in and of itself cause anyone to beat you with a wrench. Try it. Visit HN using Tor Browser. No one comes in the night to put a bag over your head.

> Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.

If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.

If you live in a country that has a modicum of respect for fundamental rights like privacy and due process, then you can use Tor when you're not breaking any laws and are just trying to avoid being tracked across the internet by Google and Facebook, because using Tor isn't in itself illegal. And doing this not only benefits you, it benefits the people in the first group who need it even more than you do, because it makes them stand out less.

So who are the people who shouldn't be using it?


> Visit HN using Tor Browser. No one comes in the night to put a bag over your head.

HN used to often not create new user accounts when connecting from Tor.

Twitter doesn't let a new user account to pass the prove you're human AI challenge. It says it passes but then shows an error message that there was a technical issue.

By using Tor I'm cut off from Twitter. Twitter is my social media of choice. By using Tor I'm cut off from social media.


You can sign into Twitter with an existing account via Tor. Go to a library or coffee shop with public wifi once and create an account.


which would defeat the purpose of tor, as your account (and presumably, your location at the time of signup), can be easily linked to your tor traffic.

The reason tor traffic is often denied is because it's hard to block or track "the same" tor use, and some people used to abuse this to perform actions that the platform does not want.

You cannot really have true privacy, and also have moderation of content.


The assumption there is that trackability is a desirable characteristic to have in a technical system. As someone who sees technical systems as the onramps to centralized abuse by institutional power, I don't see trackability as a feature, but rather an anti feature.

Consider this: just like fraud, the ideal amount of it in any purportedly liberal civilization is non-zero, because the freedom from which is derived the opportunity to engage in the behavior is more important than perfect attribution, detectability, and prosecubility of it.

People don't realize that when you set goals of zero'ing out these sorts of things, you're throwing the baby out with the bathwater.


I use TOR in the US... You're not actually making a very compelling argument here.

My statement is pretty clear - using a privacy tool can single you out. Am I afraid of that in the US? Nope, not really.

Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.

> If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.

You know a clear way to avoid this risk entirely? Don't trust your communications to a public network. Is TOR better than posting directly online? probably. Is TOR still a risk? Obviously yes. Understanding your risks is important, and simply saying "Use it anyways" is not an appropriate answer. Like... at all.


> My statement is pretty clear - using a privacy tool can single you out. Am I afraid of that in the US? Nope, not really.

Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.

> Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.

But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.

Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.

> You know a clear way to avoid this risk entirely? Don't trust your communications to a public network.

"Just build your own internet" is frequently not a realistic proposal.


I want to firmly state that this is (fucking badly) mis-stating my whole point.

> But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.

Don't use online communication. Period. Talk to people face to face.

> "Just build your own internet" is frequently not a realistic proposal.

Don't use online communication. Period. Talk to people face to face.

> Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.

Not my damn point. And you well know it, you just don't want to concede a breath of air to the idea that you might be wrong...

> Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.

Fallacy is fallacy. Dreaming of a utopia does not make it so, and expecting the average person to take this stance just isn't a realistic expectation. Noble goal. Shit thing to risk your personal safety on.

---

And that's the point. I advocate for these tools, I use them I when I think they're appropriate. Failing to be able to consider a possible downside isn't a "good" thing. It doesn't make the argument for these tools stronger... it makes it hard to evaluate your risk, and personally - makes me think you're actively undermining real efforts for security.

So if your actual stance is "Use these tools even though I understand it compromises your personal safety - I don't care because blah blah blah"... then I don't have enough respect for you to continue the conversation. You are only acting for you, and that's shitty.


Why should ordinary users do something that provides no meaningful benefit and makes their experience substantially worse?


Anyone who search for medical information online should always use a VPN and a browser that cleans itself before and afterward. Health status is one of the most valuable user data available to data brokers and is heavily collected and sought after.

I also use tor in my work in order to get a third-party perspective on a website, or when inspecting suspicious links.


>If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.

Exactly, and this same form of spurious argument came up in an hn post yesterday about cavity prevention, centering on an argument that a new advance in cavity treatment "cannot guarantee" to end cavities forever. [0]

I feel as though I've never been fooled by these arguments, although surely I have different types of weaknesses that are unique to me. But it seems to stand out as a form of argument that somehow has persuasive power among intelligent types whom I would never expect to fall for other forms of obviously fallacious arguments.

0. https://news.ycombinator.com/item?id=41573550


I wish the people back in the 90s understood this when trying to set up encrypted email.


As someone who used Internet in the 90s I don't follow. There was almost nothing encrypted.

SSL/TLS was introduced for POP3/IMAP, but I don't think that was bad.


The 90s had the opportunity to deploy something like PGP widely, but because there was no perfectly safe way to distribute the keys it never went anywhere. The most practical solution the crypto nerds could accept was the web of trust, where you were supposed to physically meet everyone you wanted to communicate with so you could physically exchange the keys, which was never going to scale.

Email to this day is unencrypted at rest and completely transparent to whomever is running your mail server. You don't think Google runs GMail out of the goodness of their heart do you?


There is S/MIME, but probably biggest thing that stopped its adoption was popularity of web mail (so yes, Google and others).


I remember reading on here years ago that people were concerned that the government was reading their "private" emails. I've always just considered email to be sent in plain text. Just 10 years ago only 30% of emails from Gmail were encrypted. Even though now its 99% of outgoing email is encrypted, but all those emails sent before are probably sitting in a database somewhere. And it still reverts to unencrypted if the recipient doesn't support TLS.


Well, for the sake of clarity I would say Tor is safer only if it’s not a honey trap. That is not knowable as a user, but I think that suspicion is well-deserved.

I think the Middle East gave us a very clear example of how state actors may target channels in unexpected ways.


This misses the point, the user in question was fully deanonymized. This blog post is saying that those successful techniques are no longer usable.

It's entirely appropriate to pursue a defense in depth strategy while questioning any particular layer.


But that's half the point. If someone has an intention to undergo some illegal activities with full intention not to be caught, only 100% "safe" solution works for them. Normally we talk about risk tolerance, but this particular use case is a bit special.


There are no "100% safe" solutions. There will always be weaknesses and vulnerabilities in any system. The sort of criminal who requires or expects 100% safety is quickly going to be caught due to being a dullard. Knowing you're never truly "safe" is what good criminals are keenly aware of at all times: you can plan and prepare for certain eventualities. Once you think you're "safe", it's the beginning of the end.


Security is a process, not a "state".

You don't do something, once, and then are good to go forever. Banks don't just put cash in a safe and forget about it; they have audits, security guards, cameras, threat intelligence profiling criminal gangs, etc.


The entire conversation has to be about risk tolerance, because that's all there is. There never has been, and never will be, a 100% safe solution.


As someone who's actually used Tor for illegal activities(buying drugs) this is completely missing the point. Criminals generally are not thinking about doing something completely risk free. The dumb ones don't consider risk at all, because they're desperate/addicted, and just hope/assume they won't get caught. More clever ones assume they'll be caught and try to make conviction less likely.

For instance, for buying drugs, the ordering isn't the risky bit. Receiving it in the mail is. Even if tor was magically "100% safe" the crime overall wouldn't be. The point of using tor is not to eliminate all risk, it's just to decouple payment from reception. I had my drugs intercepted by customs once, but they couldn't prove I ordered them, so they dropped the case. I'm sure it might've been possible for them to prove it if they spent a lot of resources trying to trace crypto transfers and so on, but police only do that if the fish is big enough because they're resource constrained.

Tor is just another tool criminals can use to reduce risk. It's not perfect, but for most things it's the best thing available.


> If someone has an intention to undergo some illegal activities with full intention not to be caught

As opposed to... people who undergo illegal activities with the intention to BE caught???


If there were a way to 100% avoid getting caught when committing illegal acts, no one would ever get caught because everyone would do it


Well no, there are loads of precautions criminals can use to avoid being caught already, and they just don't do them - most criminals are just not that smart.


The only 100% safe method is to not do the illegal activity at all. There's always a risk/rewards analysis to be performed when committing any act that could have negative consequences whether you're playing the stock market or doing credit card fraud. For any major criminal that gets caught, you can usually read the arrest affidavit which offers a pretty interesting look into how the criminal was caught despite the careful measures they took. The one for DPR is interesting to read and shows how despite taking careful measures, DPR left a trail of breadcrumbs that investigators used to track him down. His use of Tor was pretty solid (assuming the whole affidavit isn't complete parallel construction fiction) but it was everything else he did outside of it that got him in the end. There's another story of a university student that sent threats to his school to get out of an exam or something through anonymous emails over Tor. They only caught him because he was the only person using Tor on the school network at the time the email was sent. If he was off campus, he may have remained anonymous.

An analog crime I think about is the murders in Moscow, Idaho. The criminal did take some careful measures like wearing gloves but he left a knife sheath behind that contained DNA evidence. Everything else they had on him was circumstantial, he owned a similar car to what police thought they saw on people's doorbell cameras and his phone went offline during the time of the murders and also pinged a tower close to the crime scene hours afterwards. Police found a partial genealogy match to his DNA which I'm sure they compared to similar car owners and cell tower records. If he hadn't left the sheath behind, wore something like a Tyvek suit, and simply left his phone at home, the suspect pool would have likely been too large. His careful measures (turning off his phone, making multiple passes in his car) likely contributed to police focusing on him once the DNA proved a link.


> The only 100% safe method is to not do the illegal activity at all.

Nope. Not even that is 100% safe because you can be falsely convicted of a crime you never even committed. Many privacy tools reduce that risk as well, because you're less likely to be convicted by e.g. a lazy prosecutor willing to take things out of context if you provide them with less source material to trawl through.


On the other hand "he was using the dark-web Tor browser beloved of criminals and widely used amongst drug sellers" is probably pretty convincing to jurors.


What jury? Only 2% of criminal cases go to trial. The goal is to give them nothing they can use to bring you up on (false) charges. Using Tor isn't a chargeable offense in free countries.


I think the point was that you aren't being "charged" with using Tor, you are being charged with buying drugs online. You have Tor installed and unfortunately a very small percentage of people have Tor installed. That might be enough to convince a jury, or be enough pressure for you to plead down to a lower crime to reduce that risk.


There first has to be some actual evidence that you were buying drugs online. If the cops search you and find drugs, it isn't going to matter a lot one way or the other whether you have Tor installed.

If you weren't actually buying drugs online then there shouldn't be any evidence that you were (or the cops planted it and then we're back to it not really mattering whether you have Tor installed). And then what are they charging you with that would even make it to a jury instead of being dismissed by the judge for lack of evidence?


Drugs are sent to you and intercepted. You claim, though your lawyer, someone was just using your house as a drop and you have no idea who ordered them. They get your computer, you have Tor installed. Prosecutor argues Tor is only used for CP and drugs. Is that enough to convict? Maybe.

If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP. There are privacy use cases, but just like using crypto as a currency and not a speculative gambling investment, its in the small minority of uses.


The trouble is that the alternative is worse. They come to your house, you don't have Tor installed and then, because you haven't been using Tor, they pull your search history and trawl through it looking for things to take out of context.

Why did you do multiple searches for std::vector? Are you worried about sharing needles? You also read an article about caffeine, which is often used as a cutting agent. You've been participating in internet discussions about using Tor, which the prosecutor argues is only used for CP and drugs.

> If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP.

Nobody really knows what Tor is used for, by design. But the media likes to rile people up, and "Tor used by privacy activists to read Facebook" isn't a headline that does that.

It's all too easy to lie with statistics. For example, some people have looked at which hidden services are most often looked up. That's not going to tell you about real usage, because bots do lookups at a much faster rate than real people, and government agencies run automated crawlers. Then you get statistics that say a significant percentage of the lookups are for CP and drugs, but not what percentage of those lookups were made by law enforcement running crawlers 24/7 specifically looking for CP and drugs.

Here's another example:

https://www.sciencealert.com/only-a-small-fraction-of-the-da...

> "In countries coded as 'free', the percentage of users visiting Onion/Hidden Services as a proportion of total daily Tor use is nearly twice as much or ~7.8 percent."

> In other words, people living in liberal democracies are more likely to exploit the dark web for malicious purposes, whereas users living under repressive regimes in non-democratic countries might be more likely to use Tor to circumvent local censorship restrictions and access free information on the internet.

Tor is used to bypass censorship. This use case happens more often in countries where there is censorship, and less often in countries where there isn't, because obviously. Reaching from there to "people living in liberal democracies are more likely to exploit the dark web for malicious purposes" is ridiculous. A higher ratio of B to A because of a smaller need for A does not imply a greater occurrence of B.


Yes, all good. My point was that you aren't being charged with having Tor in the scenario that was described. The existence of Tor on your computer might work as connecting the user to a drug sale.


And what I'm getting at is that in that circumstance, not using Tor is worse, because at that point they have a weak case but are now searching your residence to backfill their case with whatever circumstantial innuendo they can dredge up from a fishing expedition. If you've actually been using Tor then they get less of your browser history and are deprived of material to take out of context. Instead they're left with only the rhetorical argument you propose, which is still weak.


> Nope. Not even that is 100% safe because you can be falsely convicted of a crime you never even committed.

That's so exceptionally unlikely as to be something you can discount as a possibility, providing you don't actually commit crimes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: