Replies (67)

MissingNo's avatar
MissingNo 1 week ago
Do not trust Tails OS. Tails is no longer open source. You need to email them to request permission to even look at the source code. They've closed registration to their GitLab instance, they don't explain why. Half of the opening paragraph about Getting Started as a contributor is about pronouns. Everyone working on the project seems to be salaried and keeps strict office hours. Even if you get access to their instance, as an outsider you can't report issues to it. Oh, and if you want to access their mailing list archive, you can't because it was hosted on Autistici/Inventati, the Italian hard-left entity that was just designated as a Specially Designated Global Terrorist by the US and taken offline. I would not trust the project anymore. DYOR.
The designation of Autistici/Inventati as a "Specially Designated Global Terrorist" by the US is total bullshit, and a direct attack against civil liberties.
MissingNo's avatar
MissingNo 1 week ago
Likely. I still think TOR is safe tho, i only have a problem with the team behind it (Tor Project)
MissingNo's avatar
MissingNo 1 week ago
Their wiki does't even explain why they recommend not using a VPN. So strange...
MissingNo's avatar
MissingNo 1 week ago
Using a VPN 24/7 should be the default for everyone. I see TOR an extra layer on top for added protection.
Perhaps because your ISP can't see Tor usage (though bridges do that better), but now the VPN provider knows your real identity and that you're on Tor, a correlation choke point with payment records attached. Plain Tor never asks who you are. This is negated with some VPN provider though as not all require KYC. If you're using a private VPN and then from their connecting to Tor, you're most likely fine. If you're connecting to Tor and then a VPN, that's bad. You're essentially negating Tor's random exit node. Tor exits rotate per circuit, a VPN exit doesn't, so the VPN becomes one persistent observer of all your traffic, defeating Tor Browser's per site circuit isolation. It's also technically fragile: Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config. And this special configuration is very complicated for the average person that just what's some privacy. My two sats. That said, three letter agencies absolutely run Tor exit nodes. Why wouldn't they? They'd be terrible at their jobs if they didn't.
This would be no different to an ISP? ISP can absolutely see tor traffic so this only stands if for some reason your ISP is retarded? Which in the US is likely to be one of 4-5 major companies, all of which have state-of-the-art traffic detection for their ad's business. And we cannot simply forget about Room 641A. A primary (and my opinion only) purpose of a VPN is to shield traffic from your ISP, which has the added benefit of hiding your physical location from servers. Because ISPs publish your IPaddress location information for legal reasons, and because they get advert money from it. Then, you must vet your VPN the same way we don't trust our ISPs because we simply shifted the watching to the VPN opposed to our ISP. However the VPN provider has been proven to be much less likely NOT to share your traffic information NOR your personally identifiable information on the public internet to find in milliseconds like ISPs do. > Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config. Don't think this is true at all. Tor works just fine being tunneled over wireguard out of the box ime. So not sure which setting people are leaving off that breaks this. If were worried about the alphabet bois none of these are a solution, and I would consider them equally a problem. Tor traffic is identifiable, and can be time-correlated well enough by the alphabet bois that you're pretty boned using tor at all if they care enough about you.
I didn’t see actually any bug different between if you use VPS , the functions still the same to hide your identity . If you don’t want to get tracked then you just use , incognito mode while using reguler VPS. Don’t need TOR for that . In my opinion .
Correct. Your ISP can see: That you use Tor. Your first hop connects to a guard relay, and all relay IPs are on a public list. The traffic is fully encrypted, but "connected to known Tor relay" = "this customer uses Tor." Volume and timing, how much, when. Your ISP cannot see: Content. Thanks to three layers of encryption, peeled one hop at a time. No single party holds both ends, by design. Destination. The guard knows you but not where you're going. DNS also resolves inside the circuit, so no DNS leaks (unlike a sloppy VPN setup).
MissingNo's avatar
MissingNo 1 week ago
If you are asking because you wan't to download & use old versions, please don't. They most likely contain security vulnerabilities. As of right now, Tails seems to be fully compromised, i would never be trusted again. The Tor Project has also been very shady for quite some time now.
Datura is here to fix, what Tor is refusing to fix. Better use i2p for now.
Just have a VPN on the router/secondary device and then connect over tor on the main machine.
A project by Nihilist (creator of the OpSec bible). He proposed some fixes to tor, that can be used to deanonymise circuits. After waiting for far too long he started to change his stance on Tor and now thinks it is a compromised project (better than nothing). But far from what it could offer. So he went on designing a new protocol that takes care of what needs to be fixed. Read up on it.
MissingNo's avatar
MissingNo 1 week ago
Can you provide some links? I can't seem to find anything
MissingNo's avatar
MissingNo 1 week ago
Found them. I have a week worth of reading yay!
You must understand that the USA government is controlled by pedophiles and this is what they do.
AncapCrab's avatar
AncapCrab 1 week ago
Interesting. Another thing to dive into. Did just use it twice just for fun to try it out. What about Parrot OS? In general, by any chance, do you know more about other "safe" OS that are possibly compromised?
I’m only an occasional Tails user and I’m not a dev or security expert, so I just did a quick check. Some of your points seem valid, but personally I don’t think they are enough to make me distrust Tails as a whole. I’ll probably keep using it when I need it. Still, raising doubts and looking critically at tools like Tails is always useful. Open-source privacy tools matter a lot, especially in a world that is becoming increasingly surveilled.
MissingNo's avatar
MissingNo 1 week ago
Any OS that has leftism / woke politics attached.
AncapCrab's avatar
AncapCrab 1 week ago
Yeah thats a fact I found out myself already πŸ˜† Thats their thing, being cancer to whatever "them" touch. RIP Blizzard btw. ATM I am on omarchy exclusively, so should be fine for now. 🀞
MissingNo's avatar
MissingNo 1 week ago
I'm on SecureBlue, it's the GrapheneOS of Linux.
MissingNo's avatar
MissingNo 1 week ago
Same, I only use mine to play games and to run my bitcoin node. Everything else I've transitioned to mobile. Android (and specially GrapheneOS) has superior security and privacy.
Oh well.. when a product has "secure" on the title then it is likely everything except that. Worst, they even brag about it right on their frontpage with the adoption of SELinux (Security Enhanced Linux) in contrast to other distros that tend to stay far away from it: image Do you know why they keep distance? Because it was written by the NSA, that's why: image Try to guess what is the business model of that government agency.
MissingNo's avatar
MissingNo 1 week ago
It's the only distro recommended by GrapheneOS. Their browser is a Vanadium fork. You should DYOR before talking nonsense.
Sorry for being too slow to respond. Glad you found it (only on tor).
Best to do both. Look at the code and the connection. And if one is shady put even more eyes on the other. Only relying on one data point is stupid. Compromise can come in different flavours.
Scoundrel's avatar
Scoundrel 1 week ago
Using Tor without a VPN normalizes Tor usage and is important for its continued existence. Tor requires public volunteer nodes to be able to exist, and if people start being to scared to be seen using Tor even when its legal, it can destroy the entire network. That's just a VPN-before-Tor setup though. A Tor-before-VPN setup is actually really bad for completely different reasons. The Tor protocol and browser go through a great deal of effort to ensure that even a single browser session is split up across many different Tor circuits. Usually unique circuit across browser tabs, websites, and sessions I believe. However, when you pay for a VPN subscription, it completely destroys that. Suddenly every tab, website, and browser session is associated with the exact same VPN subscription. Maybe you buy the subscription anonymously, but with a Tor-before-VPN setup, the VPN can still build a profile of your browsing habits to make guesses about who you are. The same cannot be done by the exit nodes in a Tor only setup. Personally, I think it's silly to warn people about Tor-before-VPN setups. Not only is Tor-before-VPN very difficult to set up even ON PURPOSE, but it actually has some niche applications, such as connecting to some kind of personal server associated with your identity, but without revealing to the VPS provider that you are connecting to it over Tor. Tbh, I think most people bashing Tor just want to pick on the biggest guy on the block to make themselves feel better, even if in practice their opsec is not nearly good enough to justify dismissing Tor like that.
Another reason to keep distance. That shady android distro with shady funding sources. DYOR before using gov-sponsored software.
As explained earlier, it is darn easy to hide anything inside 25 million lines of code, whereas it is easier to ask who is sponsoring a project. Past experience like Signal and its gov-sponsoring has demonstrated that it is a good practice to follow the money trail when the topic is privacy.
DARPA isn't the NSA, their goals differ. This is particularly relevant when the topic is privacy.
When did they close the registrations? There was a remote code exec vulnerability discovered in gitlab few days ago. All you needed to abuse it was a gitlab account.
Yes. I personally build my own operating systems, build the hardware as simple as possible (usually ESP32) and build my own internet (XPRS is an example) running on BLE, reticulum/i2p over internet, radio, LoRa and radio. This clip is from an operating system that I created from scratch a few years ago in what would later be called CYD (Cheap Yellow Display). In the meanwhile things evolved, now with satellite based text messages at the moment. image
↑