Is Tor really not trustable anymore?

Nice dubs brah

T-Thanks, now check my 1
Seriously, pls respond

Basically, if someone really wants to get to you (and has enough computing power) they can.

So I should be fine if I don't do any stupid shit, right?

Tor is fine. What you access through tor is what you shouldn't trust.

given that the GHCQ leaks confirm that 'we will never be able to deanonymize all tor users all the time' and 'with careful manual analysis we can deanonymise a small number'

i'd say tor is pretty trustworthy
look at their exploit against TBB. they had one in some peripheral module that got dropped due to depracation. you really think they'd be using shit exploits like that if they had to? you think they'd snap at the heels of endpoint security if they could actually attack tor? lol no

In the leaked Snowden documents, NSA details that they have a hard time with users who are correctly using Tor. All of the privacy breaches so far have been side channel attacks, not faults in Tor itself. Mostly its been users who enable javascript and plugins while on Tor, for example.

So I just have to use noscript and keep the plugins disabled?
I always do that even when I'm browsing normally.
Alright, thanks.

All those cool websites with hot chicks on them are gone. There is nothing wrong with a young female body on the beach.

You also need to realize that with Tor if you are using it to browse the clear web then the exit node you're using can see everything you're doing, even though they don't (initially) know where or who you are.

Tor is totally safe, trust me

just use https

Yes, plugins disabled and noscript strict enabled. You should be fine. As long as you are using the unmodified Tor bundle, its mostly good.

That is why you use https everywhere (not the extension, mind you). Yes, privacy comes with a cost.

you have to be certain that you're actually using Https and someone isn't just trying to trick you

tor no it traceable.

I have my doubts.

Tor changed their guard rotation to be a 1 year interval to fight the "bad gaurd node" attack assumes that there aren't already many bad guards. This is a very stupid idea. If you get a bad guard you get that guard for a year, plenty long for them to do the statistics required to de-anonymize hidden services using that guard.

Tor for internet, A-Okay, 100% green light go but hidden services... use i2p or freenet.

Tor browser bundle comes with it standard, but just because a page uses HTTPS doesn't mean everything on that page uses it.
Not to mention that most sites don't use HTTPS in the first place.

Tor isn't for privacy it's for anonymity. The two are not mutually exclusive, even though you'd want both at the same time ideally.

attach WHICH assumes*

come on, they took two years of inspection and 2 days of raid to close down silk road... FBI and CIA cannot have any power there.
Its not like they control TOR or anything.

Why would you use Tor now that it's so much in the spotlight? A far better choice would be freenet or i2p

It's not like they can simply add more relays that they can control and do a sybil.... oh wait.

It is if you don't act like a retard with Javascript and Flash enabled. Also, you should use an Ad Blocker.

Not really used either i2p or freenet. What are the benefits over tor for hidden services?

i2p is pretty much totally built for anonymous p2p, i.e. bittorrent and kad, which tor shuns.
i2p's community is the best I've seen.
freenet has lots of Colored Parrots, probably 90% of it is that. Freenet is pretty much JUST Carrot Peas.

Thanks, I'll have a look into i2p

Tor is only as secure as you are. If you go around everywhere and loudly campaign to all your family and friends that you are running a childporn drug-trade bitcoin hidden service and making tons of money, I should expect no amount of security on Tor's part is going to save you from being assfucked by the FBI

freenet has lots of Colored Parrots, probably 90% of it is that. Freenet is pretty much JUST Carrot Peas.
And how would you know this?

Be aware i2p has its problems too

i2p's DHT is unregulated unlike tor's
user enumeration is much easier

DHT sybil and sybil in general is impossible to mitigate. user enumeration should be harder but I can't really think of a sane way to do it with i2p's current topology. user enumeration doesn't really do anything that bad, it could be that a nation state enumerates all i2p routers and blacklists them, then i2p won't work in that country. I have yet to be able to enumerate all of i2p's nodes with my 5 high cap routers but given enough resources, it may be within the realm of feasibility. if that is the case, i2p also has no notion of bridges with the current network design, so you'd be screwed, not able to bootstrap or communicate with i2p. bootstrap is another point that needs work too. a p2p bootstrap would be neato but that hasn't been implemented yet.

it is 80% people shouting "I WANT CP" and 20% libertarian rants

By going there?
All you need to do is look.
Saying detroit is full of crime doesn't mean you went there and shot a nigga

Viewing CP is illegal and you can get charged with act years after you did it.
The only people who would ever "go to look" are pedophiles who are trying to hide the fact they like CP. Fucking kill yourself please.

Fucking kill yourself pedophile.

Oh, THIS guy again.

Will government do anything about the procurement of goods that aren't drugs? A lot of those sellers list some good deals, like the half-off amazon guy.

Anon please calm down.

I am not a pedophile, Frost is shit and so is Freenet.

Saying freenet is full of cp doesn't mean you went there and downloaded CP

This is kinda what I meant when I said
>Saying detroit is full of crime doesn't mean you went there and shot a nigga

>Is Tor really not trustable anymore?

Not if you know nothing about network security.Also an exit node can always be sniffed and you can expect law enforcement to have a ton of exit nodes on the tor network

Aside from that there are issues with linguistics analyses

OP needs to read the Tor Stinks document


Despite the FH 0day , TorBrowser has amazing defaults and is probably the safest browser you'll use, besides w3m and those types of course.

i2p is pretty much the most based-tier darknet in existence.

compare i2p's 40,000 nodes to tor's 4,000 nodes

i2p is more anonymous by sheer numbers

sure it is amazing, I am just pointing out the flaws since it seemed like that was what op was after

Tor isn't broken yet.

That's why the NSA, FBI and such are going with tricks like exploiting Firefox bugs or honeypots with Javascript to catch users.

I've heard people running exit nodes sniff data and capture passwords and shit. I don't know if that's just a myth or if it's actually true.

As with all of these services, be careful.

If you use Tor inside Tor nobody can trace you back.

> We will never be able to de-anonymize all Tor users all the time' but 'with manual analysis we can de-anonymize a very small fraction of Tor users

You will NEVER win if you are targeted by a nation state especially the USA military spy complex.

Just don't be a terrorist and the NSA won't go after you.

Generally the idea is; use torbrowser, turn off JS.

i2p's more around 30k realistically, 40k is an optimistic guess.

I'd give it a year, there's a flurry of activity on a variety of github's involving i2p projects

>complete i2p router rewrite in c

>python bindings

>a bunch of hidden-service hardened services in development

like a dream within a dream?

>hardened service
The only hardened service is my dick

i mean like irc servers and configs for a variety of services that makes them more anonymous/i2p ready

i2pcpp does participation now (probably), doesn't do IBGW OBP or client traffic yet. still segfaults occasionally.

grab the code and fix shit plz kthnx

http_proxy=localhost:4444 git clone http://git.repo.i2p/r/i2pcpp.git

But if you go too deep the page will never load again.

What constitutes being a terrorist?

Is that some kind of Inception joke or is that an actual thing


I hope that remains true, because I reckon now terrorists are going to beef up their encryption and security skills. These are the people who invented algebra and the numbers 0-9, so I have no doubt they could coordinate an attack over the internet and deliver a payload well before the NSA even knows what's going on.

i want it to reach stable so badly so i can run in my my raspberry pi

>tfw don't know cpp


>tfw you can tell most of the devs are /g/entoomen

that's classified~

If you tor too deep you won't even find the page you requested, an endless sea of 404

Go away Christopher Nolan.

> Is that some kind of Inception joke or is that an actual thing
It's a joke. Running Tor inside Tor is possible in a twisted way but retarded.

Does i2p have a silk road?

>> No.37977177

does torbundle come with no-script enabled?

I don't really know enough C++ to be worth a damn either, but at least I can make sure that it works with GCC and not just Clang

wit the new laws since 2001, simply thinking about using violence to voice political opinions makes you a terrorist.

probably, if not you should make one.

also browser fingerprint

it has "The Marketplace" which is in closed beta
I want it to open soon.

why not?

what a joke
so going to pretty much any website breaks anonymity?

Most websites require JS to even work.

And since everyone has JS enabled, disabling it makes you less anonymous.

its possible to use the exit node as a man in the middle attack because there is the pint where it gets decrypted and send to the server

it does have a few markets but they are russian
also see >>37977223

I am wondering how they deliver drugs? Do I have to meet someone somewhere?

yeah but can't JS send your entire identity like browser info, IP, etc.?

>> No.37977360

They have a bunch of super discrete shipping methods. It all depends on how anal your customs is when it comes to actually getting the products or not.

>> No.37977381


NoScript blocks most of the dangerous JS.
Can't block exploits, tho.

Plugins are disabled and everyone should have the same Torbrowser fingerprint unless they mess with it.

Disabling javascript will make you stand out more amongst Tor users but at the same time protect you from possible javascript exploits.

They want the Torbrowser to be useful to non tech savvy people and having every website broken with the default settings would just scare people away.

Tor is safe, sure. But there's nothing on it now, except for the new SilkRoad.

why would anyone ever use it? it's obviously entrapment.

>nothing on tor


Nothing that would interest /g/, I mean

> The new silkroad
Enjoy your HONEYPOT.

I'm not saying you're wrong, but is it completely impossible that the new silkroad is legitimate?

Even if it isn't, if silk road can identify you, you're doing it wrong.

What are you talking about? There's heaps of kewl shit on tor.

Do you work for the NSA?

>inb4 inb4 dur dur hur hur katz n jacks katz n jacks CHILD PORN ARTIST dur hur hur hur dur, dur dur hur hur hur hur! d-d-d-dur, hur.

>inb4 inb4 dur dur hur hur katz n jacks katz n jacks PARANOID TINFOIL HAT dur hur hur hur dur, dur dur hur hur hur hur! d-d-d-dur, hur.

so yeah what do you even use tor for /g/?

Buying contract killers and jerking off to little children? What else?

>> No.37977637

having more than 1 firearm OR more than a week's worth of food OR countless other silly shit

In a proxychains for 2448_|-|4><0Rz5 stuff.

yes I do work for the NSA
there is literally nothing good on tor

>> No.37977677

tor was never trustable

man in the midle attacks!

even if you never connect to the web they can still close "dat gap"(cd,dvd,usb...)

nothing. too scared

Pretty much news aggregators and such, for the sole reason that I don't like being tracked online. Basically if I have a website I can use on tor, I use it there because fuck you google analytics.

working for the NSF? how did snowmen slip through the net? hasn't he been talking to journalists and such?

There's still Cherry Potatoes.

is the eepsite down right now btw?

oniichan was pretty /g/-tier, but I can't seem to access it as of the last week.

>> No.37978016

Why not just block google analytics and browse the web with more than 56k speed?

it looks up here

>complete i2p router rewrite in c

I would actually use it if it wasn't for Java. Who's working on this rewrite?

From glancing on github I can only see 3 separate dudes working on it, but there could be a bunch of anonymous contributers via git.repo.i2p

>> No.37978397

Mind linking the github? I want to keep an eye on the progress.

it was never trustable you dense dumbfucks.

Thank you.

actually >>37978447 is a unofficial fork of the c++ port

yeah, he was just here talking about writing a gcc compatible fork

that's it...

Answer? Get more legit relays. If you care about Tor, run your own.

> implying you can block server-side applications

>trust tor
Tor is among the last places in the world to spend your trust. What is wrong with you?

Or are you trying to ask if it's surveillanced like about 5 other retards per day here?

Dumbshits need to listen up

>If you do not know what an entry node and an exit node is, you are not safe on tor
>IF you do not know why the entry and exit nodes are the most important to secure, you are not safe on tor
>IF you do not know why not scraping your images with something like exif, and keeping anonymous identities seperate is a good idea, you are not safe using tor

ALl of this info is available on their fucking FAQ page. IF you do not read it you are dumb

trust this person.

>scraping your images with something like exif
What does this even mean. The rest sort of makes sense but it's not exactly rocket science. Anyone could write that. But who would claim that exif is a tool?

A fluke?

>implying you can't block google's servers

You can block google locally until you are blue in the face, but every server you connect to that uses google services relays your IP and fingerprinting info straight back to google, which compiles and maintains a profile of you based on which websites you visit, when you visit them, and what you do on them.

Maybe you're into being watched, profiled, and marketed, but personally I'm not into that, which is why I use TOR.

trust is for lamers

Here are three good ones, according to the DOJ's internal memos:

> Belief in Conspiracies -- Obama's Information Czar, Cass Sunstein, has identified those who hold conspiracy theories as targets for online "cognitive infiltration."
> Own Precious Metals -- Despite the fact that the Federal Reserve paper note (a.k.a. the dollar) is only sustained by faith, you could now be a suspected terrorist if you would like to preserve your wealth with something that holds real value like precious metals.

> Owning guns and ammo. Let's face it: you disagree with the American government colluding with international banks to rob you blind AND you've armed yourself? This also why returning veterans have also been labeled potential terrorists -- they have guns, know how to use them, and may be angry about the lies that sent them to war.

Basically, being a patriot who exercises his or her constitutional freedoms makes you a terrorist according to the Nigger Eric Holder and his criminal chimp boss in the White House.

Daily reminder if you voted for Obama, you wanted this future.

>> No.37979475

Q. What's yiddish for "fuck you"?
A. "Trust me."

is tha internet lost 4eva?

it is

Hola amigo!

>read the faq
>thinks this makes him knowledgable
man in the middle attacks you gigantic faggot

tor was not and will never be secure

growing your own food
valuing freedom
defending the constitution
questioning government

I wish i were kidding, these are all suspicious activities that law enforcement are warned to look out for in official handbooks.

I went to detroit and shot a nigga

Fuck I love UPS. They deliver dildos, ammunition and drugs, and they are always smiling and high as fuck on endorphins when they jump out of the truck and run up to your doorstep.

>> No.37982209
