7 ms·
Snowflake
- ChrisArchitect 3y agoAnything new here from last year?
- batch12 3y agoSo, I'm reminded of the old 'store your files on youtube' thing[0] and I wonder how much bandwidth one could get using the same concept on one of the widely used voice conferencing solutions (like zoom) to further blend in. Bonus if you can do some kind of video steganography to transfer the data and have a 'real' call. [0] https://github.com/DvorakDwarf/Infinite-Storage-Glitch https://github.com/DvorakDwarf/Infinite-Storage-Glitch
- dpkonofa 3y agoThat would be amazing. If that worked regardless of network, though, I can see people setting up a node and accidentally taking it to work or some other public network by mistake. I’m not sure if that’s better or worse than using it in a persistent connection.
- darkclouds 3y ago> Bonus if you can do some kind of video steganography to transfer the data and have a 'real' call. What you are suggesting would bring the proposed UK Online Safety Bill (OSB) into operation, and by virtue of the encoding/stenography means that GCHQ govt code crackers will be involved in what would be classed Police matters, not govt regulator aka OfCom matters, despite the UK govt suggesting its just a function of the regulator. The OSB also reads like it will extend beyond borders, simply on the grounds that it could be used in the UK.
- archo 3y agoSnowflake (software) : https://en.wikipedia.org/wiki/Snowflake_(software) https://en.wikipedia.org/wiki/Snowflake_(software) Tor (network) : https://en.wikipedia.org/wiki/Tor_(network) https://en.wikipedia.org/wiki/Tor_(network) The Tor Project : https://en.wikipedia.org/wiki/The_Tor_Project https://en.wikipedia.org/wiki/The_Tor_Project
- Egrodo 3y agoNot sure how new this is but very cool that users can host a node simply by toggling an iframe or installing a browser extension. I wonder if these methods have much lower bandwidth limitations than the CLI version
- anyfactor 3y ago> If you switch on the Snowflake below and leave the browser tab open, a user can connect through your new proxy! I am not even sure, if I am getting this right. If I embed an iframe in my website, traffic from Tor users will get tunneled through my user visitor's IP? How does consent works with relay.love? Does my website vistor's IP show up as TOR exit node?
- worldofmatthew 3y agoIt not an exit. But by default someone has to knowingly run the Snowflake applet but webmasters could modify the code to automatically essentially start a Tor guard in someones browser. Though, that would be very evil to abuse someones resources like that. That example has the users consent before starting.
- KRAKRISMOTT 3y agoThat's already how many shady VPN software work. Remember if a VPN is "free", you are the product. Web scraping companies pay $$$$ for residential and mobile IPs.
- drusepth 3y agoFriendly reminder that it's not just free VPNs that sell your data; many of the paid VPNs do also.
- Fnoord 3y agoYeah, those proprietary VPN apps. "If you don't control the routing, you're being routed." To be fair, ProtonVPN allows you to export their config. It seems to be an exception to your rule.
- bebop404 3y agoYes, but running a Snowflake doesn't expose your IP to the website being visited, and therefore you're safe from abuse complaints/prosecution, unlike the people who run the exit nodes.
- deleted 3y ago
- batch12 3y agoIf Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.
- gary_0 3y agoThey could block Snowflakes with IPs from networks in unsafe countries, but that is trivially bypassed by the attacker just buying VPSs (or botnet nodes) in a freer country. Skimming the Technical Overview[0], I don't see anything about mitigating the risks you mention. The purpose of Snowflake seems to be to circumvent blocking of Tor, not to prevent detection of using Tor. It takes advantage of "Domain Fronting" and WebRTC to accomplish this. [0] https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/wikis/Technical%20Overview https://gitlab.torproject.org/tpo/anti-censorship/pluggable-...
- heresie-dabord 3y ago> that is trivially bypassed by the attacker just buying VPSs (or botnet nodes) in a freer country A.K.A. "living off the economic land"
- throwaway290 3y ago"Just" don't connect from an IP that can be tied back to you, use black market sim in a separate phone, connect from places you don't go, turn it off when not in use... It gets expensive fast...
- petesergeant 3y ago> use black market sim in a separate phone In most countries this takes you from “may have committed a crime” to “have actually committed a crime”
- throwaway290 3y ago
- bauruine 3y agoThere is also a standalone (go) version [0] that can be deployed on a server. "one of the main advantages of standalone Snowflake proxies is that they can be installed on servers and offer a higher bandwidth and more reliable option for users behind restrictive NATs and firewalls." [0] https://community.torproject.org/relay/setup/snowflake/standalone/ https://community.torproject.org/relay/setup/snowflake/stand...
- deleted 3y ago[deleted]
- jdthedisciple 3y agoWhat's my incentive to run a snowflake node?
- costco 3y agoWhat’s the incentive to donate to charity? There’s no risk to you because it’s not an exit node.
- jdthedisciple 3y agoThe difference being that a donation is one-off. Running a node is continuous.
- bauruine 3y agoYou can also do recurring donations. Running a Snowflake proxy is basically free if you don't pay for internet traffic so it's a very cheap and low work way to help censored people.
- orthecreedence 3y agoWhat's the inentive?? Try the ALL NEW TORBUX!! A new ERC20 token with only an 80% pre-mine used to incentivise the participation in the Tor network! Now instead of giving back to a community you derive benefit from, you can pervert the relationship with monetary rewards that benefit an elite class who are planning on disappearing to the Cayman Islands after extracting enough wealth from you and your peers!
- mike_d 3y agoSnowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear that countries like Iran and China would just block all of AWS. 1. https://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wiki/Domain_fronting 2. https://azure.microsoft.com/en-us/updates/generally-available-block-domain-fronting-behavior-on-newly-created-customer-resources/ https://azure.microsoft.com/en-us/updates/generally-availabl... 3. https://signal.org/blog/looking-back-on-the-front/ https://signal.org/blog/looking-back-on-the-front/
- cubefox 3y ago> The technique is heavily used by bad actors Evidence?
- broupannoiffuto 3y agoIt's in the OSEP course. :)
- mike_d 3y agohttps://attack.mitre.org/techniques/T1090/004/ https://attack.mitre.org/techniques/T1090/004/
- tialaramex 3y agoWhen I last looked, the intent was that eventually ECH endpoints offer the same effective service that you got with Domain Fronting, but without messing with the backend in a way which is disruptive for the cloud providers so they support it. Encrypted Client Hello is the in-progress work to have even the client's initial contact to an HTTPS server be encrypted. https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ Why would ECH be fine when Domain Fronting isn't? The problem with Domain Fronting is that we get surprised too late with the actual request. We get what appears to be a legitimate request for this-thing.example, so we do all the work to respond to a this-thing.example request and then... swerve, sorry I changed my mind, my request is actually about hidden-service.example. With ECH we (but not an adversary snooping the connection) know immediately that the request is for hidden-service.example and so we don't waste our time setting up for the wrong work.
- rejectfinite 3y agoI have it installed and like seeing the number go up. NUMBER BIGGER = DOPAMINE!! I'm lucky to be born in Scandinavia, so there is really 0 internet censor, for now.
- Kjeldahl 3y agoYou're just lucky YOU aren't affected yet. Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Or to any of the people who made money on crypto who they want to use as security for an appartment loan. Or to someone trying to wire gains from legal online casinos abroad. Or to someone trying to access a web site that the norwegian authorities do not like who are DNS blocked (yes, easy to circumvent for tech people). Goverment and politicians abusing authority and limiting individual freedom is already here and growing. When it starts affecting "most people" it is usually a lot harder to reverse. The norwegian goverment already passed a law that allow mass electronic surveilance. And they want to limit the public's access to goverment records. It's a very slippery slope, left side "social democrazy" (spelled "beuracratic dictatorship") like most of EU. People need to open their eyes and fight goverment overreach now.
- rejectfinite 3y agoMy 2c on your scenarios. >Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Probably blocked due to terror laws. If you can't Western Union money, there is a REALLY good reason. Wait until you hear about how we are a cashless society and our bank app for money transfer. That you need mobile ID and bank account to use :) Max tracking. But its very handy. >Or to any of the people who made money on crypto who they want to use as security for an appartment loan. Good, I hate crypto shit and I want it to go away. It is all a scam. Get a real job and invest in a real bank. Crypto is all tax fraud scam shit. >Or to someone trying to wire gains from legal online casinos abroad. Good, I hate gambling and online casinos. If you have to gamble, do it in my country so the taxes benefit. >Or to someone trying to access a web site that the norwegian authorities do not like who are DNS blocked (yes, easy to circumvent for tech people). Yes THIS I agree with. I think ISP DNS blocks piratebay etc here now. Or some ISPs do. It's shit, but I already use a 3rd party DNS provider on my PC and phones. Your point btw? I am running the Snowflake when my browser is open.
- PathfinderBot 3y agoI'm surprised by how easy and literally one-click it was to use that. Bravo, Tor Project team.
- Aachen 3y agoThis is a relay for Tor users to be able to access Tor (when normal guard relays (first hop in a Tor circuit) are blocked), using domain fronting and webrtc. The text is written quite confusingly, at least the German translation it served me by default. I was wondering how this could circumvent censorship, as the target needs to also support webrtc so there's no way to access any http(s) website via this in-browser proxy, this still requires another server to accept the webrtc connection and forward your traffic, but the point (which the article doesn't mention) is to be able to connect to this other server indirectly. It even goes so far as to claim that you don't need any software to visit censored websites: > Im Gegensatz zu VPNs musst du keine separate Anwendung installieren, um dich mit einem Snowflake-Proxy zu verbinden und die Zensur zu umgehen. Except you do. Without Tor client, this snowflake proxy is useless. Clicking through to the technical details (link marked with a warning "this content is in English"): > 1. User in the filtered region wishes to access the free and open internet. They open Tor Browser, selecting snowflake as the Pluggable Transport. The article said "contrary to VPNs, you don't need to install separate software to circumvent censorship" and the technical overview says the literal opposite: you need to install a Tor client to make use of a snowflake proxy.
- tga_d 3y agoI can't speak to the German translation, but the point the English version is making is you don't install Snowflake, you install software that uses Snowflake (most typically, Tor Browser). It's presumably trying to clarify things for confused users trying to figure out how to install Snowflake as a proxy or VPN application, when that's not how it works. edit to add the direct quote (which seems pretty clear to me): "Unlike VPNs, you do not need to install a separate application to connect to a Snowflake proxy and bypass censorship. It is usually a circumvention feature embedded within existing apps."
- VWWHFSfQ 3y agoWe block every Tor IP we can find because we don't have the time nor patience to deal with the 99% burpsuite spam originating from these servers. Very cheap and effective solution.
- bauruine 3y agoHow do you "find" them? You can just download the list with all exit node IPs. https://check.torproject.org/torbulkexitlist https://check.torproject.org/torbulkexitlist