social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

478
active users

#OnionServices

2 posts2 participants0 posts today

Before the media fixated on dark web crime stories, .onion services were a refuge for those who valued privacy, free speech, and anonymity. Early adopters of Tor used it to host personal blogs, distribute banned literature, share research in repressive regions, and build decentralized forums where users could speak without surveillance. Activists, journalists, and whistleblowers relied on hidden services to communicate and collaborate safely. It was never about profit. It was about principle. The darknet wasn't born for crime. It was born for freedom.

Replied in thread

@koenvh #FunFact: THIS is actually real when it comes to #OnionServices on #Tor / @torproject despite (or rather because of) having a self-routing and self-administrating, self-authentificating namespace utilizing #Pubkeys for addressing.

Mine merely covers a few #BonaFide ones and there are literal #scam businesses when it comes to the kinds of sites I won't name nor list!

GitHubreal-world-onion-sites/master.csv at master · alecmuffett/real-world-onion-sitesThis is a list of substantial, commercial-or-social-good mainstream websites which provide onion services. - alecmuffett/real-world-onion-sites
Replied in thread

@cadey My thoughts on #Anubis after encountering it multiple times as a user:
* mascot is nice, creative and intuitive to understand
* as a user of tor it works! cloudflare and others reject me as a bot, but anubis left me through, thank you
* onion services do not require anubis protection, though, right? Since they have their own proof of work system integrated by default …
blog.torproject.org/introducin

… equi-x function based on what Tor uses?
pony.social/@cadey/11423626384

blog.torproject.orgIntroducing Proof-of-Work Defense for Onion Services | Tor ProjectToday, we are officially introducing a proof-of-work (PoW) defense for onion services designed to prioritize verified network traffic as a deterrent against denial of service (DoS) attacks with the release of Tor 0.4.8.
Replied in thread

@max
To quote you directly:

"[...] easy to use solutions that are at the same time private and secure. [...]"

It is easier, faster, cheaper and overall simpler to get someone setup with #XMPP + #OMEMO espechally if they don't have a #PhoneNumber and/or #ID to acquire a #SIM.

And if you go and say, "Just buy a [insert country here] [e]SIM!" and expect #TechIlliterates without a #CreditCard, #PayPal or other means of #OnlinePayment to fiddle around with some #eSIM if not having to get some #eSIMcard because they can only afford to maintain one SIM and can't spend triple-digits on a new devices then you completely missed the point!

It's not that I expect anyone to get #TechLiterate within minutes, but similar to setting up a cordless DECT phone it's something one has to do once in 5 years and just have them put the password in a safe spot to retain...

Point is that #Signal #WontFix their setup and that was evidently clear even before @Mer__edith succeeded #MoxieMarlinspike: Their entire operation has a distinct #CryptoAG stench as it's an #unsustainable #VCmoneyBurning party!

A counterexample on how this could've been done are #Tor, #eMail and other truly #OpenSource as in #MultiVendor & #MultiProvider standards.

Whereas it's trivial to get people setup on one of many XMPP servers I've personally tested!

AFAIK Signal doesn't even have an #OnionService / .onion for their Website, much less any #API enpoints to use it with!

You're free to also provide evidence and supporting data to your arguments, rather then neighsaying against proven to be more secure and reliable [by virtue of decentralization] options like XMPP+OMEMO and/or #PGP/MIME.

The proper fix is to actually assess the situation and acknowledge the risks and limitations as well as the very nature of communications, which means upgrading later is exponentially more painful, thus getting people properly setup once is way easier.

  • Just because WE [ or rather @rysiek in this case ] rather privilegued enough to not be hatecrimed in their current location doesn't mean this is the case for everyone. And having places like Signal rely on a "#CDN" is just another red flag to me because questions like this one just don't arise with monocles.chat as people can just exercise proper #SelfCustody and just use Tor!

Speaking of #monocles: That business is at least #sustainable because it's funded by users (€2 p.m.) which they can pay anonymously

gruene.socialMax L. (@max@gruene.social)@kkarhan@infosec.space Sorry but no, the correct solution is to push for easy to use solutions that are at the same time private and secure. Hiding privacy and security behind a veil of "you need to know" is discrimination of people that are not able (either mentally, physically or monetary) to gain that knowledge. The correct move here is for @signalapp@mastodon.world and any other service to fix this and for legislators to enact laws enforcing proper security and privacy by design.
Replied in thread

@ploum instead of @signalapp which also falls under #CloudAct and is also a #Proprietary, #SingleVendor & #SingleProvider solution, consider #XMPP+#OMEMO for real #E2EE with #SelfCustody of all the keys!

#email#chat#ads

#TorProject State of the Onion

inv.nadeko.net/watch?v=EODNtLq [perfect example, G de-onions]

onionmobile.dev #GuardianProject

hushline.app

github.com/blueprint-freespeec

53:16 - #InternetArchive , web.archive.org/
Access to information--and the preservation of it--otherwise difficult to obtain without a congressional staff and the library of congress. #ALibraryNotTheft

youtube.com/watch?v=HjPdReNmf_
#TAILS
6:00 - partition checking (data integrity)
#Onionspray - facilitate making existing websites onion addressed! 15:00 making the addressing human accessible
18:51 - #Vanguards and #Arti
28:00 "conflux" congestion control
[...a whole lot of the internet doesn't work with Vanguards if it even did work with tor in the first place..]
#OnionServices
29:29 - Network Health
#Censorship
45:00 - webtunnel transport

Continued thread

In case you don't know, @cwtch is a decentralized end to end encrypted chat app

there's no servers by default, meaning no central authority

transport is based completely on Tor onion services, which itself is decentralized and provides automatic and transparent end to end encryption

(though @torproject still hasn't deployed any post-quantum cryptography into Tor, Cwtch is not as robust as newer PQ Signal or iMessage)

the profile ID that you share with your people is based on the Tor onion address that your profile is using for communications. if you shut down Cwtch, your Tor onion address also gets shut down, so you can't receive messages while you're offline, by default

it's my opinion that using Tor onion services for chat apps is a no-brainer. everyone with a Cwtch profile is both a client and a server. you are your own server. because of how Tor onion services works, as a reverse proxy, you don't need to host a "public" service on the internet. and e2ee, key management, encryption is all automatic. you can't fuck it up! its crazy to me that apps like Matrix don't take advantage of this. Tor onion services is an extremely powerful tool and so many people ignore or think of FUD

Replied in thread

@cryptoparty +9001%

Außerdem geht es darum #Massenüberwachung so kostenintensiv und unrealistisch wie möglich zu machen...

Hier muss die doppelte*" Aggression"* geliefert werden die #Cyberfaschisten uns #Polizeistaat-Fans an den Tag legen!

Replied in thread

@dw_innovation okay, maybe not the answer I hoped for given that this means manually dropping security in @torproject / #TorBrowser.

  • Still I'm not completely sketched out by that given #DWnews reputation, but I know this could he done better, as various websites and even stores and forums as #OnionServices showcase...

Given upcoming #accessibility requirements in #Germany I'm convinced cross-testing with #LynxBrowser over #Tor will likely be one of those things that'll necessitate changing that.

  • A potential workaround is to use an "accessibility proxy" like @ActionRetro 's #FrogFind ¹ which already comes in handy on extreme narrowband connections like #Iridium ²...
www.youtube.com - YouTubeAuf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.