Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why couldn't Firefox use Tor in the "private mode"? Wouldn't that be the ultimate private mode? It would also greatly help the Tor community, as it would "mainstream Tor" so it wouldn't have as much stigma as it does today.


Because that's not safe. Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs. That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing.

Also, the Tor network probably doesn't have enough exit node capacity to handle the volume it would get.


Not to mention non-technical users will be confused and complain how slow it would become.


Especially this since most users of private browsing are probably streaming video content.


> Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs.

This is no different from your ISP or the guy next to you on the coffee shop wireless.

If you don't want people to snoop and rewrite your HTTP connection, don't use HTTP. And the solution to broken HTTPS is to fix HTTPS. Tor doesn't decrease your security in either of these cases.

> That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing.

1. It's not a tradeoff. Tor does not decrease your security in either case. There are cases where Tor doesn't provide privacy protections, but there's not a case I know of where using Tor provides fewer protections than not using Tor.

2. It's impossible to convey to non-technical users that private browsing doesn't provide privacy from their ISP, governments, etc. I don't understand how you can claim that providing fewer privacy protections is less confusing to the non-technical user.

> Also, the Tor network probably doesn't have enough exit node capacity to handle the volume it would get.

This is a solvable problem.


> This is no different from your ISP or the guy next to you on the coffee shop wireless.

You're a paying customer of your ISP and they're bound by the law and your contract.

Tor exit nodes can be anyone, anywhere, who feels like messing up your traffic.


Also some desired endpoints might drop/mess with your traffic simply because it came from a tor exit.


These are bogus arguments that sound reasonable in the absence of a relevant comparison but are all flimsy and uninformed upon inspection.

For example, by what definition would this not be 'safe'? Do you mean in comparison to Firefox's defaults, which enable profoundly privacy-invasive tracking, hide the contents of the cookie management dialog box, and enable the delivery of malvertising at will by visiting "safe" websites - just to name a few?

MitM positions exist on the internet for all users today, both for HTTP and in the situation of "new HTTPS bugs". So you point out risks taken when using the internet in general, and the Tor Browser Bundle already mitigates many of those risks via NoScript and various patches. I've used Tor Browser Bundle daily for all purposes - including online banking and shopping - for several years with zero problems. Malicious exits exist and get flagged out of the network rapidly. Essentially all remaining risk is trivially defeated by toggling the 'block all unencrypted requests' pref in HTTPSEverywhere, which is part of the Tor Browser Bundle and could be built into an implementation in Firefox with a warning for HTTP traffic.

And you're probably thinking of 2009-era Tor network experience. For me, Tor network performance routinely boils down to ~200ms additional latency with ~1.5-2MB/s download speeds. The difference between that and an average broadband connection is barely noticeable.

I recommend using the Tor network and the Tor Browser Bundle before criticizing this idea.


Speed for starters (Tor is an order of magnitude slower) and many things, like advanced JavaScript (websockets for example), flash and Java, simply can't traverse it reliably. Also it's not what people expect. Many people expect private mode to make it so their active session's browsing doesn't effect their browsing history or they tracked history, not to anonymize them entirely.


> Tor is an order of magnitude slower

This claim is frequently made but I think I can objectively say (it's not the Tor fan speaking) that it's wrong. Can you back this up with numbers?

Like, real world user's numbers. That means WiFi or 3g, or at best a 100mbps wire to an old WRT54G; not a professional, cabled desktop setup with FTTH or 802.11ac that many of us might use (as professionals or hobbyists). Depending on some luck in the Tor circuit, it should be as good as a good public wifi hotspot. Or in a bad case it might be as bad as an overloaded and far away public hotspot, but circuits rotate now and then anyway.

I'd be genuinely interested to see some user testing in this area, especially if the users know the privacy difference it makes and can toggle it at will.


A quick test I did just now.

Response from google via Tor: 208 ms.

Response from google without: 32 ms.

To be fair I am basically on a trunk line via my university.

I mean you are right though, a domestic WiFi connection is likely to be in the 200 ms range, so another 200 ms on-top of that might not be as big of a deal, but I would suspect it would still end up being closer to 500 ms to get a response. Google made a point where anything over 200 ms feels slow to users. Tor is definitely going to push everything over that.


> a domestic WiFi connection is likely to be in the 200 ms range

My wifi connection gives me ~18ms roundtrip to Google, and about 8ms extra to work, and ~50ms roundtrip from my moms house in Norway where I am currently, via her wifi, to my home server in the UK (and ~18ms roundtrip to Google from here too).

These are nothing special for developed countries - just regular consumer connections. When I've been on business fibre subscriptions we've consistently gotten better results.

EDIT: I initially wrote "maybe 5 years ago", without thinking. Some additional observations: While ~200ms roundtrips to a site was a thing going back long enough, first hop latencies even on dialup was rarely even 100ms. I know: I ran an ISP, and had to deal with irate customer if latency from them to their nearest games servers got to that kind of level, even in the mid 90's.

SSH connection roundtrips start becoming painful in the ~120ms roundtrip range, and it's been a decade plus since that's been a problem other than when managing a slow system on the US west coast or Asia for me (connecting from Europe). Beijing or New Zealand has been in the 200ms+ range for me. If anything closer is in that range, it's a sign something is wrong.


I'm a tor fan (I run a relay) and installed it on my phone, it was objectively much much slower and things like url redirects (from emails etc) wouldn't load, I ended up having to turn it off so often that I effectively abandoned it.

I would like to move to a tor only setup, my biggest issue is that it's just too slow.

Granted I am in Australia so most of my requests were literally going to the other side of the world and then back again to complete.


You're making assumptions on what users use private mode for. I primarily use it for testing login/using alternate accounts without having my cookies set for development work, which means I would not want to be using Tor. Other users may just not want certain pages logged in their browser history.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: