Skip to content

Comment on Tinfoil Chat – Onion-routed, endpoint secure messaging systemparent

Comments

Nice to see you again Nick P!

Yes the use of Tor Onion Services is a brand new thing and something I've been working since the fall of 2017. Piggy-backing on Pidgin was always a temporary solution: The Snowden documents and Hayden's comment on killing people based on metadata made it clear something that's anonymous by default was the way to go.

Ricochet was the biggest influencer, and after I asked about OnionShare's (that's also written on Python) Tor connectivity, Micah Lee kindly pointed me to the direction of Stem. Stem's author Damian Johnson and other members of Tor Project were really helpful and I can't thank them enough. (Note that they have not vetted the implementation in any way!)

I initially implemented v2 onions and stealth authorization but with the announcement of prop224 and next gen (v3) onions I decided to wait. While working on that, new primitives were being implemented to the libraries TFC uses. So in the end, TFC got v3 onions, X448 and XChaCha20-Poly1305 at the same time which was a nice improvement.

"At best, attackers would keep trying to disrupt or brick the receiver and network components."

DoS is indeed one of the unsolvable problems. The hope with the (now) anonymous installation and use, as well as the support for Tails on Networked Computer (still waiting for Tails 4.0), make it harder to disrupt users on targeted basis. I've worked hard to ensure Relay Program on Networked Computer doesn't need to know anything about the user or their contacts, and with Tails, ideally the OS doesn't contain anything that could be used to identify the user.

You too, buddy. I've been here and on Lobste.rs mostly. All my CompSci papers are in my Lobsters stories if you want to check those out.

" The Snowden documents and Hayden's comment on killing people based on metadata made it clear something that's anonymous by default was the way to go."

Definitely a concern. Definitely should be an option. Just gotta remind you that the NSA and some other groups automatically classify people using Tor as folks to watch. Whereas, HTTPS at McDonald's WiFi doesn't get that designation. Avoiding Tor can help you avoid getting noticed in the first place. Depends on user's threat model. So, make sure it supports ability to not use Tor even if Tor is default.

"and after I asked about OnionShare's (that's also written on Python) Tor connectivity, Micah Lee kindly pointed me to the direction of Stem. Stem's author Damian Johnson and other members of Tor Project were really helpful and I can't thank them enough."

Sounds like how OSS development and communities are supposed to work! :)

"DoS is indeed one of the unsolvable problems."

Good thinking so far. For non-anonymous routes, perhaps investigate some setup that operates behind Cloudfare to get their DDOS resistance. They just become an extension of the untrusted, network component. Could make that part modular so users can swap out the service provider or even use their own anti-DDOS appliances in data center with big pipes. It's just hard to beat the big, centralized providers since vast majority of solving DDOS is huge pipes and the right hardware/software for detection.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.