TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WebTunnel

85 pointsby soheilproabout 1 year ago

4 comments

mike_dabout 1 year ago
The big win here is co-locating tunnels on existing domains with real websites. If anyone has a site that would be willing to host a tunnel but doesn&#x27;t want to run a full tor bridge, email me (in my profile) and I can help you configure your server to forward traffic to my bridge.<p>If you want to setup your own details are here: <a href="https:&#x2F;&#x2F;community.torproject.org&#x2F;relay&#x2F;setup&#x2F;webtunnel&#x2F;" rel="nofollow">https:&#x2F;&#x2F;community.torproject.org&#x2F;relay&#x2F;setup&#x2F;webtunnel&#x2F;</a>
chatmastaabout 1 year ago
Does this mean that, in theory, if you could compile the Tor library to WebAssembly then you could use it from inside a service worker in the browser?
评论 #39686041 未加载
s4mw1seabout 1 year ago
I’m an AppSec Engineer that works primarily on WebApps in eCommerce and none of this feels right to me.<p>I became very skeptical of the Tor project when I found out that the CEO of CMYRU (data broker &#x2F;threat intelligence for governments and large corporations) was on the Tor board.<p><a href="https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;z34jbj&#x2F;tor-projects-moves-away-from-team-cymru-infrastructure" rel="nofollow">https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;z34jbj&#x2F;tor-projects-moves-aw...</a><p>Privacy was incredibly hard 10 years ago, even harder 5 years ago, and it’s twice as hard today.<p>All of the sudden a solution comes out that makes it easier using what? Modern day web apps and browsers? The things that are like pulling teeth out of a pit bull to secure unless everything was diligently threat modeled from start to finish before a line of code was written?<p>If anyone has ever had the need to hide their IP address and be anonymous. It’s a real pain in the ass and takes a lot more OpSec then just using Tor.<p>This seems like it’s just opening the door for MITM attacks between the web app and the tunnel.
评论 #39688656 未加载
评论 #39687383 未加载
etskinnerabout 1 year ago
Couldn&#x27;t authoritarian regimes still block a blacklist of SSL certs, since those are sniffable? Or block the public list of bridge addresses?
评论 #39686114 未加载
评论 #39689426 未加载