Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm curious if people would use exit nodes which specifically blocked comment submission on sites. I use Tor frequently, but never for posting comments.


It's an interesting proposal, that perhaps the things that degrade the reputation of Tor nodes could be blocked by Tor nodes.

Not just comment spam, but to have the equivalent of mod_security be run over an exit node and to deny traffic that triggers it.

This wouldn't reduce privacy/anonymity, but would avoid the IP address from having its reputation damaged (in turn enhancing privacy/anonymity as the exit nodes can be protected and thus prove more useful to good users).


Yeah, we already see this with exit nodes having "cautious" policies about not allowing ssh, smtp, etc.

Being able to advertise some kind of filtered outbound on specific higher-risk traffic types so you can offer those at all might be nice. I'd have no problem offering ssh to an opt-in whitelist of destinations.


Exactly... Tor nodes that don't just let anything through, but do let "safe" (to some agreed definition) web traffic through. Then a client could say "only exit via safe nodes" and you'd have this much better chance that the exit hadn't been used for the nefarious purposes that were likely to have resulted in an IP being blocked or challenged.

I get what you said in the earlier comment, but it sounds like CF would run a node and people would need to connect to it. I'm not sure of the implementation details, but either that's only a single hop through Tor (thus reducing the privacy/anonymity), or you're still making a single entry/exit point be the focus of all traffic from a given user (reducing privacy/anonymity by creating a single target for state attacks - likely court order based).

There's got to be a way to keep the multi-hop high-privacy and high-anonymity for those who need it, without having those users treated the same as those using Tor to hide various attacks (spam, the kind of attacks the CF WAF mitigates the risk of, etc).

I think this idea of Tor nodes that are trusted to have implemented various policies, and that only exit traffic that has filtered out attacks (and obvious spam), kinda works. By protecting the IP reputation of the exit node, we get a Tor that isn't being penalised and affecting the end user experience and that doesn't reduce the privacy/anonymity stuff that is important.


I didn't mean for CF to run a Tor node (I'd be in favor of that, but I wouldn't want to run a lot of them, although having all traffic destined for cf go through special Tor infrastructure on top of everything else in a normal Tor session would be fine).

I just meant for anyone running Tor exit nodes -- it would be cool if those people could configure some kind of filter on their exit node to do this filtering.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: