New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
@ProHosting24 Tor relay allow ?
Its the weekend! Are we getting some VPS restocked or what?
hmm... changed my mind
In germany? Nein!
https://browzr.medium.com/i-got-caught-downloading-movies-in-germany-what-should-i-do-49f0ed40b1be
unfortunately both use cases are rather a bad fit with us, as they tend to generate abuse reports which we act upon
i have restocked 5 of each!
should last long enough as the deal cooled down now probably
Here for the giveaway.
Flash L is gone again, but could I stack a Flash L + Flash M to one machine with 28GB RAM and 500GB NVMe?
Okay, if it’s not an exit node, could you clarify what the concern would be? A middle relay only passes encrypted Tor traffic between other relays and does not make the relay operator the source of the traffic reaching the destination.
Middle relays also don’t directly expose the destination traffic to the operator.
If there’s a specific concern with operating a middle relay on your infrastructure, please let us know so we can address it.
In that case the only concern would be filling up the traffic commitment for a use case that no one earns money with and making the traffic budget more tight for the whole customer base.
As long as our commitments aren't full we don't care if someone generates 20 instead of 10tb of traffic once in a while. If all customers start to tun relay nodes just because they can and or because they have a vps running anyway, then this will cause either higher expenses for us or less toleration for customers with higher traffic needs then usual.
This is an interesting topic to discuss actually, this forum has a good understanding about why it would be a bad idea to rent a vps for a couple of bucks and then provide the whole cpu power to folding@home, crypto mining or other blockchain workloads. But the expenses and calculations behind traffic are less transparent and easy to grasp.
We are probably going to offer traffic flat upgrades soon which would allow you to eg fully utilize 1gbps 24/7 for idk 500 or 1000 bucks per month. I dont have the exact numbers on my head.
But to finalize my message, as long as you don't get abuse reports and don't stand out with +10tb traffic a month no one at prohosting24 will care for the relay node.
i added some again
Traffic use can be configured in
torrc, since by default it'll easily use > 10 TB/month. Assuming it's metered in+out:That'll guarantee it doesn't pass more than 10 TB/month (5 in each direction).
Though there are already a lot of relays in Germany on the network, so it's best to diversify and use other locations.
probably most at hetzner?
can't imagine how many of them must be operated by state actors
Most on OVH and Hetzner, yeah.
The majority are actually operated by well-known and trusted operators, but unfortunately that doesn't mean that nation states can't tap OVH and Hetzner (or any major ASes that most traffic in Germany goes through). That's the real risk, not malicious nodes. It's why I run relays in diverse jurisdictions.
And don't forget, Hetzner has been caught doing MITMs: https://notes.valdikss.org.ru/jabber.ru-mitm/
yes that was a crazy thing back then. i can tell from my personal experience that intelligence services are walking in and out german datacenters even with whole surveillance infrastructure onsite being colocated between customer racks and machines.
can't imagine what autocratic states must be doing to their companies and residents data without people knowing/reporting about it
Yep it's absolutely insane. Thankfully Tor does use some padding which gives it some good resistance against monitoring, but it can only do so much. And even if you avoid a monitored datacenter or provider, you can't avoid its upstreams being in one of them. People don't realize just how bad it is.
Netherlands is better in that regard but not by much. It'll probably get worse due to how much international traffic passes through Amsterdam, so it's a juicy target for monitoring. We definitely need more decentralized routing.
That's why I always laugh at Swiss VPNs, because all their traffic will go through the same NL and DE datacenters anyway.
at the end of the day i am happy to live in germany and not in eg iran or russia, altough i have some russian roots and a prety patriotic family base...
i believe that all states are spying, but in germany at least no one is going to cut of social media access because of elections
everything has its down and upsides, lets just hope the few people in charge don't fuck things up
may i ask why you are investing so much into the tor network?
isn't it enough to be able to connect to a vpn and access the stuff you need?
i saw a lot customers from russia and iran for example that used our services to bypass censorship, none of them participated in eg running a tor node. almost all of them were running some crazy new vpn protocols based on idk icmp or dns and other things. same as chinese customers
idk i just think its weird to support a network where a lot crude and criminal stuff is going on when i see that most legitimate users are getting it done easier and maybe also just more straightforward?
A lot of people need more than just a VPN, since historically and even today, VPN traffic has been traced. It's good enough for getting around basic censorship, but not much else. And even VPN companies that don't log can still trace connections. After all, promising not to log doesn't mean promising not to correlate an existing, live connection. It just means they can't do it retroactively. And while some argue that it's good for law enforcement to be able to order "logless" VPNs to trace a connection... https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/
I personally invest so much because I want to help the average person, the kind of person who can't afford to spend time to learn OPSEC and collect information about digital privacy. The kind of person who doesn't necessarily live and breathe anonymity but may occasionally have a need for it. You and I are obviously tech-savvy, but most people's tech-savvyness goes only so far as installing one or two tools. Tor just happens to be a tool that is designed to be as foolproof as possible.
I seem to recall one study showed over 90% was broadly legal, with the majority of illegal traffic being fraud/scams or simple copyright infringement. That was a while ago so I'm sure the numbers are different now. But there are more illegal hacking communities on .com sites than .onion sites. There's more illegal pornography on eD2k than Tor. There's more spam going through VPNs and proxies than Tor, etc.
The way I see it is that Tor levels the playing field. It gives regular people privacy and anonymity that previously was only available to criminals for the simple reason that criminals are willing to use unethical means to achieve their privacy. If Tor is taken away, people who cannot afford good VPNs or who don't have the technical knowledge to set up V2Ray on their own infrastructure lose out, but criminals will simply switch to other resources such as proxies made from botnets.
The average person who wants anonymity is not willing to extort someone into sending a message or to buy a proxy from a botnet. The average person isn't so invested in privacy that they'll set up underground communities like criminals will, and they wont spend time learning to be safe like criminals do. If there was no Tor (or technologies like it), criminals would be briefly and mildly inconvenienced, but the average person loses one of their few means of strong privacy and anonymity.
Thanks for the insights, sounds pretty cool actually.
I personally am a huge fan of running things just locally or completely isolated from the internet.
For working with friends and colleagues a local matrix server with a fancy client has no disadvantages against established stuff like discord.
I am also a fan of doing things more private but for other reasons, mainly being security and data privacy regulation. Imagine a leak at discord with recorded screen shares from the admin view of your customers X.x
But people tend to get pretty sloppy nowadays, some years ago people started noticing how bad it actually is to just pipe shell scripts into your bash and now the same people let openai and antrophic basically takeover their machines without questioning it, a crazy development if you ask me
Btw i really enjoy reading your posts in the other threads and stuff, @rpqu also seems to be a pretty active and cool member of the LET community. We need more people like you two
It's only because I've thought a lot about this that I invest so much money and effort into it! (Edited my previous message a bit too, adding some details).
And piping curl to bash is making an awful comeback... I just looked up how to install ollama-cli and the first installation recommendation was to pipe their installer to bash. So I downloaded it and read it, and within the script itself it does the same thing in several places! So I ended up just compiling it manually. Sadly lots of self-hosted frameworks seem to recommend piping curl to bash. And everyone posting their YABS, of course...
Meanwhile I keep saying HTTPS isn't enough and we need digital signatures for installations and updates. Of course, then Virtualizor gets hacked due to a malicious update because, of course, they didn't sign their updates and relied on HTTPS!
Thank you!
I mean thank you, I even got one Flash L last time. Would have gotten another one and stacked it to one massive VM with 36GB RAM and 600gb NVMe if that was possible?
i am sorry, but this is rather not wanted.
at some point those machines really do get to big and will be used more like cheap dedicated servers instead of being used like a vps for some easy 0815 workload
so stacking is not supported unfortunately
Ok fair enough I guess and you got me here as I kind of would have used it like a cheap dedi too. At least I would have saved some admin compared to running stuff on several machines. Thank you.
Interesting conversation, thanks @ProHosting24 and @forest
GLWS