Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you really have to trust Mozilla here someone is doing something wrong.

Presumably these hosts will be part of a relay family and so tor will not select multiple of them in constructing a circuit.

When it comes down to it no matter how trustworthy mozilla has been in the past, any service they offer could be compromised going forward in a multitude of ways. This is why its important that systems and software be designed to be secure even without trust. (Then, add in some trust for good measure too).



in an ideal world, yes, we should require 0 trust; i don't think we well ever live in that world, it is prohibitively expensive and impractical.


trust is always a fun topic, as people are still unaware of how much stuff they trust today.

Let's say you trust TOR. Great.

Now you have to trust Mozilla's software if thats what you run. Let's say you trust Mozilla too, great.

Now you have to trust your whole OS. Lets say you do that. Great.

Now you have to trust the various devices connected to your computer. Lets say you trust that too. Great.

Now you have to trust the various companies that made all the various chips on your main bus, CPU. And the RAM and many other components. And don't forget the dynamically loadable firmwares running on them.

Good luck with that!

[note: this might have needed to be a reply to the parent post]


At least Mozilla doesn't have a 'business model' which is strongly dependant on you handing your data over to them, or other opaque/closed activities or software.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: