If you're in school, though, then it's even worse. No matter what country you're in, chances are that your access to the internets is as snooped-on as any police state in the world.
So, how do we escape our little virtual prisons? In this Instructable, I'll tell you about something called Tor (The Onion Router.) I'll tell you how it works, and then offer some simple instructions on how to get your web browser hooked up. No more getting snooped!
Remove these ads by
Signing UpStep 1: How Tor Works
Tor works because the school has a finite blacklist of naughty addresses we aren’t to visit, and the addresses of the nodes change all the time—no way could the school keep track of them all.
There's a more complete overview, here, but let's get on to installing Tor.








































Visit Our Store »
Go Pro Today »




The TOR network works by channeling your data through a chain of highly encrypted SSH proxy tunnels, a so called "proxy chain".
If you visit, for example, this link: http://www.google.com/search?hl=en&q=paris+hilton, your request will be encrypted and tunnelled to another TOR user, then another, then another and so on. Your data could be passed around 20 times. The other TOR users cannot see the link you typed in (as it is encrypted). This sounds very very secure.
However, the data has the be decrypted again before google can understand what you searched for. In order to do this, the last TOR user in a proxy chain is called an "exit node". The exit node decrypts the data, contacts google for your results, encrypts the results and sends them back through the chain to you.
Sound secure so far? Well, actually, it does.
But what happens if the exit node runs a packet sniffer (like Wireshark) on their computer to monitor outgoing network connections? The url you typed in appears in plain text on their screen. They don't know who you are, but they saw what you did.
I hear you ask; "So what? - I don't care if a random Ukranian sees that I searched for 'Paris Hilton'." True. Most random Ukranians won't care at all if you searched for Paris Hilton. In fact, they may enjoy calling up the same link you searched for. But what about if you had been reading your hotmail email instead? - They get to see what you typed and to who you sent it.
The problem gets even worse if you start channeling E-Mail and Instant messenger programs through TOR. The POP3 E-Mail protocol sends usernames and passwords in PLAIN TEXT to the mail server. This means, that an exit node could sniff outgoing traffic and steal your email account. - They could then probably go to Paypal.com and request that your password be sent to your registered email address. The would then steal your Paypal information directly from your email account. - Is it sounding very secure now? Bye bye money.
But that isn't all... Some exit nodes act as bridges between you and the website you want to access, altering the data before it is send back to you. e.g. They could change all references to the name, "Paris Hilton" into "Bill Gates". - All of a sudden, you aren't looking at the innocent pictures you intended.
Even worse: It is possible for exit nodes to dynamically swap out SSL certificates of secure websites. If you called up https://www.myreallysecurebank.com over TOR, you might be sent back an SSL certificate which doesn't actually belong to your bank. - This would mean that your login details for your online banking are also visible to the exit node. - Bye bye money, again.
Sorry to rant on, but this should really be known before anyone tries to use the TOR network.
I am not saying TOR is bad - but don't ever consider sending anything personal over it or you might end up with less security than you bargained for.
Thanks
Dave from Germany.
It does protect you against determination of your location by the Internet sites you visit, and against traffic analysis -- inspection of your destinations by a person looking at your computer's link. It can get your communications through a hostile filter or firewall, because it encrypts the links from your computer to the Tor entry node, and at all points between there and the exit (3 hops, if you haven't changed configuration).
If you want to communicate securely, you should still use encryption direct to your destination (https), and you should heed browser warnings if the SSL security certificates don't match.
I am a random Ukrainian (in US) but I will snoop your packets, no doubt, no doubt at all.
TOR users - you have been warned.
Sincerely,
Random Ukrainian - Thorax Impailor
you have to use TOR to view this
or in a regular browser do this https://7jguhsfwruviatqe.onion.to/index.php/Main_Page
this is through a proxy. whatever you do on the wiki please be careful with what you click on because there is a lot of CP on deepweb
And it's linked from the ebook version straight from Doctorow's site, so I think he knows and is cool with it.