Comment by nullc
4 months ago
Any thoughts about direct lan/vpn communications as an option? The use of tor makes a working high quality internet connection a requirement, and potentially makes it more attractive for attackers to DOS attack tor in order to make their targets move off Cwtch and onto less secure communications methods.
It is something we get asked about fairly frequently, its not a high priority for us right now as it requires some thought as to not break or undermine any existing cryptographic/privacy properties that Cwtch does have (see: https://git.openprivacy.ca/cwtch.im/cwtch-ui/issues/461#issu...) - but it's also not something that we have ruled out if the right combination of design/effort is available.
Tor is important for metadata resistance.
Right but on a local network the attacker likely has no surveillance -- and if they do you probably have worse problems.
And because Tor is relatively vulnerable to DOS attack, an attacker can force users off of it and likely on to more vulnerable communications methods.
Tor also has its own vulnerable to traffic analysis which is quite significant. So I think for most users if you can satisfy communications you'd probably prefer it... Though I suppose I could argue it both ways.
> Tor also has its own vulnerable to traffic analysis which is quite significant.
[citation needed]
Here's a contrary one https://www.theguardian.com/world/interactive/2013/oct/04/to...
1 reply →