I have some possibly stupid questions about what information is given by a user who is a Snowflake volunteer. Note: I am a rather untechnical person who is occasionally forced to code small things or use command line to make stuff run during work (occasionally involving software only available on linux). Given this background, I apologize for some possibly repetitive or irrelevant material and would like to receive accessible answers. I have also tried to post the questions below to relevant subreddits, but was unable to since I just made a Reddit account and don’t quite understand how to use it.
Recently, I started using the Tor browser frequently and it has been important for doing my work safely without feeling uncomfortable (although my life doesn’t literally depend on it). Aside from this, it was my first experience living in a country where I felt needed to turn the audio off on politically sensitive news (given interactions with neighbors and state actions although no official hard policy).
For this reason, I really wanted to give back in some way. Due to my relatively non-technical background, I chose to run the Snowflake tab on my browser since it looked like a minimal-risk way to contribute for a novice user. However, I decided to close it after running it for a few days (after waiting to see no one was using my Snowflake at the moment I turned it off before uninstalling the extension). The main reason was that I am living with housemates with a common internet connection and the public IP address seems to be briefly seen by the Snowflake user (aside from the volunteer maybe being able to see that of the user on Snowflake extension operator can access the IP of client? and The "volunteers will not be able to determine your location" claim is a little misleading (#19) · Issues · The Tor Project / Web / Snowflake · GitLab ).
If I understand correctly, the websites visited by the Snowflake user only see the exit node IP and there is no likely legal liability on my end. However, I have a hard time convincing my housemates that some Snowflake user (individual or state) won’t use the public IP for nefarious purposes apart from saying “people who know what they’re doing say this is highly unlikely”. I may be willing to take a small risk, but it doesn’t seem fair for me to ask them to take such a risk and I don’t have a good enough technical understanding to properly explain why things are ok.
Apart from only running a Snowflake extension at my own place when I move out after some point, what are reasonable options to try and help? It has been hard for me to find a source that discusses something like this apart from what I linked to above. Should I try to use a VPS and a Snowflake proxy, bridge or relay on it in the future? I can sort of stupidly follow some instructions (see background note above), but I have a feeling that actually dealing with potential issues requires technical or other knowledge (e.g. asking ISPs about what is ok on Tor Project | Good Bad ISPs ).
Thanks in advance and apologies for the rambling post.
Even running snowflakes extension within your project is helping someone! You mentioned you’re non-technical so I understand how running a bridge, relay or something else may be a little daunting. All I really wanted to say is that running snowflakes extension within your browser is making a difference and is helping someone, if you have an android phone maybe you could even download the new snowflake application.
What Snowflake actually does: Your Snowflake proxy acts only as an entry step (a bridge) into the Tor network—not an exit node. Traffic passing through your browser extension is fully encrypted and sent straight into the internal Tor network.
Thanks for looking into this! In fact, explaining that Snowflake is an entry was my main point and I think my housemates understood this. I think their primary concern was whether someone can “pretend” to be an ordinary Snowflake user with bad intentions and somehow do something weird using the public IP address for our connection for whatever reason (e.g. Snowflake volunteers being targeted). The part where I think I messed up was answering “Maybe for a bit” to the question “Does anyone see our IP address?” based on Snowflake extension operator can access the IP of client? and not being able to say why things are ok other than mumbling about traffic being encrypted and saying this only seems to be possible for a short time before they disconnect from a particular session (using my Snowflake proxy).
At this point, I’m leaning towards getting a VPS and trying to run a bridge on it. I might hold off on running the Snowflake proxy until I move out later (at least for interpersonal reasons and my inability to figure out what to do). Is this a reasonable plan?
When running the extension the Snowflake user has access to the IP of the volunteer (you) because that is how the communications are done. Otherwise how can that person send you any packets? The volunteer (you) has access to the source IP of the packets which could be a proxy, VPN, or the public IP of that person.
But the IPs in both situations above don’t just jump at you on the screen. You would have to sniff them from the packets in and out.
If you live in a place where your fingernails could be pulled for circumventing censorship then I see the concern.
As for “Snowflake user with bad intentions and somehow do something weird” then I say you have deniability. But not much good if you are not allowed to circumvent censorship in the first place.
Where I am, operating a standalone Snowflake Proxy, like I do, can be considered philanthropical. As for the “something weird” and deniability I say what the gun lobby says: guns don’t kill people, people do. If I sell hardware and someone bashes another’s head in with the hammer I sold is the responsibility with me? Before running my Snowflake Proxy I had the same concerns about that “something weird”.
Thank you! This is very helpful. In particular, the part about needing to make a separate effort to sniff the IPs to access them sorted things out for me. I recently spent a long time time working in a place where censorship was applied rather inconsistently (outside the usual suspects) and was subject to random security searches where nothing turned up anyway for silly reasons. Since I’m currently in a “safe” country without internet censorship I may have been overly paranoid. It’s nice to know that I’m not the only person that had concerns about “something weird” though, haha.