diff --git a/i18n/ar/advanced/tor-overview.md b/i18n/ar/advanced/tor-overview.md index 5b8802e66..0db36943b 100644 --- a/i18n/ar/advanced/tor-overview.md +++ b/i18n/ar/advanced/tor-overview.md @@ -175,39 +175,39 @@ description: Tor هي شبكة مجانية ولا مركزية، صُممت ل على الرغم من أن Tor يوفر ضمانات قوية للخصوصية، فمن المهم أن نكون على دراية بأن Tor ليس مثاليا: - متصفح Tor لا يحميك من كشف هويتك بالخطأ، مثل أن تشارك معلومات كثيرة جدا عن هويتك الحقيقية. -- يمكن لـ Tor exit nodes أن **تُعدّل** الـ traffic غير المشفّر الذي يمر من خلالها. This means traffic which is not encrypted, such as plain HTTP traffic, can be changed by a malicious exit node. **Never** download files from an unencrypted `http://` website over Tor, and ensure your browser is set to always upgrade HTTP traffic to HTTPS. -- Tor exit nodes can also monitor traffic that passes through them. Unencrypted traffic which contains personally identifiable information can deanonymize you to that exit node. Again, we recommend only using HTTPS over Tor. -- Powerful adversaries with the capability to passively watch *all* network traffic around the globe ("Global Passive Adversaries") are **not** something that Tor protects you against (and using Tor [with a VPN](#safely-connecting-to-tor) doesn't change this fact). -- Well-funded adversaries with the capability to passively watch *most* network traffic around the globe still have a *chance* of deanonymizing Tor users by means of advanced traffic analysis. +- يمكن لـ Tor exit nodes أن **تُعدّل** الـ traffic غير المشفّر الذي يمر من خلالها. هذا يعني أن الـ traffic غير المشفّر، مثل plain HTTP traffic، يمكن أن يتم تغييره بواسطة malicious exit node. **لا تقم أبدا** بتنزيل ملفات من موقع غير مشفّر يستخدم `http://` عبر Tor، وتأكد من ضبط المتصفح بحيث يقوم دائمًا بترقية HTTP traffic إلى HTTPS. +- يمكن لـ Tor exit nodes أيضا مراقبة الـ traffic الذي يمر من خلالها. إذا كان الـ traffic غير المشفر يحتوي على معلومات تكشف هويتك الشخصية، فقد يتمكن الـ exit node من معرفة هويتك الحقيقية. ومرة أخرى، ننصح باستخدام HTTPS فقط عند استخدام Tor. +- الجهات القوية التي تملك القدرة على مراقبة *كل* الـ network traffic حول العالم بشكل سلبي، والتي تُعرف باسم "Global Passive Adversaries"، هي جهات **لا** يستطيع Tor حمايتك منها، واستخدام Tor [مع VPN](#safely-connecting-to-tor) لا يغير هذه الحقيقة. +- الجهات التي تملك تمويلا وإمكانات كبيرة، وتستطيع مراقبة *معظم* الـ network traffic حول العالم بشكل سلبي، لا يزال لديها *احتمال* لكشف هوية مستخدمي Tor باستخدام أساليب متقدمة لتحليل الـ traffic. -If you wish to use Tor for browsing the web, we only recommend the **official** Tor Browser—it is designed to prevent fingerprinting. +إذا كنت تريد استخدام Tor لتصفح الويب، فنحن ننصح فقط باستخدام Tor Browser **الرسمي**، لأنه مصمم لمنع fingerprinting. -- [Tor Browser :material-arrow-right-drop-circle:](../tor.md#tor-browser) +- [متصفح Tor :material-arrow-right-drop-circle:](../tor.md#tor-browser) -### Protections provided by bridges +### الحماية التي توفرها الـ bridges -Tor bridges are commonly touted as an alternative method to hiding Tor usage from an ISP, instead of a VPN (as we suggest using if possible). Something to consider is that while bridges may provide adequate censorship circumvention, this is only a *transient* benefit. They do not adequately protect you from your ISP discovering you connected to Tor in the *past* with historical traffic log analysis. +غالبا ما يتم تقديم Tor bridges كطريقة بديلة لإخفاء استخدام Tor عن الـ ISP بدلا من استخدام VPN، وهو الخيار الذي ننصح به إذا كان ذلك ممكنا. من المهم أن تعرف أنه رغم أن bridges قد تساعد بشكل جيد في تجاوز الرقابة والحجب، فإن هذه الفائدة تكون *مؤقتة* فقط. لكن bridges لا تحميك بشكل كافٍ من أن يكتشف الـ ISP أنك اتصلت بـ Tor في *الماضي*، وذلك من خلال تحليل سجلات الـ traffic القديمة. -To illustrate this point, consider the following scenario: You connect to Tor via a bridge, and your ISP doesn’t detect it because they are not doing sophisticated analysis of your traffic, so things are working as intended. Now, 4 months go by, and the IP of your bridge has been made public. This is a very common occurrence with bridges; they are discovered and blocked relatively frequently, just not immediately. +لتوضيح الفكرة، تخيل السيناريو التالي: تتصل بـ Tor عبر bridge، ولا يكتشف الـ ISP ذلك لأنه لا يجري تحليلا متقدما للـ traffic الخاص بك، وبالتالي تسير الأمور كما هو متوقع. بعد مرور 4 أشهر، يصبح الـ IP الخاص بالـ bridge الذي استخدمته معروفا للعامة. وهذا أمر شائع جدا مع bridges؛ إذ يتم اكتشافها وحجبها بشكل متكرر نسبيا، ولكن ليس فورا. -Your ISP wants to identify Tor users 4 months ago, and with their limited metadata logging they can see that you connected to an IP address which was later revealed to be a Tor bridge. You have virtually no other excuse to be making such a connection, so the ISP can say with very high confidence that you were a Tor user at that time. +بعد 4 أشهر، إذا أراد الـ ISP معرفة من كان يستخدم Tor في ذلك الوقت، فيمكنه من خلال سجلات الـ metadata المحدودة لديه أن يرى أنك اتصلت بـ IP تبين لاحقا أنه تابع لـ Tor bridge. ولأنك غالبا لا تملك سببا آخر للاتصال بهذا الـ IP، فيمكن للـ ISP أن يستنتج بدرجة عالية جدا من الثقة أنك كنت تستخدم Tor في ذلك الوقت. -Contrast this with our recommended scenario, where you connect to Tor via a VPN. Say that 4 months later your ISP again wants to identify anybody who used Tor 4 months ago. Their logs almost certainly can identify your traffic 4 months ago, but all they would likely be able to see is that you connected to a VPN’s IP address. This is because most ISPs only retain metadata over long periods of time, not the full contents of the traffic you request. Storing the entirety of your traffic data would require a massive quantity of storage which nearly all threat actors wouldn't possess. +قارن ذلك بالسيناريو الذي ننصح به، حيث تتصل بـ Tor عبر VPN. لنفترض أنه بعد 4 أشهر، أراد الـ ISP مرة أخرى معرفة من كان يستخدم Tor قبل 4 أشهر. من المرجح جدا أن يتمكنوا من العثور على سجل الـ traffic الخاص بك قبل 4 أشهر، لكن كل ما سيرونه غالبا هو أنك اتصلت بعنوان IP تابع لـ VPN. وذلك لأن معظم مزودي خدمة الإنترنت (ISP) يحتفظون لفترات طويلة فقط بـ metadata الخاصة بالاتصالات، وليس بالمحتوى الكامل للـ traffic الذي ترسله أو تستقبله. الاحتفاظ بكل بيانات الـ traffic الخاصة بك يحتاج إلى مساحة تخزين هائلة، وهي قدرة لا تتوفر لدى معظم threat actors. -Because your ISP almost certainly is not capturing all packet-level data and storing it forever, they have no way of determining what you connected to with that VPN *after* the fact with an advanced technique like deep packet inspection, and therefore you have plausible deniability. +ولأن الـ ISP على الأرجح لا يسجل كل بيانات الـ packets ويحتفظ بها إلى الأبد، فلن يتمكن *لاحقا* من معرفة ما الذي اتصلت به عبر الـ VPN باستخدام تقنية متقدمة مثل deep packet inspection. وبالتالي، سيكون لديك سبب منطقي للقول إن اتصالك بالـ VPN لا يثبت أنك كنت تستخدم Tor. -Therefore, bridges provide the most benefit when circumventing internet censorship *in the moment*, but they are not an adequate substitute for **all** the benefits that using a VPN alongside Tor can provide. Again, this is not advice *against* using Tor bridges—you should just be aware of these limitations while making your decision. In some cases bridges may be the *only* option (if all VPN providers are blocked, for instance), so you can still use them in those circumstances with this limitation in mind. +لذلك، تكون الـ bridges مفيدة أكثر لتجاوز الرقابة على الإنترنت *في نفس اللحظة*، لكنها لا تُعد بديلًا كافيا عن **كل** المزايا التي يمكن أن يوفرها استخدام VPN مع Tor. ومرة أخرى، هذا لا يعني أننا ننصحك *بعدم* استخدام Tor bridges، لكن من المهم أن تكون على دراية بهذه القيود عند اتخاذ قرارك. في بعض الحالات، قد تكون الـ bridges هي الخيار *الوحيد* المتاح، مثلا إذا كانت جميع خدمات الـ VPN محجوبة. في هذه الحالة، لا يزال بإمكانك استخدامها، لكن مع وضع هذا القيد في الاعتبار. -If you think that a bridge can aid in defending against fingerprinting or other advanced network analysis more than a VPN's encrypted tunnel already can, you always have the option to use a bridge in conjunction with a VPN as well. That way you are still protected by the pluggable transport's obfuscation techniques even if an adversary gains some level of visibility into your VPN tunnel. If you decide to go this route, we recommend connecting to an obfs4 bridge behind your VPN for optimal fingerprinting protection, rather than meek or Snowflake. +إذا كنت تعتقد أن الـ bridge يمكن أن يساعد أكثر في الحماية من fingerprinting أو من أساليب تحليل الشبكة المتقدمة، بالإضافة إلى الحماية التي يوفرها الـ VPN encrypted tunnel، فيمكنك أيضا استخدام bridge مع VPN في نفس الوقت. بهذه الطريقة، ستظل محميا بتقنيات الإخفاء التي يوفرها الـ pluggable transport، حتى لو تمكنت جهة ما من رؤية جزء من الـ VPN tunnel الخاص بك. إذا قررت استخدام هذه الطريقة، فننصح بالاتصال بـ obfs4 bridge من خلال الـ VPN للحصول على أفضل حماية من fingerprinting، بدلًا من استخدام meek أو Snowflake. -It is [possible](https://discuss.privacyguides.net/t/clarify-tors-weaknesses-with-respect-to-observability/3676/16) that the [WebTunnel](https://forum.torproject.org/t/tor-relays-announcement-webtunnel-a-new-pluggable-transport-for-bridges-now-available-for-deployment/8180) pluggable transport currently being trialed may mitigate some of these concerns. We will continue to keep an eye on that technology as it develops. +من [المحتمل](https://discuss.privacyguides.net/t/clarify-tors-weaknesses-with-respect-to-observability/3676/16) أن يساعد [WebTunnel](https://forum.torproject.org/t/tor-relays-announcement-webtunnel-a-new-pluggable-transport-for-bridges-now-available-for-deployment/8180)، وهو pluggable transport لا يزال قيد التجربة حاليا، في تقليل بعض هذه المخاوف. وسنواصل متابعة هذه التقنية مع تطورها. -## Additional Resources +## مصادر إضافية -- [Tor Browser User Manual](https://tb-manual.torproject.org) -- [How Tor Works - Computerphile](https://youtube.com/watch?v=QRYzre4bf7I) (YouTube) +- [دليل مستخدم Tor Browser](https://tb-manual.torproject.org) +- [كيف يعمل Tor - Computerphile](https://youtube.com/watch?v=QRYzre4bf7I) (YouTube) - [Tor Onion Services - Computerphile](https://youtube.com/watch?v=lVcbq_a5N9I) (YouTube) -[^1]: The first relay in your circuit is called an "entry guard" or "guard". It is a fast and stable relay that remains the first one in your circuit for 2-3 months in order to protect against a known anonymity-breaking attack. The rest of your circuit changes with every new website you visit, and all together these relays provide the full privacy protections of Tor. For more information on how guard relays work, see this [blog post](https://blog.torproject.org/improving-tors-anonymity-changing-guard-parameters) and [paper](https://www-users.cs.umn.edu/~hoppernj/single_guard.pdf) on entry guards. ([https://support.torproject.org/tbb/tbb-2](https://support.torproject.org/tbb/tbb-2)) +[^1]: أول relay في الـ circuit الخاص بك يُسمى "entry guard" أو اختصارًا "guard". وهو relay سريع ومستقر يظل أول relay في الـ circuit الخاص بك لمدة من شهرين إلى 3 أشهر، وذلك للحماية من هجوم معروف يمكنه كشف هويتك. أما باقي الـ circuit فيتغير مع كل موقع جديد تزوره، وتعمل كل هذه relays معا لتوفير الحماية الكاملة للخصوصية التي يقدمها Tor. لمزيد من المعلومات حول كيفية عمل guard relays، يمكنك قراءة [هذه التدوينة](https://blog.torproject.org/improving-tors-anonymity-changing-guard-parameters) و[هذه الورقة البحثية](https://www-users.cs.umn.edu/~hoppernj/single_guard.pdf) حول entry guards. ([https://support.torproject.org/tbb/tbb-2](https://support.torproject.org/tbb/tbb-2)) -[^2]: Relay flag: a special (dis-)qualification of relays for circuit positions (for example, "Guard", "Exit", "BadExit"), circuit properties (for example, "Fast", "Stable"), or roles (for example, "Authority", "HSDir"), as assigned by the directory authorities and further defined in the directory protocol specification. ([https://metrics.torproject.org/glossary.html](https://metrics.torproject.org/glossary.html#relay-flag)) +[^2]: الـ Relay flag: هي صفة خاصة تُعطى للـ relays لتحديد مكانها أو دورها داخل الـ circuit، مثل "Guard" و"Exit" و"BadExit"، أو لتحديد خصائصها مثل "Fast" و"Stable"، أو أدوارها مثل "Authority" و"HSDir". ويتم تعيين هذه الصفات بواسطة directory authorities، ويتم شرحها بشكل أكثر تفصيلًا في directory protocol specification. ([https://metrics.torproject.org/glossary.html](https://metrics.torproject.org/glossary.html#relay-flag))