Re: Tor 0.2.2.22-alpha is out
*Hi* *Tor is running since yesterday!* *Thanks Tor for support us in Iran* On Sun, Jan 30, 2011 at 10:30 AM, Roger Dingledine a...@mit.edu wrote: Tor 0.2.2.22-alpha fixes a few more less-critical security issues. The main other change is a slight tweak to Tor's TLS handshake that makes relays and bridges that run this new version reachable from Iran again. We don't expect this tweak will win the arms race long-term, but it will buy us a bit more time until we roll out a better solution. Anybody running a relay or bridge who wants it to work for Iran should upgrade. https://www.torproject.org/download/download Changes in version 0.2.2.22-alpha - 2011-01-25 o Major bugfixes: - Fix a bounds-checking error that could allow an attacker to remotely crash a directory authority. Bugfix on 0.2.1.5-alpha. Found by piebeer. - Don't assert when changing from bridge to relay or vice versa via the controller. The assert happened because we didn't properly initialize our keys in this case. Bugfix on 0.2.2.18-alpha; fixes bug 2433. Reported by bastik. o Minor features: - Adjust our TLS Diffie-Hellman parameters to match those used by Apache's mod_ssl. - Provide a log message stating which geoip file we're parsing instead of just stating that we're parsing the geoip file. Implements ticket 2432. o Minor bugfixes: - Check for and reject overly long directory certificates and directory tokens before they have a chance to hit any assertions. Bugfix on 0.2.1.28 / 0.2.2.20-alpha. Found by doorss. -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFNRQyK61qJaiiYi/URArD2AJ4oV2y8AkwauDI1in80SFKZH1bw9ACgpVrO RWQbSEo2twF6eMgbvsB6XNg= =RRxg -END PGP SIGNATURE-
Re: Tor 0.2.2.22-alpha is out
Roger Dingledine wrote: Tor 0.2.2.22-alpha fixes a few more less-critical security issues. The main other change is a slight tweak to Tor's TLS handshake that makes relays and bridges that run this new version reachable from Iran again. We don't expect this tweak will win the arms race long-term, but it will buy us a bit more time until we roll out a better solution. Anybody running a relay or bridge who wants it to work for Iran should upgrade. https://www.torproject.org/download/download Changes in version 0.2.2.22-alpha - 2011-01-25 o Major bugfixes: - Fix a bounds-checking error that could allow an attacker to remotely crash a directory authority. Bugfix on 0.2.1.5-alpha. Found by piebeer. - Don't assert when changing from bridge to relay or vice versa via the controller. The assert happened because we didn't properly initialize our keys in this case. Bugfix on 0.2.2.18-alpha; fixes bug 2433. Reported by bastik. o Minor features: - Adjust our TLS Diffie-Hellman parameters to match those used by Apache's mod_ssl. - Provide a log message stating which geoip file we're parsing instead of just stating that we're parsing the geoip file. Implements ticket 2432. o Minor bugfixes: - Check for and reject overly long directory certificates and directory tokens before they have a chance to hit any assertions. Bugfix on 0.2.1.28 / 0.2.2.20-alpha. Found by doorss. I installed it in the morning of yesterday or in the morning of the day before yesteray on my debian exit node. How can I do it before this release? *** To unsubscribe, send an e-mail to majord...@torproject.org with unsubscribe or-talkin the body. http://archives.seul.org/or/talk/
Re: Tor 0.2.2.22-alpha is out
On Sun, 30 Jan 2011 12:48:02 +0330 Hasan mhaliz...@gmail.com wrote: *I have download the new version from https://www.torproject.org/download/download but still i can't connect to tor!! :(* Tor 0.2.2.22-alpha contains 'a slight tweak ... that makes *relays and bridges* that run this new version reachable from Iran again' (emphasis added). Running it as your client will not help you. You need to find a bridge that is running 0.2.2.22-alpha, or find a relay that is running 0.2.2.22-alpha and configure it as a bridge. *My IP Add: [DELETED] * You should not have published your IP address. It is quite easy for your government to use your IP address to identify you and punish you, and no one on this list can use your IP address to help you. Robert Ransom signature.asc Description: PGP signature
Re: Tor 0.2.2.22-alpha is out
*Thanks for your attention* *but when I run Tor I receive these warnings:* *[Warning] Problem bootstrapping. Stuck at 10%: Finishing handshake with directory server. (Socket is not connected [WSAENOTCONN ]; NOROUTE; count 1; recommendation warn)* *[Notice] No current certificate known for authority moria1; launching request.* *[Notice] No current certificate known for authority dannenberg; launching request.* *and Tor status is:* *Establishing an encrypted directory connection* *The Tor Version is:* *The Tor Software is Running - You are currently running version 0.2.1.29 (r8e9b25e6c7a2e70c) of the Tor software.* On Sun, Jan 30, 2011 at 1:01 PM, Robert Ransom rransom.8...@gmail.comwrote: On Sun, 30 Jan 2011 12:48:02 +0330 Hasan mhaliz...@gmail.com wrote: *I have download the new version from https://www.torproject.org/download/download but still i can't connect to tor!! :(* Tor 0.2.2.22-alpha contains 'a slight tweak ... that makes *relays and bridges* that run this new version reachable from Iran again' (emphasis added). Running it as your client will not help you. You need to find a bridge that is running 0.2.2.22-alpha, or find a relay that is running 0.2.2.22-alpha and configure it as a bridge. *My IP Add: [DELETED] * You should not have published your IP address. It is quite easy for your government to use your IP address to identify you and punish you, and no one on this list can use your IP address to help you. Robert Ransom
Tor 0.2.2.22-alpha is out
Tor 0.2.2.22-alpha fixes a few more less-critical security issues. The main other change is a slight tweak to Tor's TLS handshake that makes relays and bridges that run this new version reachable from Iran again. We don't expect this tweak will win the arms race long-term, but it will buy us a bit more time until we roll out a better solution. Anybody running a relay or bridge who wants it to work for Iran should upgrade. https://www.torproject.org/download/download Changes in version 0.2.2.22-alpha - 2011-01-25 o Major bugfixes: - Fix a bounds-checking error that could allow an attacker to remotely crash a directory authority. Bugfix on 0.2.1.5-alpha. Found by piebeer. - Don't assert when changing from bridge to relay or vice versa via the controller. The assert happened because we didn't properly initialize our keys in this case. Bugfix on 0.2.2.18-alpha; fixes bug 2433. Reported by bastik. o Minor features: - Adjust our TLS Diffie-Hellman parameters to match those used by Apache's mod_ssl. - Provide a log message stating which geoip file we're parsing instead of just stating that we're parsing the geoip file. Implements ticket 2432. o Minor bugfixes: - Check for and reject overly long directory certificates and directory tokens before they have a chance to hit any assertions. Bugfix on 0.2.1.28 / 0.2.2.20-alpha. Found by doorss. signature.asc Description: Digital signature
Re: Tor 0.2.2.22-alpha is out
Tor 0.2.2.22-alpha fixes a few more less-critical security issues. The main other change is a slight tweak to Tor's TLS handshake that makes relays and bridges that run this new version reachable from Iran again. We don't expect this tweak will win the arms race long-term, but it will buy us a bit more time until we roll out a better solution. Anybody running a relay or bridge who wants it to work for Iran should upgrade. Do you have any plans to apply these tweaks to the 2.1.X stable branch too? Regards, Klaus signature.asc Description: This is a digitally signed message part.