Re: [Freedombox-discuss] Tor configuration

2014-03-18 Thread intrigeri
Hi, James Valleroy wrote (18 Mar 2014 03:01:05 GMT) : and are there any changes that you would recommend? I recommend additionally running obfsproxy (Cc'ing the Debian maintainer), to help more Tor users in more countries. This requires opening 1..3 more ports, depending on the exact pluggable

[Freedombox-discuss] Block brute force login attacks?

2014-03-18 Thread Petter Reinholdtsen
Hi. On all my machines, I install denyhosts with a two hour timeout (DAEMON_PURGE = 2h), to block those trying to brute force a ssh login. Should we do something similar on the Freedombox? In addition to denyhosts (which only handle ssh), there are other relevant packages in Debian:

Re: [Freedombox-discuss] Should we drop xterm from the freedombox default setup?

2014-03-18 Thread Nick Daly
Mercurial was installed because some unpackaged projects used hg instead of git. It can be removed, and certainly shouldn't be pulling xterm in, anyway... On Tue, Mar 18, 2014 at 12:26 AM, Petter Reinholdtsen p...@hungry.com wrote: I noticed today when running apt-get upgrade on my freedombox

Re: [Freedombox-discuss] Should we drop xterm from the freedombox default setup?

2014-03-18 Thread Petter Reinholdtsen
[Nick Daly] Mercurial was installed because some unpackaged projects used hg instead of git. It can be removed, and certainly shouldn't be pulling xterm in, anyway... OK. Removed in git. Also dropped git, build-essential and make as dependencies for freedombox-setup, and leave those to be

Re: [Freedombox-discuss] Getting pagekite into Debian?

2014-03-18 Thread Holger Levsen
Hi, On Montag, 17. März 2014, Petter Reinholdtsen wrote: The GIT repo is in collab-maint/pagekite.git, but as Sunil isn't a Debian Developer non DDs can be given write access to collab maint easily. cheers, Holger signature.asc Description: This is a digitally signed message

Re: [Freedombox-discuss] Getting pagekite into Debian?

2014-03-18 Thread Sunil Mohan Adapa
On Tuesday 18 March 2014 08:16 PM, Holger Levsen wrote: [...] non DDs can be given write access to collab maint easily. Thank you for pointing it. I have sent a request to join the collab-maint and I am following the process described (at http://deb.li/3qmXG). -- Sunil signature.asc

[Freedombox-discuss] Avahi (was: Re: How to use JWChat on the freedombox?)

2014-03-18 Thread Tim Retout
On 17 Mar 2014 22:06, Petter Reinholdtsen p...@hungry.com wrote: [Alberto Fuentes] echo fb ip fbx /etc/hosts then navigate to fbx You are right. This actually work. When I visit http://eth0-ip-on-freedombox/, I get the redirect to 403 Forbidden. If I add fbx to /etc/hosts on my

Re: [Freedombox-discuss] Avahi (was: Re: How to use JWChat on the freedombox?)

2014-03-18 Thread Anders Jackson
Den 18 mar 2014 19:32 skrev Tim Retout t...@retout.co.uk: On 17 Mar 2014 22:06, Petter Reinholdtsen p...@hungry.com wrote: [Alberto Fuentes] echo fb ip fbx /etc/hosts then navigate to fbx You are right. This actually work. When I visit http://eth0-ip-on-freedombox/, I get

Re: [Freedombox-discuss] Block brute force login attacks?

2014-03-18 Thread Anders Jackson
Den 18 mar 2014 13:46 skrev Petter Reinholdtsen p...@hungry.com: Hi. Hello On all my machines, I install denyhosts with a two hour timeout (DAEMON_PURGE = 2h), to block those trying to brute force a ssh login. Should we do something similar on the Freedombox? This can be done directly by

Re: [Freedombox-discuss] Block brute force login attacks?

2014-03-18 Thread Petter Reinholdtsen
[Anders Jackson] This can be done directly by iptables, (but not yet with iptables6 for ip6tables ). So I would suggest using a firewall utility instead, like ufw or shorewall. This sound interesting. How can iptables know that the login attempt failed? My idea is to block too many failed

Re: [Freedombox-discuss] Block brute force login attacks?

2014-03-18 Thread Anders Jackson
Den 18 mar 2014 22:18 skrev Petter Reinholdtsen p...@hungry.com: [Anders Jackson] This can be done directly by iptables, (but not yet with iptables6 for ip6tables ). So I would suggest using a firewall utility instead, like ufw or shorewall. This sound interesting. How can iptables

Re: [Freedombox-discuss] Block brute force login attacks?

2014-03-18 Thread Tim Retout
On 18 March 2014 12:45, Petter Reinholdtsen p...@hungry.com wrote: On all my machines, I install denyhosts with a two hour timeout (DAEMON_PURGE = 2h), to block those trying to brute force a ssh login. Should we do something similar on the Freedombox? Hmm, is the ssh port going to be

Re: [Freedombox-discuss] Test if your freedombox is working as it should (testsuite)

2014-03-18 Thread A. F. Cano
On Tue, Mar 18, 2014 at 06:32:46AM +0100, Petter Reinholdtsen wrote: ... I uploaded a new freedombox-setup with new tests yesterday, with the tor test and updated plinth test. The plinth test fail because the certificate is self signed. I changed it to skip the certificate check. Just