Re: [tor-relays] Botnet issues and upgrading to 0.2.4.x

2013-10-14 Thread Roger Dingledine
On Mon, Oct 14, 2013 at 08:36:58PM +0100, Chris Whittleston wrote: Aha - makes sense, I'll just build it myself. Thanks for the quick response. So - the new handshake in 0.2.4.x doesn't help with the ongoing issues? On that page I linked it was suggested it might... It does help! It helps

Re: [tor-relays] MaxOnionQueueDelay

2013-10-01 Thread Roger Dingledine
On Fri, Sep 27, 2013 at 11:37:55AM +0200, nsane wrote: Hello, there is a Tor setting MaxOnionQueueDelay in torrc (see https://www.torproject.org/docs/tor-manual-dev.html.en) with a default of 1750 msec. As operator of a Tor relay 0.2.4.17-rc (on Debian) I would like to know were I can

Re: [tor-relays] Relay security, re: local network

2013-09-26 Thread Roger Dingledine
On Thu, Sep 26, 2013 at 12:04:13PM -0800, I wrote: Why not? I've been running a middle relay for years in my private net behind one adress. no problems there. You should just never run an exit relay there. EFF recommends against it in their Legal FAQ: Should I run an exit relay from my

Re: [tor-relays] What happens with the time on turtles 76.73.17.194?

2013-09-21 Thread Roger Dingledine
On Sat, Sep 21, 2013 at 12:19:42PM +0200, tor-admin wrote: Hi Mike, I am seeing many of these messages in the logs of torland1/torland2: Sep 21 12:09:34.000 [warn] Received NETINFO cell with skewed time from server at 76.73.17.194:9090. It seems that our clock is ahead by 15969 days, 10

Re: [tor-relays] non-exit risks?

2013-09-20 Thread Roger Dingledine
On Fri, Sep 20, 2013 at 12:13:08PM -0500, David Carlson wrote: Considering more sophisticated methods to detect and differentiate legitimate activity from nefarious activity would be too difficult, i suppose. The step after that is when they intentionally over-list in order to try to

Re: [tor-relays] non-exit risks?

2013-09-20 Thread Roger Dingledine
On Fri, Sep 20, 2013 at 11:08:27PM -0400, krishna e bera wrote: Once the network gets big enough so that each node and client doesnt know all the nodes ip addresses, is there a compelling reason that ip addresses of relays which are non-exit and non-guard need to be published to the outside

Re: [tor-relays] safeguard operators (was: Reimbursement of Exit Operators)

2013-09-19 Thread Roger Dingledine
On Thu, Sep 19, 2013 at 11:56:22AM +0600, Roman Mamedov wrote: Just check out the idkneitzel Node. You are not running an Exit node, all of this is irrelevant to you. Right. But for those here who are wondering about running large exit relays, check out

Re: [tor-relays] 0.2.4.17-rc on Pi, a couple weeks on

2013-09-18 Thread Roger Dingledine
On Wed, Sep 18, 2013 at 06:50:46AM -0700, Gordon Morehouse wrote: The replay has settled into a fairly steady state (after losing its flags except Named) of sending 5-10KB more per sec than it gets. I have a feeling this is literally due to the TAP replies being bigger than the TAP requests.

Re: [tor-relays] Reimbursement of Exit Operators

2013-09-18 Thread Roger Dingledine
On Wed, Sep 18, 2013 at 08:10:25AM -0400, t...@t-3.net wrote: The Wau Holland Foundation can currently only reimburse via wire transfer. This seems to be end-of-story in terms of who, in the end, is ultimately getting liability/risk, and points to practically no chance at anonymity Think

Re: [tor-relays] Too little traffic on my #2 non-exit relay

2013-09-18 Thread Roger Dingledine
On Wed, Sep 18, 2013 at 06:57:54PM +0200, Christian Dietrich wrote: Now my problem is that tor relay #2 generates almost no traffic. https://atlas.torproject.org/#search/myTOR Log Relay #2: Circuit handshake stats since last time: 63/63 TAP, 1/1 NTor. Heartbeat: Tor's uptime

Re: [tor-relays] Tor Relay getting Failed to terminate process with PID messages

2013-09-18 Thread Roger Dingledine
On Wed, Sep 18, 2013 at 08:20:18PM -0400, Michael Gorbach wrote: Nope, I don?t have any special pluggable transports configured in my torrc, which is odd. What other processes would for be starting kicking off? All I have set in torrc is [...] PortForwarding That's likely the one! You might be

Re: [tor-relays] Creating circuits to myself?

2013-09-16 Thread Roger Dingledine
On Sun, Sep 15, 2013 at 10:08:58PM -0400, Niles Rogoff wrote: I was using arm when I noticed this line: 173.79.154.243 -- 173.79.154.243 (us) Purpose: Ags=is_internal,need_capacity, Circuit ID: 5 4.0m (CIRCUIT) That's

Re: [tor-relays] Tor crashes frequently on fast relay

2013-09-11 Thread Roger Dingledine
On Wed, Sep 11, 2013 at 12:34:12PM +0200, Stephan wrote: On 11.09.2013 10:05, Random Tor Node Operator wrote: Sep 10 08:59:40.000 [notice] Interrupt: we have stopped accepting new connections, and will shut down in 30 seconds. Interrupt again to exit now. I'm just taking a wild guess here,

Re: [tor-relays] Why is my fast relay so slow to gain popularity?

2013-09-11 Thread Roger Dingledine
On Wed, Sep 11, 2013 at 11:10:07AM -0600, Jesse Victors wrote: Do I have to maintain an uptime of ~70 days to see fully utilization then? This relay is on a personal computer with a static IP, so it isn't on a dedicated server or anything like that. Usually my uptime is around several weeks

Re: [tor-relays] Tor node was doing more traffic than its bandwidth is configured for

2013-09-08 Thread Roger Dingledine
On Sat, Sep 07, 2013 at 10:16:51PM -0400, t...@t-3.net wrote: I updated our node to the RC version some days ago. Earlier today, it started to do a traffic amount that was higher than it had been configured to do in torrc. Torrc was configured for 35M use and 40M burst, but today it went to

Re: [tor-relays] Tor node was doing more traffic than its bandwidthis configured for

2013-09-08 Thread Roger Dingledine
On Sun, Sep 08, 2013 at 04:00:08PM +0600, Roman Mamedov wrote: MB (capital B) = Megabyte https://en.wikipedia.org/wiki/Megabyte Mb (small b) = Megabit https://en.wikipedia.org/wiki/Megabit But torrc does not support specifying rate limits in megabits anyway. In 0.2.5 (aka git master

Re: [tor-relays] Fwd: New tor node not acting as an exit server?

2013-09-08 Thread Roger Dingledine
On Sun, Sep 08, 2013 at 05:23:12PM -0400, Niles Rogoff wrote: I scrapped my previous exit node and set up a new one on a different machine. It's been running for 6 and a half hours, but does not have the exit flag. The logs say both my ORPort and DirPort are reachable from the outside, and

[tor-relays] Upgrade your relay to 0.2.4.17-rc?

2013-09-05 Thread Roger Dingledine
Hi folks, I just released 0.2.4.17-rc. Hopefully there will be debs of it soon. It comes with a new feature: - Relays now process the new NTor circuit-level handshake requests with higher priority than the old TAP circuit-level handshake requests. We still process some TAP

Re: [tor-relays] Upgrade your relay to 0.2.4.17-rc?

2013-09-05 Thread Roger Dingledine
On Thu, Sep 05, 2013 at 06:54:57AM -0400, Roger Dingledine wrote: In my spare time I'm also working on a blog post to explain what's going on and what measures we're taking to keep things afloat. https://blog.torproject.org/blog/how-to-handle-millions-new-tor-clients --Roger

Re: [tor-relays] Patch

2013-09-04 Thread Roger Dingledine
On Wed, Sep 04, 2013 at 10:57:24PM +0200, Niels Hesse wrote: Oh, okay. Thank you for your answer. I really hope this will be resolved somehow. Keep an eye on https://trac.torproject.org/projects/tor/ticket/9657 if you want to follow along. --Roger

Re: [tor-relays] Which clock is out of sync on VPS non-exit relay?

2013-09-01 Thread Roger Dingledine
On Sun, Sep 01, 2013 at 06:57:38PM -0800, I wrote: Hej,brbrOn trying to get a non-exit relay going on a cheap VPS Vidalia saysbrSep 02 03:48:32.146 [Warning] Received NETINFO cell with skewed time from server at 128.31.0.34:9101.nbsp; It seems that our clock is ahead by 9 hours, 0 minutes,

Re: [tor-relays] A bit more evidence on circuit creation storms

2013-08-31 Thread Roger Dingledine
On Thu, Aug 29, 2013 at 11:30:33PM -0400, krishna e bera wrote: On 13-08-29 10:35 PM, Gordon Morehouse wrote: What on earth is causing so many circuit creation requests in such a short timespan? One possibility, if i recall correctly, is that the Tor that comes with the PirateBrowser

Re: [tor-relays] new relays

2013-08-28 Thread Roger Dingledine
On Tue, Aug 27, 2013 at 11:12:01PM +0200, Tor Exit wrote: Why is it so bad if a Tor exit operator tries to match the use of their node with their own moral beliefs? I really would like to support this if I could. Specifically, I'd love a way for exit relay operators to only allow people to do

Re: [tor-relays] 'service tor start' not using /etc/tor/torrc?

2013-08-14 Thread Roger Dingledine
On Wed, Aug 14, 2013 at 11:41:39PM +0800, TonyXue wrote: Hi, Today when I was using htop to check my Tor server. I found that Tor was running as /usr/sbin/tor --defaults-torrc /usr/share/tor/tor-service-defaults-torrc --hush which seems Tor is not using the configuration file

Re: [tor-relays] VPS

2013-08-04 Thread Roger Dingledine
On Sat, Aug 03, 2013 at 07:46:50PM +0100, Tom McLoughlin wrote: I'm looking for a VPS to run a tor exit node on, any ideas? Be sure to check out the wiki page: https://trac.torproject.org/projects/tor/wiki/doc/GoodBadISPs for what others have said in the past. And if you have anything to add or

Re: [tor-relays] Home broadband - worth running a relay?

2013-07-30 Thread Roger Dingledine
On Tue, Jul 30, 2013 at 05:13:09PM +0200, Andreas Krey wrote: On Tue, 30 Jul 2013 08:03:58 +, Gordon Morehouse wrote: It'd be nice if dynamic DNS could solve this somehow, but it can't with the current implementation. :/ Even if - it wouldn't help those users that have an open

Re: [tor-relays] Home broadband - worth running a relay?

2013-07-13 Thread Roger Dingledine
On Thu, Jul 11, 2013 at 09:43:00PM +0100, Nick wrote: I have a reasonable ADSL connection, and a little always-on server. The bandwidth is in the region of 2Mib/s down, something less up (maybe 256Kib/s). Is it useful for me to run a tor relay with this bandwidth? I'd like to run one which

Re: [tor-relays] Circuit creation storms overwhelming Raspberry Pi?

2013-06-05 Thread Roger Dingledine
On Wed, Jun 05, 2013 at 09:20:02AM -, te...@tormail.org wrote: I've been seeing these storms as well on my relay. I average something like 100 connections for weeks and weeks per the tor logs, but then suddenly it will jump into the thousands and I'll see the Failed to hand off onionskin.

Re: [tor-relays] Is TOR using more than just OrPort and DirPort?

2013-05-13 Thread Roger Dingledine
On Sun, May 12, 2013 at 01:45:03PM -0700, Daniel Wu wrote: There are these connections, from 127.0.0.1 back to itself. Some sort of internal process used by Tor? Not as concerned about these, since these are internal. But still curious. TCP 127.0.0.1:63417 127.0.0.1:63418 ESTABLISHED TCP

Re: [tor-relays] How to limit number of sockets used?

2013-04-10 Thread Roger Dingledine
On Wed, Apr 10, 2013 at 09:09:44AM +0200, Dennis Ljungmark wrote: You should be able to use normal ulimit style settings, Limiting open files count (a socket is an open file). Yes, you can do this, but it will degrade your relay (and hurt the network) because it will unpredictably hang up on

Re: [tor-relays] DMCA letters

2013-03-12 Thread Roger Dingledine
On Tue, Mar 12, 2013 at 09:07:09PM +0100, Moritz Bartl wrote: On 12.03.2013 08:41, jv...@altsci.com wrote: I'm wondering if anyone receives a large number of DMCA infringement notices and whether there was a resolution. We do. Given that none of the regular DMCA complaint companies were

Re: [tor-relays] Local problem or Authority problem?

2013-03-12 Thread Roger Dingledine
On Tue, Mar 12, 2013 at 01:38:26PM -0400, Steve Snyder wrote: Mar 12 16:13:57.000 [warn] Received http status code 504 (Gateway Time-out) from server '154.35.32.5:80' while fetching consensus directory. I've seen several reports of that lately. I assume Sina's directory authority is

Re: [tor-relays] Recommended specifications for 1Gbps exit

2013-02-26 Thread Roger Dingledine
On Tue, Feb 26, 2013 at 11:54:59PM +, Matt Joyce wrote: I'm a little confused though for some reason only two of the instances show up in atlas, the other one just keeps complaining it isn't in the cached consensus and isn't seeing any usage either consensus health over at metrics mentions

Re: [tor-relays] Problems with Debian package and low ports

2013-02-13 Thread Roger Dingledine
On Wed, Feb 13, 2013 at 04:41:54PM +, Chris Baines wrote: I am having some problems with tor (version 0.2.3.25-1), I get warnings when it resumes form hibernation: Feb 11 00:00:00.000 [warn] Could not bind to 0.0.0.0:80: Permission denied Feb 11 00:00:00.000 [notice] Opening OR listener on

Re: [tor-relays] Disappointing AUP - (was Re: DDOS?)

2013-01-04 Thread Roger Dingledine
On Fri, Jan 04, 2013 at 03:51:21PM -0500, Steve Snyder wrote: On Friday, January 4, 2013 3:38pm, mick m...@rlogin.net said: [snip] Thanks for the pointer - but yes, I'd prefer to stay away from the US. I think the US is probably already well served with tor nodes. Yes, about 25% of all

Re: [tor-relays] Complaint about spam originating from my server

2012-12-13 Thread Roger Dingledine
On Thu, Dec 13, 2012 at 08:28:30AM -0700, Brock Tice wrote: Hello all, I follow the guide for avoiding abuse notices, and generally I only get 1/year of the DMCA variety. However, I recently received this complaint, which appears to show spam originating from my Tor server (209.188.113.101

Re: [tor-relays] 'critical' security update: Tor 0.2.2.39

2012-09-15 Thread Roger Dingledine
On Sat, Sep 15, 2012 at 12:25:59PM +0200, tagnaq wrote: It is quite sad that one has to find out about 'critical' security updates [0] via an unrelated thread on tor-talk [1] or the blog [2] instead of getting an announcement on tor-announce [3] - where relay operators are probably expecting

Re: [tor-relays] Relay info kit for Tor exits

2012-08-23 Thread Roger Dingledine
On Thu, Aug 16, 2012 at 01:00:56PM +0200, Moritz Bartl wrote: https://trac.torproject.org/projects/tor/wiki/doc/TorExitGuidelines Comments? Do you want to see something else in an article that says Tor Exit Guidelines? Thanks! I've updated the page to include some more suggestions. Please

Re: [tor-relays] Relay info kit for Tor exits

2012-08-23 Thread Roger Dingledine
On Fri, Aug 17, 2012 at 09:15:46AM -0400, Tom Ritter wrote: It would be good to add the exit IP to services that allow Tor Exits to register to proactively stop abuse emails. http://www.blocklist.de is one I had to add mine to within the first month. Is this generally accepted as a good

Re: [tor-relays] Help the Tor Project by running a fast unpublished bridge

2012-08-14 Thread Roger Dingledine
On Tue, Aug 14, 2012 at 08:25:40AM +0200, tor-admin wrote: ON Saturday, August 11. 2012, 18:25:03 Roger Dingledine wrote: The constraints are: * 100mbit+ connectivity, though in practice I expect they will spend most of their time doing far less than that. * No more than 2 bridges per /24

Re: [tor-relays] Help the Tor Project by running a fast unpublished bridge

2012-08-12 Thread Roger Dingledine
On Sun, Aug 12, 2012 at 09:58:54AM +0200, Sebastian G. bastik.tor wrote: You ask volunteers to achieve a funders goal. Those might run a bridge already, but un-publish it. Less bridges for the rest. They could run relays and turn them into unpublished bridges. Less relays for anyone. Running

Re: [tor-relays] Call for discussion: turning funding into more exit relays

2012-07-31 Thread Roger Dingledine
On Wed, Jul 25, 2012 at 06:32:30PM +0200, Julian Wissmann wrote: we've got an offer for 10GBit unmetered@750?, which is kind of sweet spot performance/buck wise and I guess, that it could handle 8-12 Tor nodes performance wise to satisfy the pipe. It would be a large number of high performance

Re: [tor-relays] Call for discussion: turning funding into more exit relays

2012-07-31 Thread Roger Dingledine
On Thu, Jul 26, 2012 at 12:01:13PM -0400, Steve Snyder wrote: At the same time, much of our performance improvement comes from better load balancing -- that is, concentrating traffic on the relays that can handle it better. The result though is a direct tradeoff with relay diversity: on

Re: [tor-relays] Call for discussion: turning funding into more exit relays

2012-07-31 Thread Roger Dingledine
On Thu, Jul 26, 2012 at 07:34:14PM +0100, mick wrote: We've lined up our first funder (BBG, aka http://www.voanews.com/), and they're excited to have us start as soon as we can. They want to sponsor 125+ fast exits. Forgive me, but what do they want in return? (He who pays the piper...)

Re: [tor-relays] Call for discussion: turning funding into more exit relays

2012-07-31 Thread Roger Dingledine
On Fri, Jul 27, 2012 at 05:49:34AM -0400, Motoko Kusanagi wrote: I am very interested in running 100 Mbit (maybe even more) exit nodes at 100$/month, however, a question immediately comes to mind: When we say 100Mbit exit node, do we imply really unmetered traffic at 100 Mbit, or do we mean

Re: [tor-relays] [tor-assistants] Call for discussion: turning funding into more exit relays

2012-07-31 Thread Roger Dingledine
On Sun, Jul 29, 2012 at 03:05:32PM +0100, Andrew Beveridge wrote: - What do you currently pay for hosting/bandwidth, and how much bandwidth do you get for that? This is a complicated question, because I run a single Tor exit in a VPS on my company dedicated server. I run a local company

Re: [tor-relays] sustained bandwidth drop through noisetor

2012-05-02 Thread Roger Dingledine
On Wed, May 02, 2012 at 08:29:08PM -0700, Andy Isaacson wrote: Has there been a change in the routing algorithm, or any other network changes that might explain this drop? I opened https://trac.torproject.org/projects/tor/ticket/5755 for a related topic that I think will help answer questions

Re: [tor-relays] [tor-assistants] Reg : Torperf measurements

2012-03-10 Thread Roger Dingledine
On Sat, Mar 10, 2012 at 03:02:46PM -0500, Sambuddho Chakravarty wrote: The section on Performance data in the Tor metrics page https://metrics.torproject.org/data.html , says that you are recording data by running Torperf on 'moria', 'torperf' and 'siv'. I know 'moria' is a exit node. But

Re: [tor-relays] Thoughts on InspecTor?

2012-02-01 Thread Roger Dingledine
On Wed, Feb 01, 2012 at 11:36:57PM -0500, Steve Snyder wrote: This application claims to identify bad Tor nodes for the purpose of excluding them from use: http://xqz3u5drneuzhaeo.onion/users/badtornodes/ Anyone have any thoughts on this? In general it is a poor plan to change your

Re: [tor-relays] How can I tell if my bridge is working?

2012-01-22 Thread Roger Dingledine
On Thu, Jan 19, 2012 at 08:35:30PM -0500, Steve Snyder wrote: New operator of a Tor bridge here. How can I tell that it is being used? With a regular relay I can look up the stats on TorStatus, or I can see that there are n current connections. But a bridge won't be published, and the

Re: [tor-relays] Tor Status graphs

2012-01-22 Thread Roger Dingledine
On Fri, Jan 20, 2012 at 01:49:45AM +, Geoff Down wrote: Hi, the read/write graphs in my relay's TorStatus.blutmagie.de page have been broken for some time (flat-lined) but I assumed that was down to my old software. However, I see that all the relays' pages are the same. Is this data

Re: [tor-relays] torrc permission denied warning

2011-12-19 Thread Roger Dingledine
On Mon, Dec 19, 2011 at 08:09:31PM +1100, tony wrote: In the Tor logs for a relay, I get the following message: Dec 19 19:42:23.662 [notice] Renaming old configuration file to /etc/tor/torrc.orig.1 Dec 19 19:42:23.662 [warn] Couldn't rename configuration file /etc/tor/torrc to

Re: [tor-relays] TBB on same system as relay?

2011-10-21 Thread Roger Dingledine
On Fri, Oct 21, 2011 at 11:17:13AM -0400, Andrew Lewman wrote: On Thursday, October 20, 2011 21:30:59 Rick Huebner wrote: way of using Tor as a client. How can I run the TBB on my system without interfering with my relay? TBB supports randomized socks port and control port

Re: [tor-relays] Odd activity on my rely

2011-07-19 Thread Roger Dingledine
On Tue, Jul 19, 2011 at 02:20:18PM -0400, cmeclax-sazri wrote: Uploading large files sounds likely to me. Another possibility is that it's running a hidden download server that a lot of people are downloading from. Good point -- this could be a hidden service and you're actually seeing traffic

<    1   2   3   4   5