[tor-talk] VPNGate

2013-09-02 Thread Roman Mamedov
Hello, Came across this project: http://www.vpngate.net/en/ From the looks of it all the volunteers effectively operate open proxies for anyone who connects to this service. To me this sounds like a total insanity, even running a Tor Exit node can be dangerous (even though you have bullet-proo

Re: [tor-talk] VPNGate

2013-09-02 Thread grarpamp
On 9/2/13, Roman Mamedov wrote: > http://www.vpngate.net/en/ > > even running a Tor Exit node can be dangerous (even though you have > bullet-proof deniability of any knowledge of the source, you can still get > into legal trouble) You chose to provide last hop services (whether exit or vpn), a

Re: [tor-talk] VPNGate

2013-09-02 Thread Roman Mamedov
On Mon, 2 Sep 2013 05:27:45 -0400 grarpamp wrote: > You chose to provide last hop services (whether exit or vpn), any trouble > you catch does not depend on deniability of the source. Tor exit nodes can't help in finding the anonymized originator of an illegal communication, so to speak. Everyon

Re: [tor-talk] VPNGate

2013-09-02 Thread Crypto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 9/2/2013 4:27 AM, grarpamp wrote: > On 9/2/13, Roman Mamedov wrote: >> http://www.vpngate.net/en/ >> >> even running a Tor Exit node can be dangerous (even though you >> have bullet-proof deniability of any knowledge of the source, >> you can sti

Re: [tor-talk] How to test leaks on OSX?

2013-09-02 Thread Jerzy Łogiewa
Hello bry8 star, I started use the "tshark" console application. How to read this stuff? Hard to tell what is DNS leak and what not. Is there some way to distinct Tor connection from not Tor? -- Jerzy Łogiewa -- jerz...@interia.eu On Sep 1, 2013, at 6:53 AM, Bry8 Star wrote: > And, also try "

Re: [tor-talk] How to test leaks on OSX?

2013-09-02 Thread Anton Nikishaev
Jerzy Łogiewa writes: > Hello! > > I am on a Mac and now using the tor as a global (system) proxy for > connections! I like to test this for leaks. How to do it on the Mac? If you are comfortable with that, man 8 pfctl. -- lelf -- tor-talk mailing list - tor-talk@lists.torproject.org To

Re: [tor-talk] VPNGate

2013-09-02 Thread Nathan Suchy
Most of the time if you use a Tor reduced exit policy abuse is low... Sent from my Android so do not expect a fast, long, or perfect response... On Sep 2, 2013 6:05 AM, "Crypto" wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 9/2/2013 4:27 AM, grarpamp wrote: > > On 9/2/13, Roman

[tor-talk] Offtopic but... Is DotTk really that bad?

2013-09-02 Thread Nathan Suchy
I don't really do a lot of controversial writing and I like the free domains and the extension name in general. Is DotTk really that bad? Also if your worried you buy the domain name... Sent from my Android so do not expect a fast, long, or perfect response... -- tor-talk mailing list - tor-talk@

[tor-talk] verifying signature when building from source, deb-style

2013-09-02 Thread Eugen Leitl
I can verify signatures on Tor source packages, using key fingerprint given out of band. How do I do that for https://www.torproject.org/docs/debian "Building from source" (BTW, amd64 deps are missing quilt)? These would be weasel's signature, not Roger's, right? Thanks. -- tor-talk mailing list

Re: [tor-talk] New paper : Users Get Routed: Traffic Correlation on Tor by Realistic Adversaries

2013-09-02 Thread adrelanos
Roger Dingledine: > And we really should raise the guard rotation period. If you > do their compromise graphs again with guards rotated every nine months, > they look way different." TBB releases are more frequent than every nine months. With each TBB release, people are getting new entry guards.

Re: [tor-talk] verifying signature when building from source, deb-style

2013-09-02 Thread Lunar
Eugen Leitl: > I can verify signatures on Tor source packages, using key fingerprint given > out of band. How do I do that for https://www.torproject.org/docs/debian > "Building from source" (BTW, amd64 deps are missing quilt)? weasel ships signed tag in the package Git repository. See for example

Re: [tor-talk] verifying signature when building from source, deb-style

2013-09-02 Thread Eugen Leitl
On Mon, Sep 02, 2013 at 05:30:27PM +0200, Lunar wrote: > Eugen Leitl: > > I can verify signatures on Tor source packages, using key fingerprint given > > out of band. How do I do that for https://www.torproject.org/docs/debian > > "Building from source" (BTW, amd64 deps are missing quilt)? > > wea

Re: [tor-talk] Tor and Financial Transparency

2013-09-02 Thread Graham Todd
>that being said, yea, there is a problem with the global passive >adversary that we have to assume NSA and "friends" to be. and i don't >really see a viable technical solution so far. not saying there aren't >any, mind you. First of, I'll admit to not being as technically as savvy as most of you,

[tor-talk] [RELEASE] Torsocks 2.0.0-rc2

2013-09-02 Thread David Goulet
Greetings everyone! After a week or so, the release candidate 2 is now out after receiving various contributions for BSD and OS X support. A quick note. Please use the Github bug tracker for any issues and *not* trac.torproject.org. Until this code base is accepted as a potential replacement for

Re: [tor-talk] Email Clients and Tor

2013-09-02 Thread tagnaq
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 > I have an email client (Sylpheed) that I use to download email from > gmail and others. > > Can this be configured to send/receive through the Tor network? > Where would I find information on doing this, assuming it can be > done? Depending on y

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread Gordon Morehouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Nathan Freitas: > > > Sherief Alaa wrote: >> Hello, >> >> Over the past couple of days Iranian users have been complaining >> about not being able to download Orbot from Google's play store >> (error 403). [snip] > Otherwise, you can also find

Re: [tor-talk] Contents of PirateBrowser 0.6b

2013-09-02 Thread Gordon Morehouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Andrew F: > Are these guys sponsoring any Servers? Kinda rude if they are > not. Absolutely. I hope they are, but if they were, you'd kinda think they'd probably have told somebody. So I'm assuming not. Best, - -Gordon M. > > > On Sat, Aug

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread ITechGeek
You can also do hosting via Amazon S3 (example: https://s3.amazonaws.com/itg.nu/index.html) Or you can set-up Amazon Cloudfront (CDN) which will pull from S3 or someplace else (This is severely broke, but you get the idea: https://d1tltkimsxj2xg.cloudfront.net/). In either case, if you use the Am

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread ITechGeek
Also sharing the file publicly from Google Drive. --- -ITG (ITechGeek) i...@itechgeek.com https://itg.nu/ GPG Keys: https://itg.nu/contact/gpg-key Preferred GPG Key: Fingerprint: AB46B7E363DA7E04ABFA57852AA

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread Collin Anderson
It seems I was wrong about the initial request for the apk being HTTPS, however, this is a general issue with the Play Store and not Orbot specific I believe. Here is the transaction in question. GET /market/download/Download?packageName=org.thoughtcrime.securesms&versionCode=56&token=AOTCm0QNlhXj

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread Nathan Freitas
Collin Anderson wrote: >It seems I was wrong about the initial request for the apk being HTTPS, >however, this is a general issue with the Play Store and not Orbot >specific >I believe. Here is the transaction in question. > >GET >/market/download/Download?packageName=org.thoughtcrime.securesms&

Re: [tor-talk] Iranian users cannot download Orbot from Google play store

2013-09-02 Thread Collin Anderson
> Are all APK downloads blocked with the 403, or just some? Curious to figure out what the app black/whitelist looks like, and how it is bring done. All application that I tried and others are reporting the same on the Developer notice. Recall though that error is being triggered by Google's side,

Re: [tor-talk] Tor and Financial Transparency

2013-09-02 Thread adrelanos
Graham Todd: > First of, I'll admit to not being as technically as savvy as most of > you, but I've recently seen a copy of Liberte Linux 2012.3 and this > claims that ALL connections a torrified and this is what I'm after in > an anonymity set of software. You may be interested in Whonix (self-ad

Re: [tor-talk] Tor and Financial Transparency

2013-09-02 Thread andrew
On Tue, Sep 03, 2013 at 12:47:42AM +, adrela...@riseup.net wrote 1.4K bytes in 0 lines about: : I think The Tor Project has not enough time/man power/money to grant : more support to such projects, but I can not speak for them. Tails gets some money because we get to know, meet up with, and l

[tor-talk] DistroWatch.com donates to TorProject

2013-09-02 Thread Moritz Bartl
http://distrowatch.com/weekly.php?issue=20130902#donation "We are happy to announce that the recipient of the August 2013 DistroWatch.com donation is the Tor project which provides software tools and maintains a network infrastructure for increased anonymity on the Internet. It receiv

Re: [tor-talk] VPNGate

2013-09-02 Thread Percy Alpha
VPNGate is better at internet circumvention than Tor because Tor has been thoroughly and automatically blocked in China. But VPN protocol cannot be blocked as many commercial companies rely on it -- tor-talk mailing list - tor-talk@lists.torproject.org To unsusbscribe or change other settings go

Re: [tor-talk] VPNGate

2013-09-02 Thread mirimir
On 09/03/2013 05:25 AM, Percy Alpha wrote: > VPNGate is better at internet circumvention than Tor because Tor has been > thoroughly and automatically blocked in China. But VPN protocol cannot be > blocked as many commercial companies rely on it What about Tor obfuscated bridges? And what about