[tor-talk] To butt into a FOIA'd conversation

2018-03-02 Thread Ryan Carboni
> > > > > I now expect to have invitations from many FBI groups around the > east coast to come talk to them in more detail. One of the downsides > I'm beginning to realize is the high rate of churn of good technical > people at FBI. Once they learn enough useful technical stuff, they can > get hig

Re: [tor-talk] Tor users in US up by nearly 100,000 this month

2017-09-02 Thread Ryan Carboni
https://en.wikipedia.org/wiki/Facebookcorewwwi.onion I find it hard to believe that you cannot make use of any informal relationships to make a meatspace query on valid Tor usage estimates. People do not exist in isolation, and this meme that no private sector individual has knowledge on Tor ignor

[tor-talk] Tor users in US up by nearly 100,000 this month

2017-09-01 Thread Ryan Carboni
I think the graph speaks for itself. Tor usage is becoming a lot more widespread. https://metrics.torproject.org/userstats-relay-country.html?start=2017-08-03&end=2017-09-01&country=us&events=off -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go t

Re: [tor-talk] MTor (multicast tor), is it going to be released?

2017-08-22 Thread Ryan Carboni
Weren't people speculating that tens of thousands of tor connections were used to deanonymize web services like Doxbin? If mtor is implemented, I don't see any loss of security over Tor. Although many web applications are currently designed for unicast. -- tor-talk mailing list - tor-talk@lists.t

Re: [tor-talk] Tails prevents MAC changes as design feature

2017-08-17 Thread Ryan Carboni
> > Geographical movement is revealed by device leaks before Tails boots. Tor is not meant to protect against a global active adversary. In any case, one should look at who was caught using Tor, and how one should improve upon them. -- tor-talk mailing list - tor-talk@lists.torproject.org To u

Re: [tor-talk] Traffic shaping attack

2016-04-18 Thread Ryan Carboni
If I'm a global adversary, all I have to do is drop packets and see if they are resent. I could do that sequentially for each tor circuit. -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/to

[tor-talk] Comments on https://www.torproject.org/docs/faq.html.en

2016-04-18 Thread Ryan Carboni
1. "Tor does provide a partial solution in a very specific situation, though. When you make a connection to a destination that also runs a Tor relay, Tor will automatically extend your circuit so you exit from that circuit. So for example if Indymedia ran a Tor relay on the same IP address as their

[tor-talk] FPGA Tor Relay

2016-02-25 Thread Ryan Carboni
http://netfpga.org/site/#/systems/1netfpga-sume/details/ This is apparently available for an academic price of around two thousand dollars. A google search hasn't revealed much talk on the tor lists about FPGAs for Tor. Such cards will probably have to be used in the near future, at least to red

Re: [tor-talk] [Cryptography] ISIS has ‘help desk’ to aid would-be terrorists with encryption

2015-11-20 Thread Ryan Carboni
> > Forget the people, shoot the antennas. > > https://www.mca-marines.org/files/The%20Attritionist%20Letters%20Anthology_0.pdf Go to The Attritionist Letters (#11): My tour continued at an infantry regiment combat operations center (COC). We flew in at night, guided by the tactical support wide

Re: [tor-talk] KARMA POLICE

2015-10-02 Thread Ryan Carboni
http://routersecurity.org/ It just simply doesn't matter. To have a modern lifestyle, depends upon having devices of dubious or poor security. The government has shown a willingness to accumulate dossiers (seemingly including IRC chats), and then leak them when it serves their own needs. Our Con

[tor-talk] KARMA POLICE

2015-09-30 Thread Ryan Carboni
http://arstechnica.com/tech-policy/2013/06/exclusive-in-2009-ed-snowden-said-leakers-should-be-shot-then-he-became-one/ https://theintercept.com/2015/09/25/gchq-radio-porn-spies-track-web-users-online-identities/ Yep. Time to create a massive donation drive for Tor. -- tor-talk mailing list - t

Re: [tor-talk] What's to be Done

2015-08-24 Thread Ryan Carboni
> > I'm curious if any one on the list is able to determine how many of the > above issues have already been addressed by the OpenBSD project. > I don't want to steer the thread away from the main topic but I think it is > fair to say that OpenBSD has problems too. An article titled the insecurity

Re: [tor-talk] What's to be Done

2015-08-24 Thread Ryan Carboni
> > * Ways to verify system firmware compromise thru dumping images and > archiving them > > It's the problem of Plato's cave isn't it? -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-

Re: [tor-talk] (no subject)

2015-08-12 Thread Ryan Carboni
Last year's summer of code had someone working on Tor multicore. This year's summer of privacy has Donncha O'Cearbhaill working on load balancing for hidden services. -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.or

Re: [tor-talk] (no subject)

2015-08-11 Thread Ryan Carboni
> Does anyone in Tor want to name a price to get this task done? The price of a public dedicated ip address is at worst, $20 a month. Two tor nodes max per IP address, so roughly $20*6000 relays / 2 = $60,000 per year. That is perhaps the only price of no multicore support. Although, many Tor n

[tor-talk] (no subject)

2015-08-11 Thread Ryan Carboni
Why is there no multicore support for Tor? I haven't been able to find an answer to this question. -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] help needed to stress-test an onionbalanced HS - everyone is invited

2015-07-04 Thread Ryan Carboni
Suggestions: add this: and maybe a few of these pictures: https://w2.eff.org/Misc/Graphics/ livens up the bland text page. -- tor-talk mailing list - tor-talk@lists.torproject.org To uns

[tor-talk] Suggestion, hard-coded related domains

2015-07-01 Thread Ryan Carboni
Many websites operate their own CDN. Under the current Tor system each unique domain name is routed to an exit node. The obvious problem is that this provides another angle of attack for deanonymizing users if there are multiple domains controlled by a single party. -- tor-talk mailing list - tor-

Re: [tor-talk] Invaded by disconnect.me

2015-06-03 Thread Ryan Carboni
Doesn't Google Maps trivially deanonymizes you? I generally use Google Maps in normal browsing mode because of that. -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

[tor-talk] Invaded by disconnect.me

2015-06-02 Thread Ryan Carboni
> > Disconnect search allows Tor users to search privately using their > favorite search engine. This service costs money and so we’re asking users > to help keep our servers running and the search product free. Your > contributions will be used exclusively to cover the monthly server costs > asso

Re: [tor-talk] [Cryptography] Dark Web should really be called the Twilight Web

2015-05-29 Thread Ryan Carboni
> > That's only if you choose to attempt a padding-across-the-net > management scope, which is also going to be hard and slow to > manage and respond to bandwidth and other net dynamics. > (Though this was about GPA, it's probably also vulnerable to > endpoint interruption attacks that monitor your

Re: [tor-talk] [Cryptography] Dark Web should really be called the Twilight Web

2015-05-29 Thread Ryan Carboni
To my knowledge, traffic is randomly assigned by clients based on consensus percentages. In order to have a proper padding system, a lot more information needs to be leaked about current bandwidth demand. -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other sett

Re: [tor-talk] [Cryptography] Blogpost: CITAS, a new FBI security program proposal

2014-11-30 Thread Ryan Carboni
While my analogy and definition of security may not have been best suited, nor is this reply, the point remains that there is nothing special here for you as a corp. Anything you say that LE can provide for *you* with honeypots can also be sourced internally or from the open market and your subsequ

[tor-talk] Tor web hosts

2014-09-17 Thread Ryan Carboni
Considering starting a blog. What are the various web hosts for Tor? Google searches yield only Freedom... which is obviously no longer existent. > And there isn't. The DDoS part is inclusive with their other (paid) > service; they're a CDN. The DDoS part is free just because their > inbound link

Re: [tor-talk] Spoofing a browser profile to prevent fingerprinting

2014-07-29 Thread Ryan Carboni
Pretty sure there's be more collisions in regard to those yes or not questions than you think. Distribution of temperaments and opinions seem to fit a bell curve. Thus the number of collisions would be quite high. In terms of internet plug-ins, a person would customize their computer in terms of