Re: [tor-talk] Escape NSA just to enter commercial surveillance?

2016-01-14 Thread str4d
on its own, as stated business > practice. Also, I'm pretty sure if another Manning-like case > appears, NSA would immediately command Facebook to offer the > related user identification. Not everyone's adversary is the NSA. str4d > > If there's cheering about Facebook hid

Re: [tor-talk] Accessing Cloudflare sites on TBB

2015-10-03 Thread str4d
spamalot.com and shortly after multiple requests come in on slstatic.com, it should mark those as the same session, somehow (whether by adding a query parameter or header to the static requests, or being more intelligent on the server side). str4d > > best, Griffin > -BEGIN PGP SIG

Re: [tor-talk] HORNET onion routing design

2015-07-24 Thread str4d
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Seth David Schoen wrote: str4d writes: * No replay detection - packet replay is ignored within the lifetime of a session. They suggest that adversaries would be deterred by the risk of being detected by volunteers/organizations/ASs

Re: [tor-talk] HORNET onion routing design

2015-07-23 Thread str4d
a HORNET-based routing overlay using server-side software instead of network hardware, similar to Tor and I2P. Such a scheme would however not be as efficient as one based on deployed network hardware. str4d -- Seth Schoen sch...@eff.org Senior Staff Technologist https://www.eff.org/ Electronic

Re: [tor-talk] HORNET onion routing design

2015-07-23 Thread str4d
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 str4d wrote: * Stateless data transmission (as they say on the box) - the routing info is replicated in every data packet, removing the need for local lookups. This increases the data packet header size (7 hops requires 344 bytes for HORNET, c/f

Re: [tor-talk] CloudFlare one site, multiple domains problem

2015-05-27 Thread str4d
a tab (or pop-up window) for each through the same circuit. That would allow users to authenticate that site's Tor circuit with CloudFlare for all domains the site uses. But this would probably need to be repeated each time the circuit changes (like the CAPTCHAs already need to be). str4d

Re: [tor-talk] Making a Site Available as both a Hidden Service and on the www - thoughts?

2015-05-18 Thread str4d
ever sees them. It also includes a unique local address per client feature like [0] for use with off-the-shelf applications, but this is open to collisions (because the client hash space does not fit into the IPv4 or IPv6 localhost address space). str4d [0] https://lists.torproject.org/pipermail

Re: [tor-talk] SIGAINT email service targeted by 70 bad exit nodes

2015-04-26 Thread str4d
without permission, but then a malicious exit provider would have even less motivation to set it up. str4d Or is the requirement to flag them as badexit to catch them red handed? The case that one took over legit relays is unlikely since many are rather 'fresh' ones. Or: Are they still

Re: [tor-talk] git: application level leaks and best practices?

2015-02-26 Thread str4d
): alias git='TZ=UTC git' If you only want to force UTC for occasional commands then just add TZ=UTC in front of the command, but I personally prefer redefining the git command like above, to prevent accidentally forgetting. str4d On Thu, Feb 26, 2015 at 12:24 AM, meejah mee...@meejah.ca wrote

Re: [tor-talk] phantom protocol

2014-12-15 Thread str4d
above. It's worth looking at. It is an interesting protocol. I am reviewing the whitepapers, and intend to publish a comparison page on the I2P website[1] once I have a good understanding of the differences. str4d [0] http://www.magnusbrading.com/phantom/phantom-design-paper.pdf [1] https

Re: [tor-talk] Twitter account lockouts for Tor users

2014-11-05 Thread str4d
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I use Polly on my laptop with no lock-out yet. I do regularly get Unable to connect to Twitter error messages, from the exit node my circuit has switched to being blocked by Twitter (I assume). str4d Brian Kroll wrote: I use Twidere (loaded from

Re: [tor-talk] Tor Weekly News — September 3rd, 2014

2014-09-04 Thread str4d
. Disabling I2P by default was done to reduce the potential attack surface; I2P itself is no longer vulnerable to that attack. str4d -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJUB+zVAAoJEIA97kkaNHPnMAEP/igZJW4FH51mdqxHKtjpgA5Q CugZFtfl2VgKNJHE2QklWCsLH70/KL+swIHdS+UtQ6PqKcqaapIUJT/1oAk4YxPJ

Re: [tor-talk] Can NAT traversal be Tor's killer feature?

2014-07-11 Thread str4d
compatibility for applications that support hostnames. As an aside, most of the applications that you mention generally use UDP packets, which Tor does not yet support (AFAIK). I2P does support datagrams. str4d [0] https://www.onioncat.org/ [1] https://www.cypherpunk.at/onioncat_trac/browser/trunk/i2p

Re: [tor-talk] BlackHat2014: Deanonymize Tor for $3000

2014-07-05 Thread str4d
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 07/05/2014 11:13 AM, grarpamp wrote: On Fri, Jul 4, 2014 at 6:02 PM, Paweł Zegartowski pze...@gmail.com wrote: i2p does have 'exits' you can compare to tor as well. Anyone can run an exit. But users have first find one on a wiki list or

Re: [tor-talk] High-latency hidden services (was: Re: Secure Hidden Service

2014-07-03 Thread str4d
] - distributed encrypted email. Can be configured so that emails are stored via relays which delay before passing on packets, so the visible store of an encrypted email packet in the DHT can occur hours after it was sent and the original Bote node disconnected. str4d [0] http://syndie.i2p2.de/ [1

Re: [tor-talk] Freenet and hidden services

2013-10-07 Thread str4d
-October/001242.html str4d On 10/07/2013 08:11 PM, Jerzy Łogiewa wrote: Do you mean if Tor wold have distributed data store like freenet? Nice idea, please implement this. :~ -- Jerzy Łogiewa -- jerz...@interia.eu On Oct 6, 2013, at 3:26 AM, It's Good to be Alive wrote: Hi, I'm fairly new

Re: [tor-talk] Help with getting a good automated sign up script for an email service on TOR

2013-09-18 Thread str4d
postman's mail system has been running since 2004, so he could be a useful source of info for you. And I think that having the operators of two similar mail systems talking with each other would be beneficial to the development of these systems :) str4d On 09/18/2013 12:41 PM, Conrad Rockenhaus wrote