[tor-talk] Wahay: Mumble + Onion Service

2020-06-01 Thread Tom Bell
If you add an icon for Wahay, it can more easily be added to the Menu Editor in Internet as a "New Item".  The icon makes it more readily identifiable in the menu.  Adding it to the menu is pretty cut-and-dried.  It does start in Kubuntu 18.04, but I have not attempted yet to join any meetings

Re: [tor-talk] tor-talk Digest, Vol 100, Issue 18

2019-05-11 Thread Tom Bell
o use a LiveCD to go in and remove the program, then I logged back in and purged all of the program. If you have a laptop then your keyboard will still work and whatever comes with the computer that is not connected to a USB port. If your particular distro does not have this program, then good luck! To chec

Re: [tor-talk] Syncing bookmarks

2019-04-01 Thread Tom A.
h content - to refresh the Website one then need of course to have Tor. This might be part of your evaluation to store your URLs in a Database, as it is encrypted and provides options to be searched and brought to your website. Regards Tom On Sun, Mar 31, 2019 at 1:56 AM anan wrote: > Hi, >

Re: [tor-talk] Using unbound to resolve .onion domains

2017-09-11 Thread Tom van der Woerdt
Looks fine, you're getting NXDOMAIN, not SERVFAIL. What do you expect a DNS query for a .onion to return? Op 11/09/2017 om 11:23 schreef C. L. Martinez: > Hi all, > > I am trying to figure out the best way to handle DNS requests to both > clearnet and Tor onionland. Currently, I am using two

[tor-talk] Using Raspberry Pi as Tor relay is bad idea??

2017-08-01 Thread Tom Tom
I recently heard that Raspberry Pi could be used as various server, so I'd like to buy and use Raspberry Pi as tor relay. But Raspberry Pi performs slower than normal pc, so I thought it can't perform as well as I expected. 1. Comparing normal pc and RPi as Tor relay, there are no performance

[tor-talk] Fwd: Android Crypto Chat Apps - over Tor?

2017-07-12 Thread Tom A.
, some of these apps with a proxy over Tor provide it? https://m.heise.de/ix/heft/Entzaubert-3754494.html Regards Tom -- Forwarded message -- From: grarpamp <grarp...@gmail.com> Date: Mon, Jul 3, 2017 at 8:02 AM > https://smokeappope.sourceforge.io/ https://smokeappope.sourc

Re: [tor-talk] tor-talk Digest, Vol 78, Issue 4

2017-07-07 Thread Tom Tom
http://thehackernews.com/2017/07/ssh-credential-hacking.html?m=1 This post could be helpful. But how CIA could unveil the encryption? Interesting and horrable... 2017. 7. 7. 오후 9:00에 님이 작성: > Send tor-talk mailing list submissions to >

Re: [tor-talk] Tor RPM?

2016-10-09 Thread Tom van der Woerdt
Hi Sebastian, As far as I know there's no official Tor RPM channel anymore, and EPEL won't ship alphas. There may be community run repos that have Tor packages (I have one) but as a general rule you can't trust those and they'll lag behind :-) Maybe try compiling it from source? Tom Op 09/10

Re: [tor-talk] Tor RPM?

2016-10-09 Thread Tom van der Woerdt
Hi Sebastian, 0.2.8.8 is the latest version :-) Tom > On 9 Oct 2016, at 12:36, Sebastian Elisa Pfeifer > <newslet...@unicorncloud.org> wrote: > > Hi. > > I want to move my Tor Node from Debian to Fedora. The guide tells me to > install the normal packages f

Re: [tor-talk] Sorry Jake I know you are innocent

2016-06-09 Thread tom
Hello ja.talk, if you are a man, then block yourself. The main distinction between men an animals is that animals can't choose, they have to suffer their being as they are. Men have always the choice. and are able to change themselfes. So don't spread you stupid "I am an asshole". Think about

Re: [tor-talk] OT: Bitmessage

2016-01-30 Thread Tom A.
Anthony, you describe BitMail - http://bitmail.sf.net not, BitMessage, please dont mix it up! Regards Tom On Sat, Jan 30, 2016 at 3:06 AM, Anthony Papillion <anth...@cajuntechie.org> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On 01/29/2016 07:05 AM, anon

Re: [tor-talk] OT: Bitmessage

2016-01-30 Thread Tom A.
Yes take care and look yourself or believe so called experts or multiplicators. I agree that all closed source crypto is obsolete. Regards Tom Am 30.01.2016 11:47 schrieb "Jeremy Rand" <biolizar...@gmail.com>: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On

Re: [tor-talk] Ordering a .onion EV certificate from Digitcert

2015-12-15 Thread Tom van der Woerdt
That's not a guide, it just says 'call us' > On 15 Dec 2015, at 17:09, Fabio Pietrosanti (naif) - lists > wrote: > > Hello, > > we asked on Twitter to Digicert to provide a quick guide on how order an > x509v3 certificate for TLS for a .onion, they've just published

Re: [tor-talk] Question Regarding Routing of Network-Traffic using Tor-Browser

2015-11-01 Thread Tom van der Woerdt
You can't fake a Tor relay, they are cryptographically protected. At best they could tell that you're connected somewhere, or stop you from doing that, but they can't see any of the contents, or MITM it. Tom > On 01 Nov 2015, at 11:23, Felix <felix.wiedenr...@gmx.de> wrote: >

Re: [tor-talk] Question Regarding Routing of Network-Traffic using Tor-Browser

2015-11-01 Thread Tom van der Woerdt
Felix, Guards' network speeds are assessed based on the view of the network, not the client. What this means for your North Korea example is that the government couldn't affect path selection by slowing down the network, as Tor will still pick the same guards. Tom > On 01 Nov 2015, at

Re: [tor-talk] Super speed Tor

2015-10-13 Thread Tom van der Woerdt
Hi Marcos, 1. Do you run a relay yourself yet? 2. Combination of all of them 3. Current speed is good, in the future it will either get better, stay the same, or get worse, depending on how much the community contributes. Tom Op 13/10/15 om 19:38 schreef Marcos Eugenio Kehl: Hello cripto

[tor-talk] Fwd: Adaptive Echo (AE) Routing & Alibi Routing

2015-10-12 Thread Tom A.
> Hello, > > for your further research: reports about Geo Location Routing > > https://alibi.cs.umd.edu/ > http://www.heise.de/tr/artikel/Surfen-mit-Alibi-2806120.html >

Re: [tor-talk] IBM says Block Tor

2015-08-27 Thread Tom van der Woerdt
be taken with a barrel of salt. Tom On 27 Aug 2015, at 14:57, Paul Syverson paul.syver...@nrl.navy.mil wrote: On Thu, Aug 27, 2015 at 10:08:26AM +0200, Tom van der Woerdt wrote: In some corporate environments this would be a reasonable thing to do. And the article that started

Re: [tor-talk] IBM says Block Tor

2015-08-27 Thread Tom van der Woerdt
reasonable. Tom On 27 Aug 2015, at 08:47, Virgil Griffith i...@virgil.gr wrote: In general, networks should be configured to deny access to websites such as www.torproject.org Blocking Tor exit nodes is one thing, but this is just bizarre. They could make a claim that privacy from your boss

Re: [tor-talk] future of torstatus.blutmagie.de

2015-08-23 Thread Tom van der Woerdt
Olaf, If you can send me the source code and database (if any), I can continue to run it from a more favorable location (say, Amsterdam or Frankfurt). I have the resources/knowledge to do this. Tom On 23 Aug 2015, at 16:22, Olaf Selke olaf.se...@blutmagie.de wrote: Hello folks, my

Re: [tor-talk] evidence that Tor isn't amoral?

2015-07-10 Thread Tom van der Woerdt
of such research or statistics? Thanks! Drew https://keybase.io/pdp7 Doing such research, where one would be snooping on Tor users' traffic and most likely without their consent, would be amoral. Tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other

Re: [tor-talk] OnionBalance Hidden Service has over 1 million successful hits in just 3 days

2015-07-05 Thread Tom van der Woerdt
Similar from me : torsocks ab -c 10 -n 1 http://eujuuws2nacz4xw4.onion/ Tom Ben schreef op 05/07/15 om 10:02: Much the same, but with some stats (some of which are likely irrelevant, but I poached the line from another script I use) #!/bin/bash torify curl -w %{http_code},\$HOST

Re: [tor-talk] SOCKS proxy to sit between user and Tor?

2015-05-24 Thread Tom van der Woerdt
Hi Jeremy, After reading your message I wonder whether a simple TCP proxy is what you want. Maybe have a look at haproxy? Tom On 24 May 2015, at 13:15, Jeremy Rand biolizar...@gmail.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, I'm interested in having a SOCKS

Re: [tor-talk] SOCKS proxy to sit between user and Tor?

2015-05-24 Thread Tom van der Woerdt
Hi Jeremy, Yup, that's what I meant. Put haproxy between the user and the socks proxy and it'll nicely pass sockets to Tor instances, transparently. Tom On 24 May 2015, at 13:30, Jeremy Rand biolizar...@gmail.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 05/24/2015

Re: [tor-talk] 100-Foot Overview on Tor

2015-05-09 Thread Tom Ritter
is good enough. :) Yea, the extension quirk I think is a bit much, but I fixed the number of hops - now that I think about it closer, 3 makes more sense. On 9 May 2015 at 12:35, grarpamp grarp...@gmail.com wrote: On Tue, May 5, 2015 at 7:49 PM, Tom Ritter t...@ritter.vg wrote: It's (now) http

Re: [tor-talk] 100-Foot Overview on Tor

2015-05-05 Thread Tom Ritter
, or pdf and send you any one of those five. (Or all of them.) -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

[tor-talk] 100-Foot Overview on Tor

2015-05-04 Thread Tom Ritter
- it is long. There's a lot to tor these days :) -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] What is being detected to alert upon?

2015-05-01 Thread Tom van der Woerdt
deal. Bridges might have some very small benefit from looking like an old Firefox, but this is not proven. Also, pluggable transports completely eliminate the need for fingerprint resistance in Tor. Tom Allen schreef op 01/05/15 om 07:41: I didn't see an answer to this question, but I did

Re: [tor-talk] Secure DNS Addresses

2015-04-05 Thread Tom van der Woerdt
Please clarify secure? Tor has its own built-in DNS resolution that will ignore client-side settings. If you're referring to relay DNS: I strongly recommend running a DNS resolver locally, and enabling DNSSEC. That's as secure as you can get them. Tom evervigil...@riseup.net schreef op 05

Re: [tor-talk] Hi!

2015-04-04 Thread Tom van der Woerdt
I know of a good one. -T gary02121...@openmailbox.org schreef op 04/04/15 om 17:47: Hi! Are most hidden services bad? Are there more bad hidden services? Thanks! -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to

Re: [tor-talk] What relay does really help the TOR project?

2015-01-16 Thread Tom van der Woerdt
the network (not to mention the popularity gain). Oh, and don't forget that the normal internet also has quite a high share of this kind of traffic. Tom [1]: https://en.wikipedia.org/wiki/Pornography_by_region Josef 'veloc1ty' Stautner schreef op 16/01/15 om 21:40: Hello List, I first heard from

Re: [tor-talk] Question about linux-tor-prio.sh

2015-01-11 Thread Tom van der Woerdt
Hi Lorenzo, 1Mbit is 125Kbyte. :) Tom On 12 Jan 2015, at 08:18, Lorenzo Milesi max...@ufficyo.com wrote: Hi. I've recently set up a Tor node but bandwidth is running out quickly :) Since I don't want to throttle BW using Tor's options (which basically turns it down) I'd like to limit

Re: [tor-talk] To how many other relays does a relay have connections?

2014-12-27 Thread Tom van der Woerdt
that are mainly middle routers or guards. Tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Platform diversity in Tor network [was: OpenBSD doc/TUNING]

2014-11-05 Thread Tom Ritter
problems than OpenSSL. -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Krypton Anonymous: A Chromium Tor Browser

2014-11-03 Thread Tom Ritter
tor to use a bridge though. -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Escalating hidden services

2014-07-16 Thread Tom van der Woerdt
. If you run 3 nodes, tell 1 of them to handle the introductions, and have this node communicate with the other nodes which then handle the rendezvous part. It might need some hacking in the Tor code, but this should scale for several gigabits very nicely. Tom PS: These three are just some

Re: [tor-talk] Regarding #8244; Including a string not under authority control?

2013-11-25 Thread Tom Fitzhenry
look at the block closest(?) to 22:00. -- Tom Fitzhenry 0. https://en.bitcoin.it/wiki/Difficulty 1. http://bitcoin.stackexchange.com/questions/146/what-are-bitcoin-confirmations -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other settings go to https

[tor-talk] Fwd: Can You Trust NIST?

2013-10-18 Thread Tom Goldman
Recently, I stumbled upon a very interesting article at http://spectrum.ieee.org/telecom/security/can-you-trust-nist Does this mean that Tor could technically be weakened by the NSA? Best regards, cl34r -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other

[tor-talk] Can You Trust NIST?

2013-10-18 Thread Tom Goldman
Recently, I stumbled upon a very interesting article at http://spectrum.ieee.org/telecom/security/can-you-trust-nist Does this mean that Tor could technically be weakened by the NSA? Best regards, cl34r -- tor-talk mailing list - tor-talk@lists.torproject.org To unsubscribe or change other

[tor-talk] Fuck the Hell: VICE Magazine about the Darknet

2013-09-17 Thread tom
Just my 2 cents: trying to read that page using my (untorified) Web Browser with NoScript enabled, those want to execute javascript: twitter.com cloudfront.net google.com googletagmanager.com google-analytics.com outbrain.com tynt.com chartbeat.com ooyala.com stumbleupon.com ad-vice.biz

Re: [tor-talk] Tor relay activity from Antarctica

2013-08-28 Thread Tom Ritter
are supplied internet through government connections, I'd be interested in using Tor if I were on such a station... -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsusbscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] How to designate specific node as exit node

2013-08-13 Thread Tom Ritter
is likely to decrease, not increase, your security and anonymity. -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsusbscribe or change other settings go to https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] HS drop

2013-08-11 Thread Tom Ritter
Hey grarpamp, You may have explained this elsewhere, but if so I missed it (potentially while on an internet moratorium for the past week) - how are you observing these statistics? Thanks, -tom -- tor-talk mailing list - tor-talk@lists.torproject.org To unsusbscribe or change other settings go

Re: [tor-talk] NSA, Tempora, PRISM And Company always know who is behind Tor?

2013-07-19 Thread Tom Ritter
of questions once her slides go up in a couple weeks.) Regarding their ability to monitor EC2 - well it depends on what datacenter. The bulk of EC2 is in the Virginia one - and yea the NSA probably has a line on that one or it's upstream ;) But what about the one in Singapore? /shrug -tom

Re: [tor-talk] Will Tor affect Internet Explorer? (newbie question)

2013-07-12 Thread Tom Ritter
On Jul 11, 2013 11:41 PM, cl34r an0n102...@riseup.net wrote: On 07/11/2013 11:24 PM, Gabrielle DiFonzo wrote: Hi there, Hi I am currently running Windows 7 and my usual browser is Internet Explorer. If I download Tor, will I still be able to use Internet Explorer when I want to? You can

Re: [tor-talk] Plans about Askbot?

2013-06-17 Thread Tom Ritter
a full export. Also, given there's a CAPTCHA, I am not sure backups could be automated. Did they stop doing the database dumps? -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Plans about Askbot?

2013-06-17 Thread Tom Ritter
, containing all the data up until the last day, after they shuttered a site, I would consider them as having COMPLETELY violated the principles the site was founded on, and would go over to their office (they're in NYC) and see if I could plead with them into giving it to me on a thumbdrive. -tom

Re: [tor-talk] What are some good VPS providers for Tor?

2013-05-28 Thread Tom Ritter
and increases single points of failure. If you cannot find a VPS you can afford to run an exit node on, consider running a bridge or a relay node on a VPS that (you think) other people aren't also using. Sorry there's no easy answer, -tom ___ tor-talk mailing

Re: [tor-talk] What are some good VPS providers for Tor?

2013-05-28 Thread Tom Ritter
/ The Torcloud images run Obfs Bridges, so it's better to run one of those than roll your own. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

[tor-talk] Anonymity of Leaking Servers (Was Re: [tor-dev] Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization)

2013-05-27 Thread Tom Ritter
said sources are forced to use Tor, [with] end-to-end crypto without relying on CAs. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] You could use ModX to create .onion sites,

2013-05-24 Thread Tom Ritter
(to reduce the CPU needed) or make other provisions to accommodate it, like ignore PKIX validation and showing no security indicators. -tom [0]https://code.google.com/p/mod-spdy/wiki/ConfigOptions#Debugging_SPDY_without_SSL ___ tor-talk mailing list tor-talk

Re: [tor-talk] You could use ModX to create .onion sites,

2013-05-24 Thread Tom Ritter
On 24 May 2013 09:25, Andreas Krey a.k...@gmx.de wrote: On Fri, 24 May 2013 07:22:28 +, Tom Ritter wrote: ... ... Actually that's not true. I could have bought a certificate for a .onion address, any .onion address, from any CA until the end of 2015. How that? .onion is not a real TLD

Re: [tor-talk] Tragedy of the commons.

2013-05-24 Thread Tom Ritter
at all, but they won't do that either. -tom (who also uses Linode for his server, but runs it as a middleman) ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] You could use ModX to create .onion sites,

2013-05-23 Thread Tom Ritter
talk SPDY? The resource push features of SPDY might be a hugely tremendous boone, without requiring re-architecture web apps. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] memory cached pages should reload instantly-but DON'T

2013-05-07 Thread Tom Ritter
to track down. I did want to point you in the right direction for maybe finding the culprit though. -tom. ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Is using player like VLC safe alternative to Flash?

2013-05-07 Thread Tom Ritter
subjective hand-waving, but I'm not aware of one. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] HTML5 video and Tor anonymity.

2013-05-01 Thread Tom Ritter
Flash in a VM and restricting the VM from making any request except through the proxy (or routing all requests through the proxy) alleviates that concern. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin

[tor-talk] FlashProxy and HTTPS

2013-03-30 Thread Tom Ritter
introduce a DOS channel. This can be mitigated in some sense by rejecting requests for an IP if you've signed a cert for that IP in the last validity_window / 2, and preventing the IPfrom being spoofed (free if done over TCP, difficult otherwise) -tom

Re: [tor-talk] Mail services: Hotmail / Live, Outlook

2013-03-16 Thread Tom Ritter
On 15 March 2013 18:34, Joe Btfsplk joebtfs...@gmx.com wrote: Don't know if this will always work, for all providers, but I have set torrc to use only exit nodes in my country I don't think this should be a recommended practice, because (while you are in that country) it explicitly enables your

Re: [tor-talk] Mail services: Hotmail / Live, Outlook

2013-03-16 Thread Tom Ritter
. via your alternate email or phone) on the first login from an anonymous proxy service, after that they flag your account so they don't bother you again. I haven't test the limits or implementation of this. -tom. ___ tor-talk mailing list tor-talk

[tor-talk] Fwd: Starting out: Project Coordinator

2013-03-04 Thread Tom Lowenthal
Hello! I'm Tom Lowenthal; we may have spoken before, but I can tell you all about me later. I'm Tor's new project coordinator, starting forthwith. I'm here to deal with logistics and communication, and all kinds of other interfering nonsense so that Tor folks can focus on the stuff they want

Re: [tor-talk] On the Theory of Remailers

2013-01-09 Thread Tom Ritter
to 8 recipients, you can't use traffic analysis to see who I sent which message out to - because they're indistinguishable. That's high latency. But if I had sent out each message as soon as I got it, you could see which message went to each recipient - that's low latency. -tom

Re: [tor-talk] On the Theory of Remailers

2013-01-09 Thread Tom Ritter
On 9 January 2013 10:33, Alexandre Guillioud guillioud.alexan...@gmail.com wrote: Wooo thank's Tom ! First time using mailing lists, i'm going to like it :D (and it's not a problem to answer from work :DD). Ok, so i understand what you're meaning by high/low latency network. Just, why don't

Re: [tor-talk] On the Theory of Remailers

2013-01-08 Thread Tom Ritter
the desire that one day, in an ideal world, Alpha Mixing would indeed be the main mixing of the network, to allow for transit of other types of things, like email. -tom [0] http://www.freehaven.net/doc/alpha-mixing/alpha-mixing.pdf ___ tor-talk mailing

[tor-talk] On the Theory of Remailers

2013-01-07 Thread Tom Ritter
I'm hoping this will be of interest to this list. To encourage interest in the waning art of remailers, I'm starting what I aim to be a long series on how they work, design choices, technical limitations, and attacks. The first five are now live at https://crypto.is/blog/ -tom

Re: [tor-talk] On the Theory of Remailers

2013-01-07 Thread Tom Ritter
mean abuse from the perspective of the recipient, and not abuse form the perspective of the remailer operator. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Status reports archive, blog and git?

2012-12-19 Thread Tom Ritter
on the page. Now the comments are stored elsewhere and the page in git has some boilerplate javascript to load the comments. You can even let uses markdown-style their comments. -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https

Re: [tor-talk] Tor Browser protections

2012-12-18 Thread Tom Ritter
based on what I see here: https://gitweb.torproject.org/torbrowser.git/tree/HEAD:/src/current-patches/firefox and in particular here: https://gitweb.torproject.org/torbrowser.git/blob/HEAD:/src/current-patches/firefox/0016-Prevent-WebSocket-DNS-leak.patch -tom

Re: [tor-talk] Synchro of database server over Tor

2012-12-02 Thread Tom Ritter
I'd design as much or all of the db-parts of the site to load over AJAX as possible, so you can put up a nice Loading... message. Keep a persistent connection to the database; don't connect for every client (pconnect in PHP). Maybe do a redundant design that aims for eventual consistency if you

Re: [tor-talk] Hidden services home hosting

2012-11-12 Thread Tom Ritter
the blog on a HS on a VPS outside the country. Or for something that costs nothing, Host the blog on blogger.com or wordpress, and connect to it over Tor, signing up using non personally identifiable information -tom ___ tor-talk mailing list tor-talk

Re: [tor-talk] Can we come up with a lighter, easier torified client apps ?

2012-10-04 Thread Tom Ritter
would be to figure out a way to track upstream easily and identifying use cases where people would really benefit from specific tools, to focus on those first. TorPidginOTR seems like it'd be a likely candidate... unless there's a non-libpurple OTR-enabled chat client. -tom

Re: [tor-talk] new tld question

2012-07-29 Thread Tom Ritter
of exposing HS to the normal web through .onion is desirable, we could start brainstorming in advance of the several hundred pages of paperwork applying for a gTLD requires. -tom [0] If every DNS Request returned the IP of Entry Guard or similar node, along with a DANE record, and a DPF policy

Re: [tor-talk] Torbirdy and gpg --throw-keyids

2012-07-20 Thread Tom Ritter
be worth codifying a preference in the OpenPGP standard. Potentially interpreting http://tools.ietf.org/html/rfc4880#section-5.2.3.17 to also imply throw-keyid or adding a new option. - -tom -BEGIN PGP SIGNATURE- iEYEARECAAYFAlAJ/DwACgkQJZJIJEzU09tWhwCfbW9CKWhr5O4ulukjokJdRtqr wLIAniS

Re: [tor-talk] Roger's status report, May 2012

2012-06-24 Thread Tom Ritter
a separate 'Tor Engineering' blog? If you do separate it into a second blog, you could disable comments, simul-post to the tor-dev list, and say all comments should go on-list -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https

Re: [tor-talk] Webserver on 127.0.0.1 only?

2012-05-09 Thread Tom Ritter
and 443 (and really everything except how you connect to the box which is probably ssh) just to be double-safe. You can use iptables for this, but if iptables is really confusing to you, I personally use shorewall which abstracts iptables to configuration files that make (more) sense. -tom

[tor-talk] Tor with ttdnsd and unbound

2012-04-28 Thread Tom
Hello, Inspired by Tails design documents I'm trying to set up DNS resolving through Tor with Unbound and ttdnsd. Unfortunately I can't seem to get it to work... This is what I have done so far: ls /var/lib/ttdnsd pid tsocks.conf ttdnsd.conf cat /var/lib/ttdnsd/tsocks.conf # This is the

Re: [tor-talk] Evening Standard Article - Invisible Web

2012-04-23 Thread Tom Cheshire
. If you'd like to talk, please drop me an email – ttom.chesh...@condenast.co.uk chesh...@gmail.com. I'm happy to keep names anonymous and out of print if you'd prefer. My deadline is May 8. Many thanks, Tom Tom Cheshire Associate editor - WIRED magazine (UK

Re: [tor-talk] Another openssl advisory: Tor seems not to be affected (Chroot?)

2012-04-19 Thread Tom Ritter
To add another data point, Colin Percival has blogged about how he terminates SSL connections in a jail to mitigate this risk. http://www.daemonology.net/blog/2009-09-28-securing-https.html -tom ___ tor-talk mailing list tor-talk@lists.torproject.org https

Re: [tor-talk] Arm 1.4.3 Release

2011-07-17 Thread Tom L
Nice work! Those are some seriously awesome improvements. -Tom On Sun, Jul 17, 2011 at 3:26 AM, Damian Johnson atag...@gmail.com wrote: Hi all. A new release of arm (http://www.atagar.com/arm/) is now available. This completes the codebase refactoring project that's been a year in the works