Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-04-01 Thread Jann Horn
On Mon, Mar 31, 2014 at 11:12:05PM +0200, Jann Horn wrote: > Well, the subject line pretty much says it all: Lots of Tor relays send out > globally sequential IP IDs, which, as far as I know, allows a remote party to > measure how fast the relay is sending out IP packets with high precision, > poss

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-04-01 Thread Daniel Bilik
On Tue, 1 Apr 2014 02:56:38 +0200 Jann Horn wrote: > I scanned a good portion of all the tor exit nodes now, this is the > distribution of operating systems for the suspicious-looking relays: > ... > So, looks as if Windows and FreeBSD are the problems. Good catch. On FreeBSD this can be tuned v

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Roger Dingledine
On Mon, Mar 31, 2014 at 11:12:05PM +0200, Jann Horn wrote: > Well, the subject line pretty much says it all: Lots of Tor relays send out > globally sequential IP IDs, which, as far as I know, allows a remote party to > measure how fast the relay is sending out IP packets with high precision, > poss

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Jann Horn
On Mon, Mar 31, 2014 at 04:34:20PM -0800, I wrote: > I don't understand but I really want secure relays. > All my relays are on VPSs running Debian 6/7 64 and I only know enough Linux > to get Tor going. > Is being updated enough? On Linux, that should be sufficient – looking at

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread I
Jann, I don't understand but I really want secure relays. All my relays are on VPSs running Debian 6/7 64 and I only know enough Linux to get Tor going. Is being updated enough? If not would you explain how to remedy the problem you've outlined as it seems quite serious? Robert > another OS (

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Jann Horn
On Mon, Mar 31, 2014 at 06:25:46PM -0400, Tor Relay wrote: > Could you please translate your instructions into XP that I might > check and, if necessary, fix my relay? (OnionTorte) If you don't have hping, you could also e.g. start a capture in wireshark or so, then connect to your host with teln

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Jann Horn
On Mon, Mar 31, 2014 at 02:45:47PM -0800, I wrote: > How? How to fix it, you mean? Good question. Probably depends on your OS. If your OS doesn't let you change it and you can't patch it, I'm afraid you'd have to use another OS (or a newer version of the one you're using). https://en.wikipedia.or

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread I
How? ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Tor Relay
Could you please translate your instructions into XP that I might check and, if necessary, fix my relay? (OnionTorte) Thanks, P Jann Horn wrote: Well, the subject line pretty much says it all: Lots of Tor relays send out globally sequential IP IDs, which, as far as I know, allows a remote p

[tor-relays] Lots of tor relays send out sequential IP IDs; please fix that!

2014-03-31 Thread Jann Horn
Well, the subject line pretty much says it all: Lots of Tor relays send out globally sequential IP IDs, which, as far as I know, allows a remote party to measure how fast the relay is sending out IP packets with high precision, possibly making statistical attacks possible that could e.g. pinpoint t