Re: [tor-talk] [tor-dev] Linux kernel transproxy packet leak (w/ repro case + workaround)

2014-04-09 Thread Abel Luck
Abel Luck: > On Saturday 29 March 2014 03:10:47 grarpamp wrote: > > On Fri, Mar 28, 2014 at 5:20 PM, intrigeri wrote: > > > grarpamp wrote (28 Mar 2014 21:02:35 GMT) : > > >> [...] what happens with entire vm IP transproxy (perhaps like > > >> Tails)? >

Re: [tor-talk] corridor, a Tor traffic whitelisting gateway

2014-04-01 Thread Abel Luck
On Sunday 16 February 2014 13:42:59 Patrick Schleizer wrote: > Rusty Bird: > > Patrick Schleizer: > >> The problem is, any Whonix-Workstation behind Whonix-Gateway - > >> once compromised - can claim to be another Whonix-Workstation, > >> thus not being stream isolated anymore. > >> > >> This coul

Re: [tor-talk] [tor-dev] Linux kernel transproxy packet leak (w/ repro case + workaround)

2014-04-01 Thread Abel Luck
On Saturday 29 March 2014 03:10:47 grarpamp wrote: > On Fri, Mar 28, 2014 at 5:20 PM, intrigeri wrote: > > grarpamp wrote (28 Mar 2014 21:02:35 GMT) : > >> [...] what happens with entire vm IP transproxy (perhaps like > >> Tails)? > > > > Tails only uses a transproxy for the automapped .onion add

Re: [tor-talk] Tor Browser Bundle 3.0alpha1 test builds

2013-06-17 Thread Abel Luck
Mike Perry: > The new TBB 3.0 series is almost ready for its first alpha release! > > Here are the major highlights of the 3.0 series: > > 1. Usability, usability, usability! We've attempted to solve several > major usability issues in this series, including: > > A. No more Vidalia. The

Re: [tor-talk] RPM packaging back on track

2013-03-09 Thread Abel Luck
xtensive (meaning > months) > planned for anytime soon :-) > > Ondrej > Hi there Ondrej, Any idea when the fc18 repo will be available? Cheers, Abel Luck ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Re: [tor-talk] Interested in a Tor Browser update script for Debian, Ubuntu and derivatives?

2012-12-11 Thread Abel Luck
adrelanos: > Downloading and gpg verifying Tor Browser each time there is an update > gets really tiresome and I think many people either never gpg verified > or don't do it sometimes. > > What if we had a Debian package which contains a Tor Browser updater? > > I could eventually provide somethi

Re: [tor-talk] Question about using Thunderbird + EnigMail/GnuPG

2012-11-20 Thread Abel Luck
Anthony Papillion: > Hello Everyone, > > A friend of mine recently read something (I don't know what) that made him > think that there were some issue using Thunderbird with Tor that might > compromise your anonymity. I told him I thought it was probably a > configuration issue that could resul

Re: [tor-talk] Review request: TorVM implementation in Qubes OS: Vidalia

2012-10-19 Thread Abel Luck
adrelanos: >> Future Work Integrate Vidalia > > About Vidalia again... I was quickly reading my dev ticket again ( > https://trac.torproject.org/projects/tor/wiki/doc/TorBOX/Dev#SHELLSCRIPTSVidaliabydefaultGraphicalGatewayWAITINGFORVIDALIA0.3.x > ), why it's not yet integrated into Whonix. > > S

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-19 Thread Abel Luck
Abel Luck: > adrelanos: >> Hi, >> >> Is it Amnesic or can it be made Amnesic? >> >> Or in other words Can you be sure, that after deleting (or wiping) >> the torified AppVM no activity can not be reconstructed with local disk >> forensics? Could the

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-19 Thread Abel Luck
adrelanos: > Abel Luck: >> adrelanos: >>> Hi, >>> >>> Is it Amnesic or can it be made Amnesic? >>> >>> Or in other words Can you be sure, that after deleting (or wiping) >>> the torified AppVM no activity can not be reconstru

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-19 Thread Abel Luck
intrigeri: > Hi, > > adrelanos wrote (16 Oct 2012 18:28:19 GMT) : >> Abel Luck: > >>> I need to do more research into what it would take to protect the >>> localtime. For example, what are the consequences (technically and >>> UX-wise) of ch

Re: [tor-talk] Tor Browser script pack 0.3: (multiple) Tor Browser, without Tor/Vidalia; behind a transparent proxy or Tor Router

2012-10-17 Thread Abel Luck
adrelanos: > The Doctor: >> On 10/10/2012 08:59 PM, adrelanos wrote: >> >>> Alternative startup scripts for the Tor Browser Bundle. For >>> starting up Tor Browser without Tor and Vidalia. >> >> There's an easier way to go about it: >> >> https://github.com/virtadpt/Experiments/blob/master/tbb.sh >

Re: [tor-talk] registration for youtube, gmail over Tor - fake voicemail / sms anyone?

2012-10-16 Thread Abel Luck
Mike Hearn: > We blacklist SMS/voice forwarding services when we find them and > re-suspend the accounts that used them. We haven't focused on it much > so there are certainly services we haven't blacklisted yet. > > Generally, using these services is dangerous. If spammers have used > the same nu

Re: [tor-talk] registration for youtube, gmail over Tor - fake voicemail / sms anyone?

2012-10-16 Thread Abel Luck
fakef...@tormail.org: > > I wanted to register for youtube. For comments, voting... Youtube wants a > gmail account... > > Failed to make a gmail account. Gave them alternate mail, correct > captcha... First thing after registration they want is sms or phone > verification... I have no such thing

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-16 Thread Abel Luck
adrelanos: > Hi, > > I am only commenting by reading the Readme: > https://github.com/abeluck/qubes-addons/blob/master/qubes-tor/README.md > This is exactly the type of feedback I wanted, thanks. See responses inline. > First of all, I find this most interesting! > >> Non-comphrensive list of

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-16 Thread Abel Luck
adrelanos: > Hi, > > Is it Amnesic or can it be made Amnesic? > > Or in other words Can you be sure, that after deleting (or wiping) > the torified AppVM no activity can not be reconstructed with local disk > forensics? Could the torified AppVM be securely wiped without any > leftovers? (Left

Re: [tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-15 Thread Abel Luck
adrelanos: > Hi, > > released under which license? > > Cheers, > adrelanos The script is GPL v2 licensed, as the rest of Qubes. You can see that in the header [1]. [1]: https://github.com/abeluck/qubes-addons/blob/master/qubes-tor/start_tor_proxy.sh _

[tor-talk] Review request: TorVM implementation in Qubes OS

2012-10-13 Thread Abel Luck
Hey folks, I've implemented a TorVM service for Qubes OS [1] and I am seeking feedback from more knowledgeable eyes on the tor+iptables configuration. Quick background to give this context: Qubes is an OS based on Xen and Linux that isolates applications to domains. Each domain is a virtual mach

Re: [tor-talk] TBB advantages in VM

2012-09-28 Thread Abel Luck
adrelanos: > Abel Luck: >> Interesting reading, thanks! My use case is different. It's running >> Qubes-OS [1] with a specific TorVM acting as a transparent proxy for >> other AppVms. >> >> The AnonBrowserVM is a VM that only has Firefox (soon TBB without tor)

Re: [tor-talk] TBB advantages in VM

2012-09-27 Thread Abel Luck
adrelanos: > Abel Luck: >> Hi, >> >> Given the following conditions: >> >> 1) Firefox (15.0 lets say) is running in an isolated VM, and only >> Firefox is running (i.e., no other user apps) > > Bad. You'd be one of the very few people not using

[tor-talk] TBB advantages in VM

2012-09-27 Thread Abel Luck
Hi, Given the following conditions: 1) Firefox (15.0 lets say) is running in an isolated VM, and only Firefox is running (i.e., no other user apps) 2) The VM is being properly transparently proxied by another machine running tor in transparent proxy mode 3) The proxy machine fails cosed upon Tor