Re: [tor-talk] How much of SSL CA protected traffic is read by NSA etc. according to...?

2015-01-05 Thread Michael O Holstein
>Could you please explain how to interpret Jacob Appelbaum's talk at 31c3? [1] >From all the various documents they have collected it's fair to say that at >the present time, barring non-technical methods (http://xkcd.com/538/) .. the >only applications they have seen reported as "no intercept a

Re: [tor-talk] How much of SSL CA protected traffic is read by NSA etc. according to...?

2015-01-05 Thread Michael O Holstein
>Web certificates is broke, certification itself might not be fundamentally >flawed. Check out Moxie Marlinspike's "Convergence.IO" project : http://www.thoughtcrime.org/blog/ssl-and-the-future-of-authenticity/ Cheers, Michael Holstein Cleveland State University -- tor-talk mailing list - tor

Re: [tor-talk] foxnews blockade

2015-01-19 Thread Michael O Holstein
not just you .. the 404 is 403 : You don't have permission to access "http://www.foxnews.com/404error/"; on this server. sarc They probably figured their target audience is lucky their trailer park permits DVB dishes, and that anyone using TOR to get there was going to SQL inject some truthin

Re: [tor-talk] Blockchain down.

2015-01-23 Thread Michael O Holstein
That "quota exceeded" message just sounds like somebody went over the limit on their vhost someplace. probably figured that traffic to localhost (via tor) didn't count but they were apparently wrong. my take anyway .. /mike. From: tor-talk on behalf of

Re: [tor-talk] SIGAINT email service targeted by 70 bad exit nodes

2015-04-23 Thread Michael O Holstein
>The question to me is: Do they all have something in common? What was the >vector of compromise? >Curiously enough, they all run Debian stable (according to the SSH version >string "SSH-2.0->OpenSSH_6.0p1 Debian-4+deb7u2” *ALL* of them spit out on port >22 — no exception!). FWIW a lot of Rasb

Re: [tor-talk] Running an exit node which exits on a different IP than it listens to

2014-06-24 Thread Michael O Holstein
Is the collateral damage from trying to play hide-and-seek from RBL services really worth it? .. the "overzealoous" RBL operators just want to catalog proxy servers so website ops can decide if they want the headache or not -- which is a perfectly valid concern. Overzealous is what happens when

Re: [tor-talk] Tor Exit Operator convicted in Austrian lower court

2014-07-02 Thread Michael O Holstein
>That is nonsense. Why not arrest the owners of a stainless steel blade >factory, because some people stab other people with those blades. Okay .. try giving knives away anonymously out of the back of your garage and let us know how you make out. tl;dr .. don't tell the world to use TOR for host

Re: [tor-talk] Funny, but not amusing browsing

2014-07-03 Thread Michael O Holstein
>I got worried yesterday when instead of the Wikipedia logo on the >top-left corner there was the picture of a nazi (army) guy with a Is this reproducible? To successfully (without error) insert into an HTTPS connection you must be trusted by the client .. would need list of CAcerts from firefo