Re: TBB in a sandbox (osx)

2010-10-27 Thread Roger Dingledine
On Tue, Oct 05, 2010 at 11:31:25PM +0200, Andreas Jonsson wrote: Hi List! I've been working with Erinn to sandbox the TBB much like chrome and ironfox are on osx, but now I think we need some opinions regarding where to go next. See this page for more information on what the sandbox is

Re: New Bundle Version 1.3.10

2010-10-27 Thread Erinn Clark
* M moeedsa...@gmail.com [2010:10:16 18:48 +]: Why the switch to noscript? and link on the issue? Hey there, I am working on writing this up -- I sat down with Mike Perry, the Torbutton developer, and we went over what each of the Firefox extensions added. It's not in any kind of proper

Re: Question about torbrowser for mac

2010-10-27 Thread Erinn Clark
* Justin Aplin jmap...@ufl.edu [2010:10:27 01:46 -0400]: Thats why i was confirning whether the torbutton was intentionally left our of the package and covered by noscript I don't see Torbutton installed either (latest browser bundle on OSX 10.5), but I was under the assumption that the

Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Matthew
Hello, There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. The section on proxies includes Tor-related information which I fail to understand: You may actually get more anonymity when using the Tor cloud by *not* using the https:// version of a web page

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Jan Weiher
Hi, I don't understand, too and in my opinion, this is utter nonsense. I'm not aware of any negative impacts on privacy due to the usage of https://, but without, there is the danger of eavesdropping at the exit node. best regards, Jan Am 27.10.2010 20:19, schrieb Matthew: Hello, There

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Sebastian Hahn
On Oct 27, 2010, at 8:19 PM, Matthew wrote: Hello, There is a “Hints and Tips for Whistleblowers Guide” available at http://ht4w.co.uk/ . The section on proxies includes Tor-related information which I fail to understand: You may actually get more anonymity when using the Tor cloud by

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Joe Btfsplk
On 10/27/2010 1:19 PM, Matthew wrote: Hello, There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. Thanks for the link. -How on earth can it be mistaken to insist on using https:// encryption? Why would using https:// betray the real IP addresses?

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Jan Weiher
Hi, Am 27.10.2010 20:55, schrieb Joe Btfsplk: On 10/27/2010 1:19 PM, Matthew wrote: Hello, There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. Thanks for the link. I'm not sure this is a good ressource, due to the misinformation it is spreading. Don't

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread coderman
On Wed, Oct 27, 2010 at 11:49 AM, Jan Weiher j...@buksy.de wrote: ... I'm not aware of any negative impacts on privacy due to the usage of https://, client certificates, although fortunately these are difficult to leverage surreptitiously... ... but without, there is the danger of

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Andrew Lewman
On Wed, 27 Oct 2010 19:19:02 +0100 Matthew pump...@cotse.net wrote: There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. The first problem is the content is actually served up by hostingprod.com and not ht4w.co.uk. As far as the content in question, it is

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Jan Weiher
Am 27.10.2010 21:04, schrieb Andrew Lewman: On Wed, 27 Oct 2010 19:19:02 +0100 Matthew pump...@cotse.net wrote: There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. The first problem is the content is actually served up by hostingprod.com and not

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread krishna e bera
The bad advice may be a misinterpretation or poor rephrasing of this advice in the Tor FAQ Wiki: https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TorFAQ#WhyisitbettertoprovideahiddenserviceWebsitewithHTTPratherthanHTTPSaccess

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Seth David Schoen
Jan Weiher writes: Hi, I don't understand, too and in my opinion, this is utter nonsense. I'm not aware of any negative impacts on privacy due to the usage of https://, Session resumption can be used to recognize an individual browser that connects from different IP addresses, or even over

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread startx
On Wed, 27 Oct 2010 15:35:27 -0400 krishna e bera k...@cyblings.on.ca wrote: The bad advice may be a misinterpretation or poor rephrasing of this advice in the Tor FAQ Wiki:

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Roger Dingledine
On Wed, Oct 27, 2010 at 07:19:02PM +0100, Matthew wrote: There is a Hints and Tips for Whistleblowers Guide available at http://ht4w.co.uk/. The section on proxies includes Tor-related information which I fail to understand: You may actually get more anonymity when using the Tor cloud

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Joe Btfsplk
On 10/27/2010 2:35 PM, krishna e bera wrote: The bad advice may be a misinterpretation or poor rephrasing of this advice in the Tor FAQ Wiki: https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TorFAQ#WhyisitbettertoprovideahiddenserviceWebsitewithHTTPratherthanHTTPSaccess

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Mike Perry
Thus spake Seth David Schoen (sch...@eff.org): Hi, I don't understand, too and in my opinion, this is utter nonsense. I'm not aware of any negative impacts on privacy due to the usage of https://, Session resumption can be used to recognize an individual browser that connects from

Re: Hints and Tips for Whistleblowers - their comments on Tor and SSL - I don't understand.

2010-10-27 Thread Seth David Schoen
Mike Perry writes: Thus spake Seth David Schoen (sch...@eff.org): Hi, I don't understand, too and in my opinion, this is utter nonsense. I'm not aware of any negative impacts on privacy due to the usage of https://, Session resumption can be used to recognize an individual

Re: Question about torbrowser for mac

2010-10-27 Thread Aplin, Justin M
On 10/27/2010 6:16 AM, Erinn Clark wrote: This is actually a weird Firefox thing -- depending on where you install the extensions, they either show up in the add-on list or they don't. The Torbutton extension is installed somewhere different from the other extensions, because that was how I got

Re: Question about torbrowser for mac

2010-10-27 Thread Erinn Clark
* Erinn Clark er...@torproject.org [2010:10:27 10:16 +]: I'll see if it will actually work in another location so it'll show up, because it should. It just didn't originally. Fixed in master: https://gitweb.torproject.org/torbrowser.git/commitdiff/0bb1302a23d4e41b262d03185a33099fdc2a5964