Re: BetterPrivacy - necessary?

2010-09-30 Thread The Doctor
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

On 09/29/2010 02:19 PM, Matthew wrote:

 Are any other add-ons necessary or would people suggest I am now fully
 protected?

I am fond of using AdBlock Plus and Ghostery to suppress adverts and web
bugs (ideally so there is one less thing to worry about leaving records,
but it also speeds up browsing a little).  HTTPS-Everywhere is useful
for making sure that connections to some websites are encrypted to
provide a bit more privacy at the exit node.

- -- 

The Doctor [412/724/301/703]

PGP: 0x807B17C1 / 7960 1CDC 85C9 0B63 8D9F  DD89 3BD8 FF2B 807B 17C1
WWW: http://drwho.virtadpt.net/

Screaming right along at 9600 bps...

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkyku7YACgkQO9j/K4B7F8HJHQCbBVZ/4nRE1L4DH6w2vjnj47Na
QJwAn0TB8w49h4V4XCe/VPukAywj7/Ao
=+bZM
-END PGP SIGNATURE-
***
To unsubscribe, send an e-mail to majord...@torproject.org with
unsubscribe or-talkin the body. http://archives.seul.org/or/talk/


Torbutton 1.3.0-alpha: Community Edition!

2010-09-30 Thread Mike Perry
Release early and release often is the motto, or so I'm told.. Well
I never liked getting up early, but maybe we can at least try for
often with this one. But probably not..

Despite these shortcomings of mine (among others), Torbutton
1.3.0-alpha is the first release of Torbutton where most of the code
has come from our community members! 

This is great, because after many long years of Torbutton development,
I barely have enough time and sanity remaining to maintain bugfixes on
1.2.x. Not that I started with very much of either in the first place,
I suppose[1]...


And with that, it gives me great pleasure to announce Torbutton
1.3.0-alpha! Due to limitations of addons.mozilla.org, the alpha
series will only be available at the Tor website:
https://www.torproject.org/torbutton/releases/torbutton-1.3.0-alpha.xpi{,.asc}

This release features tor:// and tors:// urls that will
automatically enable Tor before loading the corresponding http or
https url. Useful for bookmarks of your tor sites, or sharing urls
with other Torbutton users to ensure that they load them safely
through Tor. It also features a cookie manager that attempts to allow
you to protect specific cookies that you want to preserve between Tor
modes, as well as intelligent referrer spoofing.

All three of these features were written by Kory Kirk, for his 2009
GSoC summer of code project. (What did I say about early?)

It also features support for a Transparent Proxy or Tor router (or
your regular connection), where Torbutton's protections can be enabled
without using any proxy. This feature was written by Jacob Appelbaum
and Kory Kirk.

These features should be regarded as *experimental*. In particular,
the cookie manager needs testing, to ensure that it is actually
properly protecting and deleting the right cookies, without leaking
them from state to state. Someone should also pay close attention to
the referrer behavior to ensure it is behaving sanely.

What little time I have for Torbutton development will be devoted to 
supporting Firefox 4, and trying to work through this neverending set
of bugs for 1.2.x: https://trac.torproject.org/projects/tor/report/14

However, it would be great if we could drum up some more community
interest in developing these and other features, too. In particular, I
think it would be really swell if the cookie manager could be extended
into providing a New Identity button, complete with an optional
timer to run periodically. There's tons of other potential features
waiting to be implemented in the Enhancements section of that trac
report, too.


Here is the complete ChangeLog for 1.3.0-alpha:

 * new: Support for transparent proxies in settings
   (patch from Jacob Appelbaum and Kory Kirk)
 * new: tor:// and tors:// url support to auto-toggle into tor mode
   (patch from Kory Kirk)
 * new: Cookie manager to allow individual Cookie protection
   (patch from Kory Kirk)
 * new: Add referrer spoofing based on modified same origin policy
   (patch from Kory Kirk)
 * new: Add DuckDuckGo.com as a Google captcha redirect destination
   (patch from aiden tighe)
 * bugfix: bug 1911: Fix broken useragent locale string on debian
   (patch from lunar)
 * bugfix: Fix captcha detection for encrypted.google.com


[1]. http://archives.seul.org/or/talk/Mar-2007/msg00417.html

-- 
Mike Perry
Mad Computer Scientist
fscked.org evil labs


pgp7g0wnUDodv.pgp
Description: PGP signature


Re: Torbutton 1.3.0-alpha: Community Edition!

2010-09-30 Thread Drake Wilson
Quoth Mike Perry mikepe...@fscked.org, on 2010-09-30 15:57:48 -0700:
 This release features tor:// and tors:// urls that will
 automatically enable Tor before loading the corresponding http or
 https url.

Ick.  This sort of layer-mixing is the sort that forces people to use
a certain protocol for no actual reason.  (Cf. the feed schema,
which similarly forces HTTP with a certain interpretation, last I
recall.)  Tor doesn't just work with HTTP, and URIs don't only refer
to HTTP resources, even if HTTP is one of the most popular protocols
in use today and possibly the only one many non-technical people would
recognize.

Is there a reason not to use something like tor+http and tor+https for
the schema, thus opening up the space for (as a facetious example)
tor+nntp or analogous usages later?

   --- Drake Wilson
***
To unsubscribe, send an e-mail to majord...@torproject.org with
unsubscribe or-talkin the body. http://archives.seul.org/or/talk/