Re: [tor-talk] Cannot access tor onion sites via FF

2018-07-08 Thread Roger Dingledine
On Sun, Jul 08, 2018 at 06:35:40PM -0400, David Niklas wrote:
> 2. Where is the source code?

Building Tor Browser is ugly because of another critical feature that
it provides: reproducible, aka deterministic, builds. You can read more
about that feature here:
https://reproducible-builds.org/
and then if you want to build it yourself (it won't be easy), start at
https://gitweb.torproject.org/builders/tor-browser-build.git/tree/README

But in terms of just the source code changes (from the various Firefox
releases), check out
https://gitweb.torproject.org/tor-browser.git/
e.g.
https://gitweb.torproject.org/tor-browser.git/log/?h=tor-browser-60.1.0esr-8.0-1

> 3. Noscript is a poor man's privacy protector. I use scriptsafe. It has
> many JS fingerprinting protections. And yes, many sites do require JS. I
> block as much as possible by default.

One of the goals of Tor Browser is that Tor Browser users should blend
together as much as possible. So if you run javascript here and here
and here but not there and there and there, then this unique set of
configuration choices acts like a cookie for recognizing you. That's
why there's a security slider, to disable functionality in chunks so
that we don't splinter the anonymity sets too much.

--Roger

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


Re: [tor-talk] Cannot access tor onion sites via FF

2018-07-08 Thread David Niklas
On  Sun, 8 Jul 2018 02:54:19 -0400
Roger Dingledine  wrote:
>
> On Sat, Jul 07, 2018 at 11:19:49PM -0400, David Niklas wrote:
> > Hello,
> > I'm running firefox 61.0.1. I am trying to access the media outlet
> > defcon's onion site. https://media.defcon.org/ points me to:
> > http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/
> > 
> > I have network.dns.blockDotOnion false
> > network.http.referer.hideOnionSource true and
> > network.proxy.socks_remote_dns true.
> > Tor's https://check.torproject.org/ reports that I am using tor.  
> 
> You should first be aware that the right way to do what you want is to
> use Tor Browser. Using any other browser with Tor is likely to not
> provide the same behavior, protections, etc:
> https://www.torproject.org/projects/torbrowser/design/

Ah, finally I find out how the TBB has been changed.

> So if you have a great reason to not use Tor Browser, ok, but you are
> in expert mode territory. :)

1. I did not know what they changed.
2. Where is the source code?
3. Noscript is a poor man's privacy protector. I use scriptsafe. It has
many JS fingerprinting protections. And yes, many sites do require JS. I
block as much as possible by default.

> > This: http://www.idnxcnkne4qt76tg.onion/ is said to be the tor
> > projects home page which times out. Defcon's address returns "Unable
> > to connect" without any perceptible delay.  
> 
> This could be explained by a lot of things. My first thought is that the
> version of Tor you have is old, so it doesn't know about v3 onion
> service names (the longer safer kind). And my first suggestion for
> fixing it is to use Tor Browser.
> 
> Hope that helps,
> --Roger

Fixed. Now tor works, thanks!
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


Re: [tor-talk] Cannot access tor onion sites via FF

2018-07-08 Thread Roger Dingledine
On Sat, Jul 07, 2018 at 11:19:49PM -0400, David Niklas wrote:
> Hello,
> I'm running firefox 61.0.1. I am trying to access the media outlet
> defcon's onion site. https://media.defcon.org/ points me to:
> http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/
> 
> I have network.dns.blockDotOnion false
> network.http.referer.hideOnionSource true and
> network.proxy.socks_remote_dns true.
> Tor's https://check.torproject.org/ reports that I am using tor.

You should first be aware that the right way to do what you want is to
use Tor Browser. Using any other browser with Tor is likely to not
provide the same behavior, protections, etc:
https://www.torproject.org/projects/torbrowser/design/

So if you have a great reason to not use Tor Browser, ok, but you are
in expert mode territory. :)

> This: http://www.idnxcnkne4qt76tg.onion/ is said to be the tor projects
> home page which times out. Defcon's address returns "Unable to connect"
> without any perceptible delay.

This could be explained by a lot of things. My first thought is that the
version of Tor you have is old, so it doesn't know about v3 onion service
names (the longer safer kind). And my first suggestion for fixing it is
to use Tor Browser.

Hope that helps,
--Roger

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


[tor-talk] Cannot access tor onion sites via FF

2018-07-07 Thread David Niklas
Hello,
I'm running firefox 61.0.1. I am trying to access the media outlet
defcon's onion site. https://media.defcon.org/ points me to:
http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/

I have network.dns.blockDotOnion false
network.http.referer.hideOnionSource true and
network.proxy.socks_remote_dns true.
Tor's https://check.torproject.org/ reports that I am using tor.
This: http://www.idnxcnkne4qt76tg.onion/ is said to be the tor projects
home page which times out. Defcon's address returns "Unable to connect"
without any perceptible delay.

The reason I am trying to reach defcon over tor is that my connection to
them is plagued with connection and speed problems. First I tried their
torrents, but after a few minutes rtorrent returned an SSL connection
error, and a torrent not allowed on this server error. I notified defcon
and now the tracker is down. Not even a ping responce.
Second, I tried the media server directly, at first it worked and I could
download. An hour later or so, the server began returning SSL connection
problems. Here is a curl dump:

% curl --trace-ascii - \
-o 'Hacking Related Documentaries x265/DEF CON 20 Documentary 1080p
x265.mp4' \ --continue - \
'https://media.defcon.org/Hacking%20Related%20Documentaries%20x265/
DEF%20CON%2020%20Documentary%201080p%20x265.mp4'

** Resuming transfer from byte position 471530444 % Total% Received %
Xferd  Average Speed   TimeTime Time  Current Dload  Upload
Total   SpentLeft  Speed 0 00 00 0  0  0
--:--:-- --:--:-- --:--:-- 0

== Info:   Trying 162.222.171.207...
== Info: TCP_NODELAY set
== Info: Connected to media.defcon.org (162.222.171.207) port 443 (#0) ==
Info: ALPN, offering h2 == Info: ALPN, offering http/1.1
== Info: Cipher selection:
ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH == Info:
successfully set certificate verify locations: == Info:
CAfile: /etc/ssl/certs/ca-certificates.crt CApath: /etc/ssl/certs
== Info: TLSv1.2 (OUT), TLS header, Certificate Status (22):
=> Send SSL data, 5 bytes (0x5)
: .
== Info: TLSv1.2 (OUT), TLS handshake, Client hello (1):
=> Send SSL data, 512 bytes (0x200)
: ..v...C.[B..@.k8.4...n0.,.(.$.k.
0040: j.i.h.9.8.7.6.2...*.&...=.5.../.+.'.#.g.
0080: @.?.>.3.2.1.0.E.D.C.B.1.-.).%...<./...A.G...
00c0: ..media.defcon.org... ..
0100: ...3t.h2.http/1.1...
0140: 
0180: 
01c0: 

  0 00 00 0  0  0 --:--:--  0:00:14
  --:--:-- 0

== Info: Unknown SSL protocol error in connection to media.defcon.org:443
== Info: Curl_http_done: called premature == 1
== Info: stopped the pause stream!

  0 00 00 0  0  0 --:--:--  0:00:15
  --:--:-- 0

== Info: Closing connection 0
curl: (35) Unknown SSL protocol error in connection to
media.defcon.org:443

It is now going again. For about 30min it was moving at 1/10th speed, now
it is going faster. This is very strange to me...
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk