Re: [guardian-dev] finally setting up direct donations

2018-04-30 Thread Abel Luck
Awesome Hans, that's cool. Also its good news that we got funding to give gp.i some love! ~abel Hans-Christoph Steiner: > > Hey all, > > Since the ISC grant includes work on moving guardianproject.info to a > static site generator, I wanted to include part of that work finally > adding direct

[guardian-dev] Privacy preserving anonymized nginx log config

2018-01-30 Thread Abel Luck
Does anyone know of a configuration solution for nginx to meet any or all of these bullet points? * log only the date, not the time or time zone * referer, ip, user-agent are never logged * country is logged by looking up the ip in a geoip database Ideally this would apply to both the standard

Re: [guardian-dev] Privacy preserving anonymized nginx log config

2018-02-13 Thread Abel Luck
nfigurations and identify 404s that should or shouldn't be happening. Best to disable error logs it seems, and only enable them when debugging. ~abel [0]: https://nginx.org/en/docs/ngx_core_module.html#error_log On January 30, 2018 7:11:59 PM GMT+02:00, micah <mi...@riseup.net> wrote: >Abel

[guardian-dev] stegdetect CVE

2018-10-31 Thread Abel Luck
An old project that GP had used for stegnography research has gotten a CVE submitted against it for an out-of-bound write which causes crashes and potential CE (I'm guessing). The details are hazy, but we ported this utility to Android in order to be able to run stegnographic detection from an

Re: [guardian-dev] UDP ASSOCIATE is not working with orbot using SOCKS5

2019-01-16 Thread Abel Luck
Unfortunately, Tor only supports TCP traffic. Can you switch to TCP? nanu sonu: > Dear Members, > > Can anyone please help me on this. > > > > On Thu, Jan 10, 2019 at 5:59 PM nanu sonu wrote: > >> >> Dear Members, >> >> I am using orbot to hide the data which is sending from one of my >>

[guardian-dev] ALERT: matrix.org compromised, change your IRC passwords

2019-04-12 Thread Abel Luck
Hey folks, Matrix.org's infra has been hacked. It was down all day yesterday, back up again this morning for a short time, them hacked again as the attacker regained a foothold. DO THESE THINGS: * You need to change your matrix.org/riot password, but you can't do this now as it is still offline

Re: [guardian-dev] ALERT: matrix.org compromised, change your IRC passwords

2019-04-12 Thread Abel Luck
x.org/issues/364 > > You should immediately remove the riot Debian repo since the install > process of deb packages runs things as root. You can see whether your > Debian-ish machine has this repo by doing: > > $ grep riot.im /etc/apt/sources.list /etc/apt/sources.list

Re: [guardian-dev] ALERT: matrix.org compromised, change your IRC passwords

2019-04-13 Thread Abel Luck
Marcus Hoffmann via guardian-dev: > > On 13.04.19 00:17, Kevin Steen wrote: >> On 12/04/2019 11:51, Abel Luck wrote: >>>>> >>>>> If you still have Riot open and it hasn't logged you out yet, you need >>>>> to export your E2E room keys so yo

Re: [guardian-dev] Fwd: NitroPad: Secure Laptop With Unique Tamper Detection

2020-03-04 Thread Abel Luck
doing those things better. Things like: >> >> * true free software support >> * hardware switches >> * repairability >> * conflict-free minerals >> >> .hc >> >> Abel Luck: >>> I have a Purism Librem v3 (the 13" model) and I have to say

Re: [guardian-dev] Fwd: NitroPad: Secure Laptop With Unique Tamper Detection

2020-03-05 Thread Abel Luck
Devrandom: > AFAIK, all librem laptops work with 32GB DIMMs, even though they are > not "certified". Are you sure? Even the old models? I have a Librem 13 v2 and was told by Purism support that 16GB is the maximum supported due to the mobo. It is also DDR3L not DDR4. AFAIK 32GB max mem landed

Re: [guardian-dev] Fwd: NitroPad: Secure Laptop With Unique Tamper Detection

2020-01-15 Thread Abel Luck
I have a Purism Librem v3 (the 13" model) and I have to say I am not very happy with it. From a privacy pov, it's nice. ME can be disabled manually. The hardware switches are very handy. Rather than ship binary blobs for the bluetooth driver, they left that feature out, not compromising. Which I

Re: [guardian-dev] Fwd: NitroPad: Secure Laptop With Unique Tamper Detection

2020-01-17 Thread Abel Luck
in a >> similar boat. I think we need to compare apples to apples here: what >> Nitrokey, Librem and Fairphone are trying to do is important, no other >> providers are doing those things better. Things like: >> >> * true free software support >> * hardware switches >

Re: [guardian-dev] jitsi-monitor to track basic data about all known public instances

2020-04-06 Thread Abel Luck
Nice work Hans! Reminds me of the XMPP compliance tester.. which serves a sligthly different purpose: list XMPP servers and the XEPs they support and suggest ones with secure settings. https://compliance.conversations.im/ Still, could be a nice UI inspiration. They used to have a list of all

Re: [guardian-dev] Android App Bundles

2021-04-29 Thread Abel Luck
Amogh Pradeep: I can see this being a problem for Guardian Project and other organizations like Tor, is there a discussion on this that I'm missing? There was some discussion about this almost a year ago https://lists.mayfirst.org/pipermail/guardian-dev/2020-June/thread.html However no