Re: Shadow TCP stacks

2014-10-20 Thread Ian Grant
On Mon, Oct 20, 2014 at 8:01 PM, Giancarlo Razzolini wrote: > On 20-10-2014 21:52, Ian Grant wrote: >> >> How else can one protect a system from DoS attacks, other than by >> concealing it some way? And what is cryptography if it's not >> concealing the meanin

Re: Shadow TCP stacks

2014-10-20 Thread Ian Grant
On Mon, Oct 20, 2014 at 8:33 AM, Giancarlo Razzolini wrote: > On 19-10-2014 21:01, Ian Grant wrote: > > On the contrary: it _will_ make it impossible for people to know what > _we_ are doing. This is not one system I'm talking about: it's > countless independent VPNs. N

Re: Shadow TCP stacks

2014-10-20 Thread Ian Grant
On Mon, Oct 20, 2014 at 6:18 PM, john slee wrote: > On 20 October 2014 14:13, Worik Stanton wrote: >> Yes all traffic of a country can be analysed, fairly close to real time. >> With some basic statistics, smart sampling and a dedicated team >> crafting cleaver algorithms... That is what those

Security Engineering for Linux Users

2014-10-19 Thread Ian Grant
"This is one way die-hard Linux users can find out what the word "engineering" really means. They can learn about OpenBSD without rebooting either their machines, or their minds. First read the man pages. OpenBSD man pages aren't documentation, they're literature, so you need to see them nicely fo

Re: LibreSSL 2.1.1 released.

2014-10-19 Thread Ian Grant
On Sat, Oct 18, 2014 at 11:36 AM, Reiner Jung wrote: > On Fri, 2014-10-17 at 16:52 -0400, Ian Grant wrote: >> On Thu, Oct 16, 2014 at 9:15 AM, Bob Beck wrote: >> > We have released LibreSSL 2.1.1- which should be arriving in the >> > LIbreSSL directory of an OpenBS

Re: Shadow TCP stacks

2014-10-19 Thread Ian Grant
On Sun, Oct 19, 2014 at 1:40 AM, Giancarlo Razzolini wrote: > This tcp shadow stack would do no good in preventing > people from learning what you're doing. It's security > through obscurity, even though the authors of the paper try to say > that it ain't. On the contrary: it _will_ make it impos

Re: LibreSSL 2.1.1 released.

2014-10-17 Thread Ian Grant
On Thu, Oct 16, 2014 at 9:15 AM, Bob Beck wrote: > We have released LibreSSL 2.1.1- which should be arriving in the > LIbreSSL directory of an OpenBSD mirror near you very soon. If I clone the GitHub repo from Bolivia, do I have to cut my eyeballs out or stand guilty of re-exporting munitions fro

Re: Shadow TCP stacks

2014-10-17 Thread Ian Grant
On Fri, Oct 17, 2014 at 2:49 PM, Bret Lambert wrote: > Well, if, as Herr Schroeder seems to be implying, this is used to > avoid port scans, I'd look for traffic to/from address:port which > don't show up on scans. That's why I want to hide it behind an ordinary service. >> Also, the VPN could b

Re: Shadow TCP stacks

2014-10-17 Thread Ian Grant
On Fri, Oct 17, 2014 at 4:24 AM, Bret Lambert wrote: > On Thu, Oct 16, 2014 at 02:48:22PM +0200, Martin Schr??der wrote: >> 2014-10-16 13:16 GMT+02:00 Kevin Chadwick : >> The impossibility to scan for services - which the NSA/GHCQ/... do. > > It's a good thing that traffic analysis isn't a thing,

Re: [Bulk] Re: Shadow TCP stacks

2014-10-15 Thread Ian Grant
On Wed, Oct 15, 2014 at 4:47 PM, Kevin Chadwick wrote: > On Sat, 11 Oct 2014 13:38:49 -0400 > Ian Grant wrote: > >> No, the "pre-shared keys" are communicated over the VPN, as are the >> keys which encrypt the VPN's own data as it appears in the actual T