Re: Country-code exit broken in 0.2.2.21-alpha?

2011-01-23 Thread Nick Mathewson
On Sun, Jan 23, 2011 at 2:42 PM, Geoff Down geoffd...@fastmail.net wrote: Hi list,  I know for a fact that there is at least one GB exit running, but ExitNodes {gb} StrictNodes 1 no longer works - no circuits get built. Tor 0.2.2.21-alpha (git-5f63f0d6312d9f0d) PPC OSX10.3.9 No flags next

Re: Double log entries?

2011-01-06 Thread Nick Mathewson
On Wed, Jan 5, 2011 at 9:32 PM, Geoff Down geoffd...@fastmail.net wrote: Hi All, Happy New Year.  I have double entries, including the timestamp, in my Notice-level Tor  logs. I think it started when I sent a SIGHUP. lsof shows two Write  file descriptors fwiw. This is Tor 0.2.2.15-alpha OSX

Re: Key length and PK algorithm of TOR

2010-12-31 Thread Nick Mathewson
On Fri, Dec 31, 2010 at 5:10 PM, and...@torproject.org wrote: On Fri, Dec 31, 2010 at 09:21:53PM +0100, canconsult...@web.de wrote 0.6K bytes in 20 lines about: : 1) is there a specific reason why TOR does use RSA with : a keylength of only 1024 Bit? Start here,

Re: 27C3 on Tor

2010-12-28 Thread Nick Mathewson
On Tue, Dec 28, 2010 at 8:27 PM, Roc Admin onionrou...@gmail.com wrote: This doesn't seem like much of a flaw as it is a design decision. See https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TorFAQ#Youshouldsendpaddingsoitsmoresecure. I'm not trying to dismiss the researcher but

Re: Tor 0.2.1.26-1~~lenny+1: segfault with libcryto.so.0.9.8

2010-11-17 Thread Nick Mathewson
On Fri, Nov 12, 2010 at 5:49 PM, Paul Menzel paulepan...@users.sourceforge.net wrote: Dear Tor folks, I noticed that Tor had crashed on my system. I am using Debian Lenny with Tor 0.2.1.26-1~~lenny+1. The only thing I could find out about this crash is the following line running `dmesg`.  

Re: AdvTor

2010-10-07 Thread Nick Mathewson
On Thu, Oct 7, 2010 at 4:32 AM, Anon Mus my.green.lant...@googlemail.com wrote: On Sun, Oct 3, 2010 at 2:05 PM, kalitnik...@privatdemail.net wrote: Hello everyone. I found a fork (?) of tor software with GUI named Advanced Tor. I was surprised of its features, but found just nothing about it

Re: Stop TOR from building circuits in the background?

2010-10-06 Thread Nick Mathewson
On Wed, Oct 6, 2010 at 8:47 AM, Brian Johnson brian_john...@gmx.net wrote: Hello, I am using the -controlport Commands to build custom Circuits. My problem with this is that I cannot trust TOR to use these circuits. It keeps building new ones which were not requested by me via the command

Re: tor and resolv.conf / ipv6

2010-09-02 Thread Nick Mathewson
On Thu, Sep 2, 2010 at 12:10 PM, Udo van den Heuvel udo...@xs4all.nl wrote: On 2010-09-02 17:34, Udo van den Heuvel wrote: Tor chokes and stops when it finds ipv6 numbers in resolv.conf. Is this a known issue? Sadly, yeah. As a workaround, if you build Tor with Libevent 2.0.x, Tor will use

Re: Vulnerability in OpenSSL 1.0.x Firefox 4 Silent Updates

2010-08-13 Thread Nick Mathewson
On Wed, Aug 11, 2010 at 2:42 AM, whowatchesthewatcherswatc...@safe-mail.net wrote: Vulnerability in OpenSSL 1.0.x http://marc.info/?t=12811816911r=1w=2 http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0085.html Tor server/client use vuln? Looking at the claims, it seems to

Re: Why not TOR come up with an encryption system?

2010-06-07 Thread Nick Mathewson
On Mon, Jun 7, 2010 at 6:03 AM, Sebastian Hahn m...@sebastianhahn.net wrote: On Mon, June 7, 2010 4:26 am, emigrant wrote: i mean apart from anonymity, can it have something to do the work of SSL? i mean for all connection. thanks a lot No, this is not possible. To do the work of SSL, you

Re: Tor Problems on Korean Windows

2010-05-12 Thread Nick Mathewson
On Tue, May 11, 2010 at 6:31 PM, Kees keesv...@gmail.com wrote: I recently installed tor on the windows machine of a Korean friend and it did not want to work. After a lot of messing about we worked out the the problem was his Korean user name in the path to the torrc file. Once we moved the

Re: messages indicate strange choice by tor

2010-05-12 Thread Nick Mathewson
On Wed, Apr 14, 2010 at 10:02 AM, Scott Bennett benn...@cs.niu.edu wrote:     I would be most interested in knowing the explanation for the decision that tor announced in the following pair of messages. Apr 14 08:55:50.861 [info] connection_or_group_set_badness(): Marking OR conn to

Re: Bug in .tmp file handling

2010-04-28 Thread Nick Mathewson
On Sat, Mar 20, 2010 at 1:45 PM, grarpamp grarp...@gmail.com wrote: Note the double .tmp file extension. Added as bug 1376. Thanks! -- Nick *** To unsubscribe, send an e-mail to majord...@torproject.org with unsubscribe

Re: Advertising multiple ORPorts at once

2010-03-19 Thread Nick Mathewson
On Fri, Mar 19, 2010 at 11:26 AM, hiro 23h...@googlemail.com wrote: Hi, I've been skimming over the gsoc ideas. The Tor 0.2.1.x series makes significant improvements in resisting national and organizational censorship. But Tor still needs better mechanisms for some parts of its

Re: tor 0.2.1.24 crashes on Sparc-Solaris10

2010-03-10 Thread Nick Mathewson
On Wed, Mar 10, 2010 at 3:47 PM, thomas.hluch...@netcologne.de wrote: Am Dienstag 09 März 2010 schrieb Roger Dingledine: On Tue, Mar 09, 2010 at 08:23:30PM +0100, thomas.hluch...@netcologne.de wrote: When starting tor it comes up but crashes within one minute. Try these:

Re: tor 0.2.1.24 crashes on Sparc-Solaris10

2010-03-09 Thread Nick Mathewson
On Tue, Mar 9, 2010 at 2:23 PM, thomas.hluch...@netcologne.de wrote: [...] Any ideas, any help? Can you get a stack trace? That's usually the best way to start debugging a crash. -- Nick *** To unsubscribe, send an e-mail

Re: getinfo circuit-status

2010-02-15 Thread Nick Mathewson
On Sat, Feb 13, 2010 at 3:21 PM, Nico Weinreich i...@web-unity.de wrote: Hi, when interacting with tor control I can get the circuit with command getinfo circuit-status. What's a bit confusing for me, there are more than one circuits: getinfo circuit-status 250+circuit-status= 51 BUILT

Re: getinfo circuit-status

2010-02-15 Thread Nick Mathewson
On Mon, Feb 15, 2010 at 2:17 PM, Nico Weinreich i...@web-unity.de wrote: [...] OK, thanks for this very detailed explaination. But is there a way to get (before or after a HTTP request) the circuit which will be (or was) used? If you watch for STREAM events, you'll learn which streams get

Re: Path-spec - fast circuits

2010-02-12 Thread Nick Mathewson
2010/2/12 ilter yüksel ilteryuk...@gmail.com: Hello, For exit router selection path-spec says that; For circuits that do not need to be fast, when choosing among multiple candidates for a path element, we choose randomly. For fast circuits, we pick a given router as an exit with probability

Re: Nodes selection algorithm

2010-02-12 Thread Nick Mathewson
On Mon, Feb 8, 2010 at 10:02 AM, Mansur Marvanov nanorobo...@gmail.com wrote: Oh, I got the meaning of exit-nodes: it's for selection the preferred country as exit of your route. But still the question is How Tor choose the route? The best specification of this is in the path-spec.txt

Re: What means that log record?

2010-02-12 Thread Nick Mathewson
On Mon, Feb 8, 2010 at 12:27 AM, Soviet Union unionsovietun...@aol.com wrote: I have some the next recored in logs of the Tor: [warn] Bug: Duplicate call to connection_mark_for_close at connection.c:1175 (first at connection_edge.c:1618) What mean that bug and what I need to do? (or not I need

Re: Bringing back Tor on the iPhone - take 2

2010-02-04 Thread Nick Mathewson
On Tue, Feb 2, 2010 at 8:13 AM, Marco Bonetti marco.bone...@slackware.it wrote: [...] 1) strictly related to tor: I build the latest stable release *WITHOUT* the --enable-iphone switch. As I can understand from the post linked above, that option will jusr add some compiler flags needed only by

Re: Memory usage on relays

2010-01-19 Thread Nick Mathewson
On Tue, Jan 19, 2010 at 4:18 AM, Olaf Selke olaf.se...@blutmagie.de wrote: Nn6eumtr wrote: Binaries are staticly linked so that someone can't substitute a replacement library. Otherwise you can replace the library or set LDPRELOAD to implement a variety of attacks. can you give an example

Re: Memory usage on relays

2010-01-18 Thread Nick Mathewson
On Sun, Jan 17, 2010 at 11:29 PM, John Brooks spec...@dereferenced.net wrote: [...] As a vaguely related sidenote, is it intentional that openssl is statically linked? I would expect that Tor more than anything would want to benefit from security updates as quickly as possible, and most

Re: Memory usage on relays

2010-01-17 Thread Nick Mathewson
On Sun, Jan 17, 2010 at 9:36 PM, Roger Dingledine a...@mit.edu wrote: On Sun, Jan 17, 2010 at 06:41:03PM -0700, John Brooks wrote: I run a reasonably fast (500KB/s) node with Guard+Fast+Stable, so it's a popular destination. It runs at bandwidth capacity at all times. The only problem with

Re: Failed to decode requested authority digest

2010-01-15 Thread Nick Mathewson
Quoth Nick Mathewson ni...@torproject.org, on 2010-01-14 21:49:33 -0500: Nevermore! Jan 12 08:57:59.119 [warn] Failed to decode requested authority digest 14C131%2027B6B5%20585769%2081349F%20E2A2AF%20E8A9C4. Jan 14 11:40:05.641 [warn] Failed to decode requested authority digest 14C131

Re: Latest router selection algorithm

2010-01-15 Thread Nick Mathewson
2010/1/10 ilter yüksel ilteryuk...@gmail.com: Hello, I'm searching latest router selection algorithm which implemented on Tor 0.2.1.21. I couldn't find spec. or proposal for it. Could you help me how i can find some docs about it? The best document is still path-spec.txt, though proposals

Re: Failed to decode requested authority digest

2010-01-14 Thread Nick Mathewson
On Thu, Jan 14, 2010 at 9:12 AM, Olaf Selke olaf.se...@blutmagie.de wrote: Olaf Selke wrote: since a couple of days tor logs an error condition about every 32 hours. Even looking at the code I don't really understand the cause. Jan 07 00:56:46.100 [warn] Failed to decode requested authority

Re: TLS Man-In-The-Middle Vulnerability

2009-11-11 Thread Nick Mathewson
On Wed, Nov 11, 2009 at 12:59:21PM -0500, Andrew S. Lists wrote: On 11/05/09 15:52, Nick Mathewson wrote: On Thu, Nov 05, 2009 at 02:10:00PM -0500, Marcus Griep wrote: Don't know if any one else has seen or taken a look at this. I don't know if this affects Tor, though I believe that we

Re: TLS Man-In-The-Middle Vulnerability

2009-11-05 Thread Nick Mathewson
On Thu, Nov 05, 2009 at 02:10:00PM -0500, Marcus Griep wrote: Don't know if any one else has seen or taken a look at this. I don't know if this affects Tor, though I believe that we do use certificate renegotiation in the protocol, and that is the entry vector for this particular

Re: 0.2.2.5-alpha doesn't know how to make libtor.a

2009-10-18 Thread Nick Mathewson
On Sun, Oct 18, 2009 at 10:40:44AM -0500, Scott Bennett wrote: After running './configure CFLAGS=-march=prescott', a 'make' in the top (tor-0.2.2.5-alpha) directory did the following. I can't reproduce this; can you say more about your toolchain? What OS are you getting this on? Whose

Re: Random chaff [was: more work for Grobbages]

2009-09-23 Thread Nick Mathewson
On Fri, Sep 18, 2009 at 10:19:17PM -0400, Ted Smith wrote: On Fri, 2009-09-18 at 04:25 -0400, grarpamp wrote: Nodes usually have a max bandwitch set. Nodes often comsume less than this. All node to node traffic is encrypted. Perhaps implement a random stream generator that only runs

Re: unable to submit bug report

2009-06-05 Thread Nick Mathewson
On Fri, Jun 05, 2009 at 02:41:53AM -0500, Scott Bennett wrote: On Fri, 05 Jun 2009 00:45:11 -0600 Jon scr...@nonvocalscream.com wrote: Scott Bennett wrote: Well, I *intended* to submit a bug report, but appear to be unable to log into the bugs.torproject.org web site to do so. I

The Git conversion is done.

2009-04-29 Thread Nick Mathewson
Tor is now in Git. The repository is at git://git.freehaven.net/git/tor.git There is also a historical-interest repository at git://git.freehaven.net/git/tor-history.git It has all the obsolete branches that we would never have put into svn in the first place if we had been working with a

Re: The Git conversion is done.

2009-04-29 Thread Nick Mathewson
On Thu, Apr 30, 2009 at 12:57:30AM -0400, Nick Mathewson wrote: Tor is now in Git. The repository is at git://git.freehaven.net/git/tor.git There is also a historical-interest repository at git://git.freehaven.net/git/tor-history.git ARGH. That should be git.torproject.org

Be ready: We're switching version control systems

2009-04-24 Thread Nick Mathewson
://www.kernel.org/pub/software/scm/git/docs/user-manual.html yrs, -- Nick Mathewson

Re: Segfaults on tor-0.2.12-alpha and tor-0.2.0.34

2009-02-21 Thread Nick Mathewson
On Sat, Feb 21, 2009 at 11:12:35AM -0800, Phil wrote: This is driving me nuts. tor compiles fine but segfaults soon after starting. I have googled and found similar complaints but no solution. [...] How do I fix this? Can you get a stack trace? See

Re: Excludenodes not considered?

2009-02-16 Thread Nick Mathewson
On Sun, Feb 15, 2009 at 08:12:44AM -0500, forc...@safe-mail.net wrote: I have in my torrc file this line: Okay. Thanks to help from lark on IRC, I think we've chased this one down. It should be fixed in r18575 in trunk. If anybody else can build from source and try it out, that'd be great.

Reminder: Please use the friendly bugtracker.

2009-02-15 Thread Nick Mathewson
know that the 'flyspray' tracker is annoying. Some time around when we start 0.2.2.x development, we'll probably be switching to Trac.) Thanks again for everybody's help in making a better Tor! yrs, -- Nick Mathewson

Re: No such file or directory: router-stabilit; unverified-consensus, cached-extrainfo

2009-02-15 Thread Nick Mathewson
On Sat, Feb 14, 2009 at 03:33:23AM -0800, Germershausen wrote: I am using the Debian testing package with tor 0.2.0.34-1 and I am getting some error messages in my debug.log. Maybe i can ignore those lines or not? You can ignore those; they're at level info. If they were important they'd be

Re: Excludenodes not considered?

2009-02-15 Thread Nick Mathewson
On Sun, Feb 15, 2009 at 08:12:44AM -0500, forc...@safe-mail.net wrote: I have in my torrc file this line: ExcludeNodes {de},xxx,yyy Despite the German nodes should not be used, some circuits use some of them, right now for example LavendarMan (Online) Location: Worms, DE IP Address:

Re: Grrr...SafeLogging doesn't work in 0.2.1.12-alpha :-{

2009-02-10 Thread Nick Mathewson
On Tue, Feb 10, 2009 at 02:59:44PM -0500, Roger Dingledine wrote: [..] All of that said, at some point we should teach clients to discard v3 certs from authorities they don't recognize. Otherwise they'll just sit around in the cached-certs file taking up space. I'll put that on the todo list.

Re: Some Bones to Pick with Tor Admins

2009-02-10 Thread Nick Mathewson
On Tue, Feb 10, 2009 at 06:24:27PM -0500, Ted Smith wrote: On Tue, 2009-02-10 at 18:17 -0500, Ringo Kamens wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 It absolutely would. Here are some things TorButton defends against that wouldn't be covered in your scenario: 1.

Tor on win98 [was Re: Some Bones to Pick with Tor Admins]

2009-02-10 Thread Nick Mathewson
On Tue, Feb 10, 2009 at 04:51:42PM -0700, mark485ander...@eml.cc wrote: Maybe not many users because Tor's last two versions are buggy and don't allow them to use it? Still plenty of 98se users out there and I have 3 browsers now that can use tor safely. course they will not work on .33 and

Re: another BADEXIT found $8424E8653469B1EFF87E79E8599933A3BAF8FDB2

2009-02-09 Thread Nick Mathewson
On Mon, Feb 09, 2009 at 11:10:28PM -0600, Scott Bennett wrote: [...] I think it would be a useful modification for the authorities to be able to flag IP addresses and address ranges with BadExit in addition to being able to flag nicknames and key fingerprints. That way, when a case like

Re: Lame and unimportant

2009-01-23 Thread Nick Mathewson
On Fri, Jan 23, 2009 at 04:39:42PM -0500, Justin Coffi wrote: Line 834 in log.c has a typo. I caught it in .2.1.9-alpha and told myself that if I saw it in the next upgrade I'd say something. I just spotted it in 0.2.1.11-alpha. log_warn(LD_CONFIG, No such loggging domain as

Re: command line control software

2009-01-20 Thread Nick Mathewson
On Tue, Jan 20, 2009 at 11:18:33PM +0300, ivvmm wrote: Hello, Is there any command line control software? Excuse me for that question. Just read control-spec.txt and found it very easy to talk to Tor server via telnet. But it would be rather convenient to use some tuned tool. Check out

Re: cannot compile 0.2.1.10-alpha

2009-01-20 Thread Nick Mathewson
other issue. Could it be some kind of resource exhaustion thing? I didn't think that XP Server had that kind of problem. The diagnostic and workaround approaches people discussed at bug 98 may be apropos. (That reminds me: I must get back to libevent hacking!) yrs, -- Nick Mathewson

Re: tor over ipv6

2009-01-19 Thread Nick Mathewson
On Mon, Jan 19, 2009 at 07:54:53PM +0100, Udo van den Heuvel wrote: Just a thought: With the previous tor experiences in mind w.r.t. services blocking me, I thought about IPv6. I could run a somewhat open relay on an IPv6 number via a IPv6 in IPV4 tunnel if I (ever) get that to work. My

Re: cannot compile 0.2.1.10-alpha

2009-01-14 Thread Nick Mathewson
compress it and send a copy to me and coderman, if you could.) thanks, -- Nick Mathewson ni...@freehaven.net

Re: tor controlport wants authentication even if authentication is switched off

2009-01-08 Thread Nick Mathewson
On Wed, Jan 07, 2009 at 11:59:41PM +0100, Sebastian Schmidt wrote: Thanks for your reply now I understand :) ! But this isn't explained in control-spec.txt. Good point. I've cleaned it up a bit. Thanks! yrs, -- Nick

Re: tor controlport wants authentication even if authentication is switched off

2009-01-07 Thread Nick Mathewson
On Wed, Jan 07, 2009 at 07:03:03PM +0100, Sebastian Schmidt wrote: [...] Why does TC tell me authentication is required even if it's switched off? Or is this the default reply if a not supported command was given to it? Even if authentication is turned off, the first command on the control

Re: SSL certificate checker plugin for Firefox?

2008-12-31 Thread Nick Mathewson
On Wed, Dec 31, 2008 at 01:21:53PM +0100, Matej Kovacic wrote: Hi, problaby you have seen that: http://www.phreedom.org/research/rogue-ca/md5-collisions-1.0.ppt My question is - is there a plugin for Firefox, which saves info about certificate of a website. When user comes back next time,

Re: Tor on Android

2008-12-28 Thread Nick Mathewson
can tell, I'd like 0.2.1.x to build out-of-the-box for Android, especially given how little code changing seems to be required. Yrs, -- Nick Mathewson

Re: Tor on Android

2008-12-28 Thread Nick Mathewson
On Sun, Dec 28, 2008 at 07:24:17PM -0800, Adam Langley wrote: On Sun, Dec 28, 2008 at 6:30 PM, Nick Mathewson ni...@freehaven.net wrote: Hm. Libevent should be made to detect this. Ordinarily, fd_mask is defined in sys/select.h or something it includes. Can you grep around a little

Re: Tor on Android

2008-12-28 Thread Nick Mathewson
On Sun, Dec 28, 2008 at 08:01:26PM -0800, Adam Langley wrote: On Sun, Dec 28, 2008 at 7:24 PM, Adam Langley a...@imperialviolet.org wrote: from reading around, fd_mask is POSIX. Rather than change libevent, probably bionic should be changed. Nick, does this work for you?

Re: [Fwd: (Probably) a known problem?] - cant run a relay node

2008-12-12 Thread Nick Mathewson
On Wed, Dec 03, 2008 at 11:52:50AM -0500, pho...@rootme.org wrote: [...] A few things, you probably haven't received a response because no one has a good idea how to fix it. You may have 2 issues, one is that libevent can't find nameservers, and the other is that the config options are

Re: [Fwd: (Probably) a known problem?] - cant run a relay node

2008-12-12 Thread Nick Mathewson
On Wed, Dec 03, 2008 at 06:35:19PM +0100, Fabian Keil wrote: [...] While we're talking about DNS issues, I recently got: Nov 30 06:25:02.803 [notice] Tor 0.2.1.6-alpha (r17011) opening new log file. Nov 30 06:25:02.818 [warn] eventdns: Unable to add nameserver 164.148.169.81: error 2 Nov

Re: Tor cleverness?

2008-11-17 Thread Nick Mathewson
On Mon, Nov 17, 2008 at 06:54:49PM +, Geoff Down wrote: Hi, two questions: I renamed (with 'mv') the file I was sending Tor logs to whilst Tor was running. I actually moved it to a different directory. The log data kept being written to that file. How? Welcome to Unix. :) A file on

Re: Any plans to fix tor for OpenDNS?

2008-11-13 Thread Nick Mathewson
On Thu, Nov 13, 2008 at 11:17:20AM -0500, Praedor Atrebates wrote: I use OpenDNS servers and tor messages always contain a message that my service provider may be hijacking DNS requests. It isn't a problem for functionality of tor but it is somewhat annoying to see that warning all the

Re: Problems runing Tor on Vista x64

2008-11-11 Thread Nick Mathewson
On Mon, Nov 10, 2008 at 11:51:45PM -0500, [EMAIL PROTECTED] wrote: On Mon, Nov 10, 2008 at 09:51:00AM +0100, [EMAIL PROTECTED] wrote 0.7K bytes in 16 lines about: : Nov 10 09:34:42.445 [err] Error from libevent: evsignal_init: : socketpair: No error It reads like libevent doesn't like

Re: SANS Paper: Detecting Tor

2008-11-09 Thread Nick Mathewson
On Sun, Nov 09, 2008 at 09:54:53PM -0500, Roc Admin wrote: I just read this article in the SANS reading room called Detecting and Preventing Anonymous Proxy Usage http://www.sans.org/reading_room/whitepapers/detection/32943.php Cosmetic issues: 1) It's Tor, not TOR. 2) The paper

Re: any middlemen seeing DoS currently?

2008-11-09 Thread Nick Mathewson
On Fri, Nov 07, 2008 at 01:38:28PM +0100, Eugen Leitl wrote: I've seen continuous table state increase since about 3.5 hours. It went up from 1 k baseline to 5 k. Anyone else seeing this? Any alternative explanation to DoS? (ISP throttling?). Judging by the timing, I'd think it might be

Re: php hex code for cookie authentication to controller?

2008-10-21 Thread Nick Mathewson
On Tue, Oct 21, 2008 at 11:52:33AM -0700, Wesley Kenzie wrote: per 5.1 Authentication in control-spec.txt: To authenticate, the controller must send the contents of this file, encoded in hexadecimal. Fine, but when using the following in PHP: $ch = fopen('cookiefilename', 'r');

Re: php hex code for cookie authentication to controller?

2008-10-21 Thread Nick Mathewson
On Tue, Oct 21, 2008 at 04:29:08PM -0700, Wesley Kenzie wrote: What's the actual length of $auth_value? If it's not AUTHENTICATION_COOKIE_LEN (32, I think), that's when I'd expect that error. Thanks, Nick. The length of $auth_value is 32 though, and the length of bin2hex($auth_value) is 64.

Re: Tor 0.2.1.5-alpha is out

2008-09-11 Thread Nick Mathewson
On Thu, Sep 11, 2008 at 05:52:21AM +, otto otto wrote: When I try to build Tor 0.2.1.5-alpha on Solaris10 I get the following warning and can't build the binaries.: geoip.c: In function `geoip_get_client_history': geoip.c:446: warning: comparison between signed and unsigned gmake[3]:

Re: Google's Chrome Web Browser and Tor

2008-09-05 Thread Nick Mathewson
On Thu, Sep 04, 2008 at 03:20:34PM -0700, Kyle Williams wrote: Hi all, I've been playing around with Google's new web browser and Tor. I thought it might be good to share my findings with everyone. After reading Google's privacy policy[1], I for one would not want to use this on a regular

Re: DNS lookup types

2008-08-20 Thread Nick Mathewson
On Wed, Aug 20, 2008 at 05:16:39PM -0400, Erilenz wrote: Hi, When using DNSPort or tor-resolve, you can look up A records and PTR records, but not NS or MX records. Can this functionality be added? It can be. Somebody would need to write a proposal (see the process in

Re: MaxOnionsPending questions

2008-08-16 Thread Nick Mathewson
On Fri, Aug 15, 2008 at 04:58:48AM -0500, Scott Bennett wrote: The tor man page says, MaxOnionsPending NUM If you have more than this number of onionskins queued for decrypt, reject new ones. (Default: 100) Does onionskins in this context mean

Re: exit node tortila adds material to www.barnesandnoble.com home page

2008-08-07 Thread Nick Mathewson
On Thu, Aug 07, 2008 at 03:26:37PM +0200, Steffen Schoenwiese wrote: On Thursday 07 August 2008 12:19:22 Scott Bennett wrote: [...] The point is, this is written in way that hardly anyone, even native germans, would bother to read it, so I'm not 100% convinced someone would deliberately

Re: Tor 0.2.0.30 does not bootstrap when FastFirstHopPK 0 in torrc file

2008-08-07 Thread Nick Mathewson
On Sun, Aug 03, 2008 at 09:30:56PM +0200, Erwin Lam wrote: Hello, Today, I upgraded my Tor client to version 0.2.0.30 (an RPM for SUSE 10.3 obtained from the Packman repository). Because I know something changed with respect to the format of the information supplied by the directory

Re: Mixed pages - serious bug of tor

2008-07-19 Thread Nick Mathewson
On Thu, Jul 17, 2008 at 02:30:25AM +0200, slush wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 More information: I tried to repeat this bug (really sorry for all relays operators). I found that this part of python code breaks connection of standalone browser. Since this is getting

Re: question about cached-status

2008-07-11 Thread Nick Mathewson
On Thu, Jul 10, 2008 at 02:59:57PM -0700, Steve Southam wrote: Hi Hi! Since you replied to Roger's 0.2.0.29-rc email, I initially assumed that you were referring to the directory protocol as used in 0.2.0.x. For 0.1.2.x and earlier, the answers are different. But since your subject line says

Re: Circuit question

2008-07-11 Thread Nick Mathewson
On Sat, Jul 05, 2008 at 12:23:18PM +0300, Evgeniy Minakov wrote: Hello, I have a question about the circuit construction. The getinfo circuit-status sometime returns response without any exit nodes. Which node used as exit node in this case? First, you might be wrong about what nodes are

Re: Circuit question

2008-07-11 Thread Nick Mathewson
On Fri, Jul 11, 2008 at 11:37:04AM -0400, Nick Mathewson wrote: [oops. Didn't end the paragraph.] First, you might be wrong about what nodes are exits. The Exit flag in the networkstatus document is not a perfect view of whether a node can be used as an exit: to actually see whether a node

Re: Tor 0.2.1.1-alpha is out

2008-06-17 Thread Nick Mathewson
On Wed, Jun 18, 2008 at 01:12:45AM -0400, Roger Dingledine wrote: [...] - Never use OpenSSL compression: it wastes RAM and CPU trying to compress cells, which are basically all encrypted, compressed, or both. Is compression negotiation (or lack thereof) visible to

Re: controller GETINFO ns/id/fingerprint s record

2008-06-01 Thread Nick Mathewson
On Thu, May 29, 2008 at 12:03:48PM -0700, Wesley Kenzie wrote: On Tue, May 27, 2008 at 02:19:22PM -0700, Wesley Kenzie wrote: where does the data originate from when the controller GETINFO command is used? Does it just grab data out of the cached* files on disk? Or poll one of

Re: Fwd: Logistics of International Policy Restrictions (project liberation)

2008-05-27 Thread Nick Mathewson
On Tue, May 27, 2008 at 03:00:12PM -0400, [EMAIL PROTECTED] wrote: [...] It's also news to me that the US State Dept. funded Tor. Perhaps we should update the sponsors page, https://www.torproject.org/sponsors.html.en. Wilfred might have erroneously thought that IBB is part of the state

Re: Router Flags

2008-05-23 Thread Nick Mathewson
On Fri, May 23, 2008 at 12:47:54AM -0500, Scott Bennett wrote: On Fri, 23 May 2008 00:05:37 -0500 Nathaniel Dube [EMAIL PROTECTED] wrote: Can someone explain what these router flags mean? Some of them I have a good [...] These have been explained in the documentation available

Re: controller GETINFO ns/id/fingerprint s record

2008-05-22 Thread Nick Mathewson
On Wed, May 21, 2008 at 09:21:20PM -0400, BarkerJr wrote: What is the criteria for getting listed as an Exit node in the s record for the controller interface's GETINFO /ns/id/fingerprint? You need to have two of these three ports wide open: 80, 443, 6667. No, I don't think it's fair that

Re: a serious TOR adversary?

2008-05-22 Thread Nick Mathewson
On Wed, May 21, 2008 at 05:47:41PM -0500, Eugene Y. Vasserman wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Thus spake Bernardo Bacic, on 5/21/08 6:45 AM: | This link http://web.crypto.cs.sunysb.edu/spday/ contains a summary | description of a possible TOR threat. | | Does anyone

Re: ContactInfo?

2008-05-19 Thread Nick Mathewson
.) yrs, -- Nick Mathewson

Re: Tor server for port 443

2008-05-19 Thread Nick Mathewson
On Mon, May 19, 2008 at 04:31:42AM -0400, Grant Heller wrote: Can I get some feedback regarding the deployment of an exit node restricted to port 443? A port-443-only exit would definitely be useful. The usefulness of an exit is IMO basically what you allow, not what you restrict. -- Nick

Re: unnamed exit nodes

2008-05-14 Thread Nick Mathewson
On Wed, May 14, 2008 at 06:15:18AM -0400, [EMAIL PROTECTED] wrote: Hi, Using tor/vidalia, how can I know the ID number of a tor node? I want to put some unnamed in my black list, but as a few nodes have the same name, it looks hard. What happens if I put just unnamed in the blacklist?

Re: Question

2008-05-14 Thread Nick Mathewson
On Wed, May 14, 2008 at 01:26:02PM +0200, Ivan ??ipka wrote: Hello everyone :) I'm a computer science student studying Tor (if necessary I can send the same mail from my official college mail). I have questions about Tor and the types of services that use it (in the aspect of the reputation

Re: Exit node's IP

2008-05-14 Thread Nick Mathewson
On Thu, May 15, 2008 at 08:09:49AM +0300, Evgeniy Minakov wrote: Hello all, Is it possible for controller to get current circuit nodes IPs through GETINFO command? You can get current circuits by watching circuit events, or by looking at the results of GETINFO circuit-status. From there,

Re: About the MapAddress option

2008-03-22 Thread Nick Mathewson
On Thu, Mar 20, 2008 at 05:17:18PM -0400, [EMAIL PROTECTED] wrote: Hi, I connect to servers through SSH on port 22 with Tor: The SSH client connects to localhost:9050 and privoxy does the job with Tor. I connect to the server IP, like 1.2.3.4 Is there a way to select an exit node so that

Re: Proposal: Incorporate Unreachable ORs into the Tor Network

2008-03-22 Thread Nick Mathewson
On Sat, Mar 22, 2008 at 11:11:12AM +, Robert Hogan wrote: I'm not sure how much merit this proposal has, or how serious it's problems are. Does anyone have any thoughts on it? Are the problems I've outlined fatal, or is there a problem with it I've missed? I suspect one or the other.

Re: max number of file descriptors hard coded

2008-02-18 Thread Nick Mathewson
On Sun, Feb 17, 2008 at 06:36:13PM +0100, Olaf Selke wrote: Narf! debugging the [warn] Error creating network socket: Too many open files messages I just found the max number of file descriptors apparently being hard coded in or.h to a value of 15.000. Raising the number using ulimit -n

Tor meetup in San Francisco this Thursday, 7pm, Sugarlump Coffee Lounge

2008-01-23 Thread Nick Mathewson
On Tue, Jan 22, 2008 at 01:13:24AM -0500, Nick Mathewson wrote: Hi, all! I'll be in San Francisco for most of this week, and I thought it would be neat to have a Tor Folks meetup on Thursday, probably in the late afternoon or early evening. Let me know (off-list) if there's any interest

Tor meetup in San Francisco this Thursday

2008-01-21 Thread Nick Mathewson
, -- Nick Mathewson pgpIRukqHlGhT.pgp Description: PGP signature

Re: SORBS vs Tor and the world

2008-01-07 Thread Nick Mathewson
On Mon, Jan 07, 2008 at 09:33:50AM -0500, Michael Holstein wrote: and no involvement with SORBS idiots is required. If you don't like SORBS, don't use them. TOR doesn't try to be invisible .. if a site admin wants to block anonymous ($whatever) .. they're free to do so, and SORBS just

Re: tor26 missing certificate messages today

2008-01-02 Thread Nick Mathewson
On Sun, Dec 09, 2007 at 11:42:22PM -0600, Scott Bennett wrote: This afternoon my tor server began logging the following messages: Dec 09 15:10:18.474 [notice] We're missing a certificate from authority tor26 with signing key : launching request.

Re: [OT] more from Cryptome on NSA, Windows firewals, mail services

2008-01-02 Thread Nick Mathewson
On Wed, Jan 02, 2008 at 02:47:11PM -0600, Eugene Y. Vasserman wrote: Thus spake Ringo Kamens on Sun, 23 Dec 2007: (snip) Also, we know the NSA and DoJ have engaged in this type of activity in the past such as working with Microsoft to secure vista and having their private key

Re: Tsocks and DNS

2008-01-02 Thread Nick Mathewson
On Sat, Dec 29, 2007 at 07:54:28PM -0500, Ringo Kamens wrote: I have a question regarding tsocks. According to http://wiki.noreply.org/noreply/TheOnionRouter/TorifyHOWTO#DNSNote, tsocks leaks DNS requests and it suggests I either use tor-resolve or apply the patch at

Re: Tsocks and DNS

2008-01-02 Thread Nick Mathewson
On Wed, Jan 02, 2008 at 04:41:32PM -0500, Nick Mathewson wrote: [...] They don't say what license their code is distributed under. I spoke too soon. tsocks is under GPLv2, and they distribute a patched tsocks with the license in place. Honestly, I don't want to make it sound like there's

Re: Your computer is too slow to handle this many creation requests!

2008-01-02 Thread Nick Mathewson
On Wed, Dec 26, 2007 at 10:43:32PM +0100, Olaf Selke wrote: morphium wrote: Tor is only using about 80 MBits, so that aren't even 10% of the Bandwith I want to give for tor. eeh? Wanna give Tor 800 MBits/s? Tor is a cpu hog efficiently using one core only. On my Debian box the other

Re: Build Problems on Solaris

2007-12-08 Thread Nick Mathewson
On Wed, Dec 05, 2007 at 08:27:39PM +, Steve Murphy wrote: Hi Nick. Got a bit further building from svn-12686. Throws up a warning about tor_threads_init Also tried --disable-threads did the same. Ah, I think I see what this is. In 0.2.0.x, threads are now mandatory. But threads

Re: suspicious log warning messages

2007-11-08 Thread Nick Mathewson
above. There's a new v3 directory authority, ides, run by Mike Perry. Apparently, adding it caused some weird bug to show up in the new certificate download code. See Flyspray bug 546. yrs, -- Nick Mathewson pgpjWKaK2FnEe.pgp Description: PGP signature

Re: peculiar 0.2.0.9-alpha behavior this a.m.

2007-10-31 Thread Nick Mathewson
) If possible, log at info for a while: it says a lot more about what's happening with downloads. I'm going to try to make those Not enough info messages more useful in the next alpha; sorry I can't figure this out just now. yrs, -- Nick Mathewson pgpbodUz50Poz.pgp Description: PGP

  1   2   >