Re: [Tails-dev] Tails cert warning

2013-11-12 Thread Maxim Kammerer
returning the right certificate. It might be because the office building I'm in is using OpenDNS, since the bad cert CN=*.opendns.com. Here's the bad cert that was returned: http://pastebin.com/y02MsmNm -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] Removing the clock applet from the desktop

2013-10-06 Thread Maxim Kammerer
the system files that are used to construct the menus. https://github.com/mkdesu/liberte/blob/master/src/root/helpers/gen-locale-menu https://github.com/mkdesu/liberte/blob/master/src/usr/local/bin/customize-locale -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] Tails Feature Highly requested - Very Important

2013-10-03 Thread Maxim Kammerer
. See my replies at https://forum.dee.su/topic/how-to-install-bitcoin. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Removing the clock applet from the desktop

2013-09-20 Thread Maxim Kammerer
/liberte/blob/master/src/home/anon/bin/wrappers/epiphany Hopefully, I saved you guys some time in navigating through the complex and not too newbie-friendly world of Linux. Good luck! :) -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev

Re: [Tails-dev] [tor-talk] secure and simple network time (hack)

2013-04-18 Thread Maxim Kammerer
the server *or* the client, since both IP addresses are signed. I guess the reason is that NTP has no clear distinction between client and server. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https

Re: [Tails-dev] [tor-talk] secure and simple network time (hack)

2013-04-12 Thread Maxim Kammerer
that tlsdated in tlsdate-0.0.6 is dying with a segmentation fault after a while. Not surprised after seeing the code — my experimentation with this gimmick is finally over. Turns out that “throw something together and wait for patches” is not a sound development approach. -- Maxim Kammerer Liberté Linux

Re: [Tails-dev] Please review merge bugfix/less-aggressive-hard-disk-APM-on-AC

2013-03-13 Thread Maxim Kammerer
does. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Please review merge bugfix/less-aggressive-hard-disk-APM-on-AC

2013-03-02 Thread Maxim Kammerer
On Fri, Mar 1, 2013 at 7:34 PM, intrigeri intrig...@boum.org wrote: commit 65c78a5594ba7fff98683959d46bf431a065b77d Author: Tails developers amne...@boum.org Date: Fri Mar 1 13:17:54 2013 +0100 Enable laptop-mode-tools hard drive power management settings. Set APM level to 127 on

Re: [Tails-dev] Please review merge bugfix/less-aggressive-hard-disk-APM-on-AC

2013-03-02 Thread Maxim Kammerer
On Sat, Mar 2, 2013 at 6:45 PM, Maxim Kammerer m...@dee.su wrote: Note that NOLM_AC_HD_POWERMGMT=254 is there since the beginning — as usual, bottom-up approach produces better results. Although LM_AC_HD_POWERMGMT=128 — oh well, I guess users who experience issues can stop laptop_mode service

Re: [Tails-dev] Tails Mac support

2013-02-25 Thread Maxim Kammerer
] https://lists.torproject.org/pipermail/tor-talk/2012-July/024964.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Tails Mac support [Was: Training Journalists in Istanbul]

2013-02-22 Thread Maxim Kammerer
to be exciting, not this… bureaucracy. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Let's share username, /etc/hostname and /etc/host among all anonymity distributions

2013-01-23 Thread Maxim Kammerer
On Tue, Jan 22, 2013 at 8:00 PM, Maxim Kammerer m...@dee.su wrote: (/etc/conf.d/hostname in Liberté) can be potentially disclosed via DHCP requests, but dhcpcd has been configured to avoid that Just recalled another place while updating configuration: default Bluetooth adapter name (/etc

Re: [Tails-dev] Let's share username, /etc/hostname and /etc/host among all anonymity distributions

2013-01-22 Thread Maxim Kammerer
if there is actual possibility of leaks. Otherwise, it hurts usability. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

[Tails-dev] Attribution mistake in The Metadata Anonymization Toolkit paper (arXiv:1212.3648v1)

2013-01-17 Thread Maxim Kammerer
in final paper version! [1] http://arxiv.org/abs/1212.3648 [v1] [2] https://forum.dee.su/topic/liberté-linux-maxim-kammerer-is-this-fact-or-fiction Thanks, Maxim -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails

Re: [Tails-dev] Support EntropyKey?

2012-11-26 Thread Maxim Kammerer
/projects/hipsor/publi.php -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Tails: pcmcia / firewire / etc.

2012-10-14 Thread Maxim Kammerer
On Sat, Oct 13, 2012 at 5:18 AM, Maxim Kammerer m...@dee.su wrote: On Sat, Oct 13, 2012 at 5:04 AM, Steve Weis stevew...@gmail.com wrote: I think the kernel is working as expected. Debian and Ubuntu are both also vulnerable by default, since FireWire modules are loaded automatically. From

Re: [Tails-dev] Tails: pcmcia / firewire / etc.

2012-10-14 Thread Maxim Kammerer
, there is also asynchronous DMA, but its accessible memory regions are kernel's responsibility. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] Tails: pcmcia / firewire / etc.

2012-10-14 Thread Maxim Kammerer
On Sun, Oct 14, 2012 at 11:38 PM, Maxim Kammerer m...@dee.su wrote: there is currently no other way to enable physical DMA in Firewire than via firewire_sbp2 or via unfiltered physical DMA (enabled by CONFIG_FIREWIRE_OHCI_REMOTE_DMA). Ah, there is also CONFIG_PROVIDE_OHCI1394_DMA_INIT

Re: [Tails-dev] Tails: pcmcia / firewire / etc.

2012-10-12 Thread Maxim Kammerer
on the relevant Tails TODO page. So why disable the interfaces? Looks like an overkill to me. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] from sdmem to memtest, and testing procedures

2012-10-12 Thread Maxim Kammerer
On Thu, Dec 29, 2011 at 12:53 AM, intrigeri intrig...@boum.org wrote: Maxim Kammerer wrote (26 Dec 2011 17:59:44 GMT) : But best option, of course, is if kernel developers fix the kernel Sure. Ah, by the way, they won't fix memtest. Nobody cares [1]. [1] https://bugzilla.kernel.org

Re: [Tails-dev] Tails: pcmcia / firewire / etc.

2012-10-12 Thread Maxim Kammerer
driver in drivers/firewire uses filtered physical DMA by default, which is more secure but not suitable for remote debugging.” Isn't this supposed to limit DMA? I can send some fix suggestions if you like. Not being a kernel developer, I am not sure I will be able to act on them. -- Maxim

Re: [Tails-dev] Block/unblock wireless devices?

2012-09-25 Thread Maxim Kammerer
during boot is that some systems turn wireless radio off on boot: https://forum.dee.su/topic/wireless-problem. I also think that having Bluetooth off by default is the optimal choice, but there are still problems with it, as you noted. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] PGP Smart Cards

2012-08-27 Thread Maxim Kammerer
process has only gained the minimum rights needed to do its job (instead of gaining root access).” -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo/tails-dev

Re: [Tails-dev] PGP Smart Cards

2012-08-25 Thread Maxim Kammerer
that at one point I considered asking some guy who would send evaluation USB tokens for a free one, but it turned out as too much trouble). [1] https://forum.dee.su/topic/a-new-snapshot-has-been-released-20120825 -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] [tor-talk] secure and simple network time (hack)

2012-07-18 Thread Maxim Kammerer
whether Chrome OS's usage of tlsdate is confirmed by Google, or this information comes from a single pull request on GitHub. In any case, I suspect that Chrome OS developers did not properly explore the available time setting options. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] Why doesn't Tails use tlsdate? (htp replacement)

2012-06-05 Thread Maxim Kammerer
current tlsdate. With all that said, I actually intend to fork tlsdate at some point and implement the required features, but it's quite low priority. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ tails-dev mailing list tails-dev@boum.org https

[Tails-dev] Has Tails joined Open Invention Network?

2012-05-31 Thread Maxim Kammerer
surrendering part of project's independence for some vague American thing in return. Maybe I'm wrong, though. Debian is not on the list, by the way (although Gentoo is). [1] http://www.openinventionnetwork.com/licensees.php -- Maxim Kammerer Liberté Linux: http://dee.su/liberte

Re: [Tails-dev] Building without a proxy?

2012-05-09 Thread Maxim Kammerer
no_proxy and copies host's /etc/resolv.conf over (which is later excluded from the build). -- Maxim Kammerer Liberté Linux (discussion / support: http://dee.su/liberte-contribute) ___ tails-dev mailing list tails-dev@boum.org https://mailman.boum.org/listinfo

Re: [Tails-dev] Building without a proxy?

2012-05-09 Thread Maxim Kammerer
without *_proxy variables had builds failing due to non-working DNS. It could be the reason for failing builds in your case. -- Maxim Kammerer Liberté Linux (discussion / support: http://dee.su/liberte-contribute) ___ tails-dev mailing list tails-dev

Re: [Tails-dev] Switch to Privoxy?

2012-03-25 Thread Maxim Kammerer
in Liberté's git, which includes Referer/Host header rewriting for .exit notation support, for instance. -- Maxim Kammerer Liberté Linux (discussion / support: http://dee.su/liberte-contribute) ___ tails-dev mailing list tails-dev@boum.org https

Re: [Tails-dev] Please review and test feature/tordate

2012-01-28 Thread Maxim Kammerer
be well from here on. It will download a new consensus after an hour. If htpdate fails, that's where Tor stops working. Also, won't other nodes treat another Tor node with clock time before their consensus differently? -- Maxim Kammerer Liberté Linux (discussion / support: http://dee.su/liberte

Re: [Tails-dev] Please review and test feature/tordate

2012-01-27 Thread Maxim Kammerer
On Fri, Jan 27, 2012 at 17:39, Maxim Kammerer m...@dee.su wrote: When writing and testing that script, I noticed that the incoming valid-after is never more than an hour earlier from the current (correct) time, but at that point it was all kind of black magic, and I didn't know that (as you

Re: [Tails-dev] tordate: why is it safe to set time from unverified-consensus?

2012-01-20 Thread Maxim Kammerer
/pipermail/tails-dev/2011-October/000571.html [2] https://trac.torproject.org/projects/tor/ticket/4187 [3] https://gitweb.torproject.org/tor.git/blob/HEAD:/src/or/networkstatus.c -- Maxim Kammerer Liberté Linux (discussion / support: http://dee.su/liberte-contribute

Re: [Tails-dev] PROBLEM: memtest tests only LOWMEM

2012-01-20 Thread Maxim Kammerer
the difficulties of adapting it for the task. Best regards, Maxim On Mon, Dec 26, 2011 at 04:18, Maxim Kammerer m...@dee.su wrote: 1. On 32-bit x86, memtest=n tests only LOWMEM memory (~ 895 MiB), HIGHMEM is ignored 2. On 3.0.4-hardened-r5, HIGHMEM memory (HIGHMEM64G in my tests) is apparently ignored