Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-07-27 Thread Jacob Appelbaum
On 7/27/14, intrigeri wrote: > Hi, > > I was a bit sad that the TCP timestamps thing went nowhere, after the > energy we've put into discussing it, so I've built an ISO with the > corresponding branch merged in, and successfully run the automated > test suite on it. So, at least we now know it doe

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-07-27 Thread intrigeri
Hi, I was a bit sad that the TCP timestamps thing went nowhere, after the energy we've put into discussing it, so I've built an ISO with the corresponding branch merged in, and successfully run the automated test suite on it. So, at least we now know it doesn't break too much stuff in obvious ways

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-06-21 Thread jvoisin
On 06/21/2014 04:00 PM, intrigeri wrote: > Hi, > >>> jvoisin started doing it --> now known as #6580. > >> Julien made it clear on IRC that he won't be able to take care of this >> in time for 0.23. Any taker? > > Julien, do you think you can handle that in time for 1.2 (likely > freezing in Sep

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-06-21 Thread intrigeri
Hi, >> jvoisin started doing it --> now known as #6580. > Julien made it clear on IRC that he won't be able to take care of this > in time for 0.23. Any taker? Julien, do you think you can handle that in time for 1.2 (likely freezing in September or October), e.g. during the HackFest? Cheers, -

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-02-19 Thread intrigeri
Patrick Schleizer wrote (16 Feb 2014 18:44:07 GMT) : > TCP timestamps are created using the systems clock, is that correct? That's also my understanding. > Would it make sense to, > - when Tails starts: save system clock > - before Tor starts: randomize system clock (+/- a random amount of > mill

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-02-16 Thread Patrick Schleizer
Hi, TCP timestamps are created using the systems clock, is that correct? Would it make sense to, - when Tails starts: save system clock - before Tor starts: randomize system clock (+/- a random amount of milliseconds [and seconds?]) - when Tails is shut down: undo system clock randomization ? Th

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-02-15 Thread intrigeri
Hi, intrigeri wrote (07 Jan 2014 23:12:31 GMT) : > intrigeri wrote (05 Jan 2014 12:09:06 GMT) : >> intrigeri wrote (23 Dec 2013 09:15:53 GMT) : >>> Care to file a ticket, drop a tcp_timestamps.conf into >>> config/chroot_local-includes/etc/sysctl.d/, and test the >>> resulting ISO? >> Anyone? >

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-01-07 Thread intrigeri
intrigeri wrote (05 Jan 2014 12:09:06 GMT) : > intrigeri wrote (23 Dec 2013 09:15:53 GMT) : >> Care to file a ticket, drop a tcp_timestamps.conf into >> config/chroot_local-includes/etc/sysctl.d/, and test the >> resulting ISO? > Anyone? jvoisin started doing it --> now known as #6580. >> I'll c

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2014-01-05 Thread intrigeri
intrigeri wrote (23 Dec 2013 09:15:53 GMT) : > Care to file a ticket, drop a tcp_timestamps.conf into > config/chroot_local-includes/etc/sysctl.d/, and test the > resulting ISO? Anyone? > I'll come back to you and Jacob for the design doc phrasing, as I'm > still not convinced we can put statemen

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2013-12-23 Thread intrigeri
jvoisin wrote (22 Dec 2013 19:46:18 GMT) : > I agree with Jacob: I don't think Tails needs this features. > TCP timestamps are defined in [RFC > 1323](http://www.ietf.org/rfc/rfc1323.txt), entitled "TCP Extensions for > High Performance". > Timestamps are used for: > - "Protection Against Wrapped

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2013-12-22 Thread jvoisin
On 12/19/2013 10:56 PM, Jacob Appelbaum wrote: > intrigeri: >> Hi, >> >> it was brought to our attention (thanks Jacob!) that TCP timestamps >> (net.ipv4.tcp_timestamps) are enabled in Tails, and this might be >> a problem. >> > > No problem. Glad to help, if it is actually helpful! > >> In a n

Re: [Tails-dev] Risks of enabled/disabled TCP timestamps?

2013-12-19 Thread Jacob Appelbaum
intrigeri: > Hi, > > it was brought to our attention (thanks Jacob!) that TCP timestamps > (net.ipv4.tcp_timestamps) are enabled in Tails, and this might be > a problem. > No problem. Glad to help, if it is actually helpful! > In a nutshell, we're said that the risks that go with the current >

[Tails-dev] Risks of enabled/disabled TCP timestamps?

2013-12-19 Thread intrigeri
Hi, it was brought to our attention (thanks Jacob!) that TCP timestamps (net.ipv4.tcp_timestamps) are enabled in Tails, and this might be a problem. In a nutshell, we're said that the risks that go with the current setting are: 1. The system uptime can be inferred from this information. 2.