Re: [tor-relays] public relay stats

2018-08-10 Thread Nathaniel Suchy
A link to the DMCA Archive for those who want to see them: https://github.com/GreyPony/dmca On Fri, Aug 10, 2018 at 4:38 PM wrote: > I'm gathering them for all of the Greypony relays...if you're interested > in that information, I can give you some charts if you want. I plan to > start

Re: [tor-relays] Dropping packets with TCP MSS=1400 to foil GFW active probing

2018-08-20 Thread Nathaniel Suchy
Interesting. Is there any reason to not use an obfuscated bridge? On Mon, Aug 20, 2018 at 2:16 PM David Fifield wrote: > On Sun, Aug 19, 2018 at 07:41:26PM -0400, Nathaniel Suchy wrote: > > Is China successfully probing OBFS4 bridges? Or does this apply more to > non > > obfs

Re: [tor-relays] Cloudflare Onions Beta and Network Stability

2018-08-20 Thread Nathaniel Suchy
Except perhaps the directory authorities? On Mon, Aug 20, 2018 at 7:19 PM, Alec Muffett wrote: > One point that's been completely missed in the hyperbolic fear-mongering > so far: > > Even if Cloudflare onionified a bazillion domain names, there are still > only a few million people who use Tor

Re: [tor-relays] Cloudflare Onions Beta and Network Stability

2018-08-20 Thread Nathaniel Suchy
dth / > connections they are expecting to route? > > Having a sense of scale in a ratio of current numbers I think would let > everyone plan for what they're currently seeing multiply by X as a > baseline. > > > On 2018-08-20 11:23 AM, Nathaniel Suchy wrote: > > As some of you m

[tor-relays] Snowflake PT

2018-08-21 Thread Nathaniel Suchy
, Nathaniel Suchy ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Cloudflare Onions Beta and Network Stability

2018-08-21 Thread Nathaniel Suchy
Imagine if Cloudflare adds CAPTCHAs to Onion services. Now that’d be something  On Tue, Aug 21, 2018 at 1:18 PM grarpamp wrote: > On Mon, Aug 20, 2018 at 7:19 PM, Alec Muffett > wrote: > > Even if Cloudflare onionified a bazillion domain names, there are still > only > > a few million people

Re: [tor-relays] Should a hoster be considered a relay operator because he hosts relays? I don't think so.

2018-08-28 Thread Nathaniel Suchy
Is there a way to switch my current relays to use offline keys and invalidate the old keys without losing current stats? On Tue, Aug 28, 2018 at 7:28 AM nusenu wrote: > Jordan: > > I'd be much more supportive of the typical "donate x to have a relay > > hosted for you" [1][2] rather than "host

Re: [tor-relays] switching to OfflineMasterKey mode

2018-08-28 Thread Nathaniel Suchy
Thanks for the heads up. On Tue, Aug 28, 2018 at 8:42 PM teor wrote: > > > On 29 Aug 2018, at 05:38, nusenu wrote: > > > > Signed PGP part > > > > > > Nathaniel Suchy: > >> Is there a way to switch my current relays to use offline keys and >

Re: [tor-relays] 4 of Conrad Rockenhaus trial servers are in the top ten exit relays for Canada

2018-08-27 Thread Nathaniel Suchy
Hi Ralph, Writing to you off-list. I'm sorry to hear you had a bad experience with GreyPony IT Services. Cordially, Nathaniel On Mon, Aug 27, 2018 at 1:59 PM Ralph Seichter wrote: > On 27.08.18 19:11, zimmer linux wrote: > > > Well done to Conrad - I say. The more, the merrier. > > I

Re: [tor-relays] 4 of Conrad Rockenhaus trial servers are in the top ten exit relays for Canada

2018-08-27 Thread Nathaniel Suchy
ust. Although, better path selection could play in here :) Cordially, Nathaniel Suchy On Mon, Aug 27, 2018 at 8:37 PM Jordan wrote: > >> No, because Digital Ocean doesn't market itself as a relay hoster-- the > >> percentage of relay-hosting clients wouldn't even near 0.1%. > &g

[tor-relays] Protecting Tor Circuit path selection from correlation attacks by an autonomous system

2018-08-27 Thread Nathaniel Suchy
everything about the circuit most of the time. Everyone on the list has a had very insightful and helpful thoughts on this discussion so far and I'm looking forward to getting more discussion of the broader issue. Cordially, Nathaniel Suchy ___ tor-relays

Re: [tor-relays] 4 of Conrad Rockenhaus trial servers are in the top ten exit relays for Canada

2018-08-27 Thread Nathaniel Suchy
read regarding Conrad and I's services as that's been discussed enough. Let's discuss path selection among the same hosting provider in general. On Mon, Aug 27, 2018 at 10:09 PM teor wrote: > > On 28 Aug 2018, at 10:47, Nathaniel Suchy wrote: > > > > Tor will already avoid

Re: [tor-relays] Dropping packets with TCP MSS=1400 to foil GFW active probing

2018-08-21 Thread Nathaniel Suchy
Hi David, Couldn't I firewall the non-obfs port so only looback addresses may access it? Cordially, Nathaniel Suchy On Tue, Aug 21, 2018 at 11:37 AM David Fifield wrote: > On Mon, Aug 20, 2018 at 02:25:40PM -0400, Nathaniel Suchy wrote: > > Interesting. Is there any reason t

Re: [tor-relays] Abuse Complaints

2018-08-29 Thread Nathaniel Suchy
as possible until they get too many to ever hope to respond to and then try to get them to terminate your account. Depending on the ISP it'll work. Cordially, Nathaniel Suchy On Wed, Aug 29, 2018 at 8:49 AM Ralph Seichter wrote: > On 29.08.2018 12:48, John Ricketts wrote: > > > For the n

Re: [tor-relays] FYI: Subpoena Received

2018-07-23 Thread Nathaniel Suchy
If you were required to hand over your relay keys be sure to switch over to new ones to avoid future traffic from being affected by MITMs. On Mon, Jul 23, 2018 at 12:26 PM IPfail (Tor Admin) wrote: > Vasilis, > > It turned out to be a pretty "non-event". The jurisdiction was a > relatively

Re: [tor-relays] Exit in Turkey blocking torproject (komm EA93C), BadExit, Node Subscription Services, Censorship

2018-08-30 Thread Nathaniel Suchy
) situation A could happen. The odds might not be in your favor. Don't risk that! Cordially, Nathaniel Suchy On Thu, Aug 30, 2018 at 3:25 PM grarpamp wrote: > This particular case receiving mentions for at least a few months... > D1E99DE1E29E05D79F0EF9E083D18229867EA93C kommissarov 185.125.

Re: [tor-relays] Exit in Turkey blocking torproject (komm EA93C), BadExit, Node Subscription Services, Censorship

2018-08-30 Thread Nathaniel Suchy
8229867EA93C kommissarov 185.125.33.114 > > > On Thu, 30 Aug 2018 at 22:11, Nathaniel Suchy wrote: > >> So this exit node is censored by Turkey. That means any site blocked in >> Turkey is blocked on the exit. What about an exit node in China or Syria or >> Iraq? The

Re: [tor-relays] Announcement: Relay operator meetings on IRC

2018-09-01 Thread Nathaniel Suchy
Hi Livak, Yes OFTC Webchat works over Tor. Also you can run “torify irssi” in bash if you’re about the command line life. Sometimes OFTC blocks Tor briefly. Sometimes just webchat, sometimes IRSSI too. You might want to consider using a VPS as a bouncer so you aren’t locked out of the meetings :)

[tor-relays] Policy Question: Tor Exits at Universities, Corporate Networks, etc

2018-09-01 Thread Nathaniel Suchy
Recently we've been discussing a Tor Exit in Turkey censoring access to various websites. It's less to some err, disagreements on what should and should not be allowed. I've seen a few opinions: *) It grants an outside view at what Turkey censors *) It could push new tor users away This leads me

Re: [tor-relays] SSH login attempts

2018-09-04 Thread Nathaniel Suchy
> Using an obscure port only prevents attempts being logged, nothing else. And if you’re going to use an alternate port, pick one under 1024. Make it so an attacker needs to be root before they replace your sshd process. If you take that approach, make sure you are using a hardware firewall

Re: [tor-relays] Suspension of service (ISP Scaleway / tor exit)

2018-09-04 Thread Nathaniel Suchy
For DoS traffic, it'd be nice to have some agreed upon rate limit rules of obvious syn flood and similar traffic which both stop the attacks, or slow them down so they don't affect anything and cause complaints, while still allowing legitimate traffic to flow as normal. Scaleway knows about Tor,

Re: [tor-relays] Suspension of service (ISP Scaleway / tor exit)

2018-09-04 Thread Nathaniel Suchy
I run a "browser-only" exit relay at Scaleway, by "browser-only" I mean only ports 53 (DNS), 80 (HTTP), 443 (HTTPS) and so far it's gone well. Their support recommends if you run "an open proxy" to check your abuse inbox daily (See: https://cloud.scaleway.com/#/abuses) as they will suspend after

Re: [tor-relays] Suspension of service (ISP Scaleway / tor exit)

2018-09-08 Thread Nathaniel Suchy
If your service is automatically terminated, will they reinstate once you respond? On Sat, Sep 8, 2018 at 3:52 AM Anders Andersson wrote: > > On Tue, Sep 4, 2018 at 11:00 PM, Paul wrote: > > I made the same experience as you several times in the last few weeks with > > Scaleway. > > Usually you

Re: [tor-relays] Exit in Turkey blocking torproject (komm EA93C), BadExit, Node Subscription Services, Censorship

2018-08-30 Thread Nathaniel Suchy
ing it and > the result is the same than websites blocking the country, users of that > exit can't access the websites just because the exit is in that country but > doesn't do any filtering itself. > > On Thu, 30 Aug 2018, 16:14 Nathaniel Suchy, wrote: > >> That’s a website blockin

Re: [tor-relays] Exit in Turkey blocking torproject (komm EA93C), BadExit, Node Subscription Services, Censorship

2018-08-30 Thread Nathaniel Suchy
ted with a detection addon in Tor Browser? Detect that > the site may be blocked at the exit and offer to fetch a new circuit for > the site? > > > On Thu, Aug 30, 2018, 19:22 Nathaniel Suchy wrote: > >> The exit is behind a filtered ISP. Opposed to a website blocking exits. >&g

Re: [tor-relays] Exit in Turkey blocking torproject (komm EA93C), BadExit, Node Subscription Services, Censorship

2018-08-30 Thread Nathaniel Suchy
On 8/30/2018 2:11 PM, Nathaniel Suchy wrote: > > So this exit node is censored by Turkey. That means any site blocked in > Turkey is blocked on the exit. What about an exit node in China or Syria or > Iraq? They censor, should exits there be allowed? I don't think they > should.

Re: [tor-relays] The Assistance and Access Bill 2018

2018-09-04 Thread Nathaniel Suchy
I live in the United States so they’d need to pass an act here for it to be enforced, which would be constitutionally challenged with every last legal measure available. Have you seen the legal shitstorm with social networks censoring conservatives, can you imagine them hearing the government is

[tor-relays] Bridge bandwidth usage?

2018-07-11 Thread Nathaniel Suchy
Hi. I would like to run a public OBFS4 Tor Bridge. Digitalocean’s price changes made running an exit too expensive. In comparison how much bandwidth would a Tor bridge use per month? Cheers, Nathaniel ___ tor-relays mailing list

Re: [tor-relays] Turning down my relay from DigitalOcean

2018-07-03 Thread Nathaniel Suchy
Scaleway is an option that's worth considering. Hetzner Cloud is also good but I'd avoid running an exit there. If you try BuyVM make sure you have a dedicated CPU Core or you could have trouble with the fair share CPU policy with crypto using too much CPU time. On Tue, Jul 3, 2018 at 5:36 AM,

[tor-relays] Documentation on hardening Debian and Tor Bridge?

2018-10-12 Thread Nathaniel Suchy
make Tor use even stronger keys and such? I want things to be as hard to hack as possible. Cordially, Nathaniel Suchy ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Loss of Guard Flag

2018-10-22 Thread Nathaniel Suchy
If your relay restarts it’ll temporarily lose the guard flag or if it has slower than average bandwidth it won’t be granted the guard flag. On Mon, Oct 22, 2018 at 7:00 AM Harkirat Virk wrote: > > Hi, > > I am running an Tor Node nickname 3sKtjMnoiZAIGz07 from ip 59.179.28.221. > I was given

Re: [tor-relays] exit operators: overall DNS failure rate above 5% - please check your DNS

2018-10-19 Thread Nathaniel Suchy
The Tor relays guide in trac makes that recommendation. On Fri, Oct 19, 2018 at 11:07 PM Conrad Rockenhaus wrote: > Would you make a recommendation of running unbound on the local exit nodes > to resolve local DNS server congestion to get around this issue? > > Thanks, > > Conrad > > > On Oct

Re: [tor-relays] Running relay on vmware ? is it secure to use Tor on virtual systems ?

2018-11-02 Thread Nathaniel Suchy
, Nathaniel Suchy On Fri, Nov 2, 2018 at 3:38 PM wrote: > No, I`m not hosting any Tor exits in my apartment. Only Relay without > exit. > I have some pool of vmware systems with public ips, they are running doing > nothing... so I have decided to put some non exit tor traffic to them. >

Re: [tor-relays] Strength in numbers (of $$)

2018-10-23 Thread Nathaniel Suchy
That money pays for other costs including but not limited to: *) Hosting torproject.org and core infrastructure. *) Paying full time developers *) Marketing expenses *) Advocacy expenses *) Funding research projects *) Bug bounties? (Can a Tor Project staffer confirm if donation money is used for

Re: [tor-relays] Monitoring exit node traffic by port?

2018-10-29 Thread Nathaniel Suchy
Hi Isaac, The tool “ifconfig” shows the amount of traffic since last reboot. The tool vnstat is nice but you should check what data it stores. Any data collection however small is a fine line with US Federal Wiretapping laws. Be careful. Running a Tor Exit at your home is dangerous, it might be

Re: [tor-relays] Running relay on vmware ? is it secure to use Tor on virtual systems ?

2018-11-02 Thread Nathaniel Suchy
A bit confused. Are you running a Tor Exit or the Tor Browser Bundle? Cordially, Nathaniel Suchy On Fri, Nov 2, 2018 at 2:32 PM wrote: > Hi, > > is it secure to run Tor Relay / Tor browser on Vmware ? > On my Windows 10 desktop I have installed VMware Player where is running &

Re: [tor-relays] Running relay on vmware ? is it secure to use Tor on virtual systems ?

2018-11-02 Thread Nathaniel Suchy
be more specific. Are you hosting a Tor Exit in your home? Cordially, Nathaniel Suchy On Fri, Nov 2, 2018 at 2:52 PM wrote: > Sorry Nathaniel, my english is not so well. > > General I`m using Virtual operating system + Tor Web Browser to browse the > internet. > My question i

Re: [tor-relays] Continuing To Run A Relay On Mac OS High Sierra Via Homebrew After A New Mac OS Version Is Released

2018-10-04 Thread Nathaniel Suchy
At that point it might be worth installing Linux on the computer and running a relay that way :) On Thu, Oct 4, 2018 at 2:28 AM Keifer Bly wrote: > Hi all, > > > > So I am having a bit of a dilemma, the computer I am running my relay on > is running Mac OS High Sierra, and despite the fact that

Re: [tor-relays] Greypony / Conrad Rockenhaus offline?

2018-10-04 Thread Nathaniel Suchy
. Whatever we do it turns out negative for someone. Cordially, Nathaniel Suchy On Thu, Oct 4, 2018 at 3:50 PM s7r wrote: > George wrote: > > Roman Mamedov: > >> On Wed, 3 Oct 2018 03:52:24 +0200 > >> niftybunny wrote: > >> > >>> A Tor friendly ISP is

Re: [tor-relays] Greypony IT - Public Statement to the Tor Community

2018-10-04 Thread Nathaniel Suchy
Another update: Conrad hired a contractor to replace a broken switch and fix the cabling so the redundant switch would take over in the event of a failure again. An SLA credit will be issued to affected customers. Cordially, Nathaniel Suchy On Wed, Oct 3, 2018 at 7:08 PM Mirimir wrote: > On

Re: [tor-relays] Greypony / Conrad Rockenhaus offline?

2018-10-04 Thread Nathaniel Suchy
Hi Matt, That project is now in the works. Meanwhile will other community members continue creating threads about our organization? It has to stop on both ends otherwise we’re forced to respond when people create threads about us. Cordially, Nathaniel Suchy On Thu, Oct 4, 2018 at 6:24 PM Matt

Re: [tor-relays] Greypony / Conrad Rockenhaus offline?

2018-10-02 Thread Nathaniel Suchy
. Cordially, Nathaniel Suchy On Tue, Oct 2, 2018 at 4:41 PM Olaf Grimm wrote: > Yes, since some days. I cancel my accounts and looking forward to other > provider. greyponyit.com and XOA-Portal are offline. Two weeks ago my > server in the USA gone offline, two day ago my server in E

Re: [tor-relays] relay and bridge on the same IP

2018-10-01 Thread Nathaniel Suchy
, Nathaniel Suchy On Mon, Oct 1, 2018 at 4:59 PM wrote: > Hi, > > is it possible to build tor non-exit relay and bridge on the same IP, > the same tor instance ? > > I have running Freebsd non-exit relay instance and I can build more > instances in different countries, t

Re: [tor-relays] Multi node management programs/platforms?

2018-09-03 Thread Nathaniel Suchy
I use a platform called time and SSH :) On Mon, Sep 3, 2018 at 10:12 PM Isaac Grover, Aileron I.T. < igro...@aileronit.com> wrote: > Good evening, > > For those of you who manage multiple exits and/or relays, what > program/platform do you use to manage them? > > Make your day great, > Isaac

Re: [tor-relays] Possible problem with NYX

2018-09-03 Thread Nathaniel Suchy
You have to decide a balance of usefulness to a legitimate operator and privacy concerns. I could just as easily run Wireshark or TCPDump on my relays and get client IP Addresses that way. You are trusting most operators, like me, are the good guys. Of course a client IP isn’t very useful without

Re: [tor-relays] [SPAM] Re: Jerk spammers on tor-relays

2018-09-21 Thread Nathaniel Suchy
I use Google’s G Suite with my personal domain name for email. They let you drop emails or send them to spam if they contain certain words or phrases. Beyond that disable conversation view and press report spam on the individual emails and hope the spam filter improves to the point you no longer

Re: [tor-relays] having just 1 exit port - helpful?

2019-01-06 Thread Nathaniel Suchy
traffic, potentionally being a user's guard, among other things :) Cordially, Nathaniel Suchy Jan 6, 2019, 5:42 AM by toralf.foers...@gmx.de: > If just 1 port would be opened at an relay, eg. 6697, would this help the Tor > network or would only spammers and DDoS use tha

Re: [tor-relays] AS: "ColoCrossing" - 28 new relays

2018-12-12 Thread Nathaniel Suchy
It's scary to think there are bad people out there actively trying to harm our community :( Cordially, Nathaniel Suchy Dec 12, 2018, 10:46 AM by dgou...@torproject.org: > On 12 Dec (09:33:58), Toralf Förster wrote: > >> On 12/11/18 10:54 PM, nusenu wrote: >> > from thei

Re: [tor-relays] Advice for new exit relay

2018-12-20 Thread Nathaniel Suchy
I'll add most providers willing to do custom WHOIS records are generally much more expensive. Is custom WHOIS an absolute requirement? Many providers are willing to work with you. Cordially, Nathaniel Suchy Dec 20, 2018, 2:04 AM by dns1...@riseup.net: > Ook, thank you everyb

Re: [tor-relays] AS: "ColoCrossing" - 28 new relays

2018-12-11 Thread Nathaniel Suchy
It looks like they are all running an alpha release with various Gmail addresses. Maybe they're trying to correlate some traffic. What can be done in situations like this where the operator is (likely intentionally) being dishonest about their identity? Cordially, Nathaniel Suchy Dec 11

Re: [tor-relays] Who is permanently checking my bridge relay?

2018-12-04 Thread Nathaniel Suchy
traffic across all of your IP Ranges at random and they would have to comply. If this is your threat model a Private OBFS4Proxy Bridge (not published in BridgeDB and blocking the ORPort (only allow the OBFS4 Port) might be a better solution for you :) Cordially, Nathaniel Suchy Dec 4, 2018, 8:43

Re: [tor-relays] IP addresses on the list

2018-12-04 Thread Nathaniel Suchy
I disagree with scrambling the IP Addresses. What if you are posting the IP Address of a Tor Exit or Relay Server and trying to get help with an issue? Scrambling that would break some discussions. Cordially, Nathaniel Suchy Dec 4, 2018, 9:20 AM by charlyghisl...@gmail.com: > We have s

Re: [tor-relays] community team highlights: Relay Advocacy

2019-01-13 Thread Nathaniel Suchy
from OVH likely without their mercy. Cordially, Nathaniel Suchy Jan 13, 2019, 4:54 PM by grarp...@gmail.com: >>> communicating with OVH regarding relays without contactinfo >>> >> Is it *really* a good idea to poke OVH over this? >> in their ToS >> I

Re: [tor-relays] Advice for new exit relay

2018-12-19 Thread Nathaniel Suchy
experiences with them in the past :) Cordially, Nathaniel Suchy Dec 19, 2018, 2:40 AM by dns1...@riseup.net: > Hi, > > excuse my bad english. > > I would run an exit relay on a virtual server. For now i run just a non exit > relay on my own mini server. I don't like too much do not

Re: [tor-relays] Spamcop question

2019-04-02 Thread Nathaniel Suchy
Someone likely abused a webmail provider. Respond to them that SMTP isn’t available from your exit and they’ll have to contact the email service provider directly. Cordially, Nathaniel Suchy > On Apr 2, 2019, at 5:04 PM, ylms wrote: > > Hello fellow Tor-Exit operators, > &

Re: [tor-relays] Hello

2019-04-04 Thread Nathaniel Suchy
considered if the spam starts again. Likewise my clarifications are over and my request for not name-calling me has been made. Cordially, Nathaniel Suchy Old Man Tor: > Sorry to hear that, that's really unfortunate and I would never want to wish > that upon anyone. I wish you a speedy recover

[tor-relays] Should new exit relays be probed for public DNS resolvers

2020-03-04 Thread Nathaniel Suchy
There has been discussion over the past several years that the Tor network should not use public DNS resolver as it has security implications on the Tor network (https://medium.com/@nusenu/who-controls-tors-dns-traffic-a74a7632e8ca). Should new Tor Exit Relays be probed and not included in the

Re: [tor-relays] Should new exit relays be probed for public DNS resolvers

2020-03-05 Thread Nathaniel Suchy
It’s not a threat model issue. It’s more of a let’s make Tor less dependent on a few public resolvers. Running our own resolvers just makes more sense at such a scale. Cordially, Nathaniel Suchy (they/them) Sent from ProtonMail Mobile On Thu, Mar 5, 2020 at 1:59 AM, Alec Muffett wrote

[tor-relays] Request for removal of an exit from the consensus

2018-05-04 Thread Nathaniel Suchy (Lunorian)
This is more of a message to the directory authorities. After a discussion with Digitalocean - they will not relent on the bandwidth policy. The server tor-exit-us-1.lunorian.is (Tor Metrics link below) has been turned off for now - if the directory authorities would like further proof to confirm

[tor-relays] What's the timeline for a Tor relay to start routing a large amount of traffic?

2018-04-27 Thread Nathaniel Suchy (Lunorian)
I started to run a few Tor Exit Relays (My exit policy only allows ports 80 and 443 only to minimize the amount of abuse) a few days ago. Currently Tor Metrics shows the relays are only advertising 700Kb/s despite the fact the minimum port speed on the VPSes I host on is 100Mb/s. I've been told by

[tor-relays] What's the timeline for a Tor relay to start routing a large amount of traffic?

2018-04-27 Thread Nathaniel Suchy (Lunorian)
, Nathaniel Suchy > On Apr 27, 2018, at 3:00 PM, Matt Traudt <pas...@torproject.org> wrote: > >> On 4/27/18 14:34, Nathaniel Suchy (Lunorian) wrote: >> I started to run a few Tor Exit Relays (My exit policy only allows ports >> 80 and 443 only to minimize the a

Re: [tor-relays] Timeframe for a relay to be removed from the consensus and tor metrics

2018-04-28 Thread Nathaniel Suchy (Lunorian)
Thanks for the clarification. Once my last relay gets listed in the consensus I will update the family again :) Cheers, Nathaniel Suchy On 4/28/18 11:31 AM, nusenu wrote: > > > Nathaniel Suchy (Lunorian): >> While setting up my fleet of Tor Relays, one relay IP Address >>

Re: [tor-relays] lets stop using central big DNS resolvers (Google, Level3, OpenDNS, Quad9, Cloudflare)

2018-05-12 Thread Nathaniel Suchy (Lunorian)
I don't know how everyone else feels about this - rather than using a secondary resolver in the event Unbound fails - why not let the query fail and the user have to try again? Is there any reason to risk letting a third party resolver possibly log exit node DNS queries? nusenu: > > > Andrew

[tor-relays] PSA regarding Quad9 DNS Resolver

2018-05-11 Thread Nathaniel Suchy (Lunorian)
Like OpenDNS, Quad9 is a censoring DNS resolver and exits using it are / should be considered bad exits. I haven’t seen any exits using it yet however I thought I’d bring it up. Thoughts? Cheers, Nathaniel Sent from my iPhone ___ tor-relays mailing

Re: [tor-relays] lets stop using central big DNS resolvers (Google, Level3, OpenDNS, Quad9, Cloudflare)

2018-05-11 Thread Nathaniel Suchy (Lunorian)
I’m quite worried about the number of relays using Google DNS. With Google DNS, Google gets to know a Tor exit proxied X website at X time. I don’t think they can be trusted with this information. As for privacy concerns: Google claims these logs are only stored for up to 48 hours. It worries

Re: [tor-relays] lets stop using central big DNS resolvers (Google, Level3, OpenDNS, Quad9, Cloudflare)

2018-05-11 Thread Nathaniel Suchy (Lunorian)
You have a very good point - we could all run our own resolver(s) with a fallback. This idea sounds much better than just reassigning trust. On 5/11/18 8:52 AM, Ralph Seichter wrote: > On 11.05.18 13:55, Nathaniel Suchy (Lunorian) wrote: > >> My first thought is to use ISP DNS if it

Re: [tor-relays] lets stop using central big DNS resolvers (Google, Level3, OpenDNS, Quad9, Cloudflare)

2018-05-11 Thread Nathaniel Suchy (Lunorian)
I dislike OpenNIC as they are operating their own TLDs - this would end up being confusing as some Tor Exits would allow access to OpenNIC TLDs and others would not. On 5/11/18 8:18 AM, Famicoman wrote: > OpenNIC is always an option, https://www.opennic.org > > On Fri, May 11, 2018, 8:12 AM

Re: [tor-relays] PSA regarding Quad9 DNS Resolver

2018-05-11 Thread Nathaniel Suchy (Lunorian)
As long as their alternate resolvers do not censor any queries it's (probably) allowed and will (probably) not get you flagged as a bad exit for censoring traffic. On 5/11/18 12:24 PM, nusenu wrote: > > > Toralf Förster: >> On 05/11/2018 01:41 PM, Nathaniel Suchy (Lunorian)

Re: [tor-relays] Verizon AS701 blocking Tor consensus server tor26 (86.59.21.38)

2018-05-16 Thread Nathaniel Suchy (Lunorian)
If Verizon is suddenly worried about malware, why not block at the DNS level with something like Quad9 where it’s managed by more competent professionals? (Of course still allowing alternate DNS Servers) Does Tor bootstrap by IP Address directly? Sent from my iPhone > On May 16, 2018, at

Re: [tor-relays] Verizon AS701 blocking Tor consensus server tor26 (86.59.21.38)

2018-05-16 Thread Nathaniel Suchy (Lunorian)
Can you still use Tor on Verizon with bridges? Sent from my iPhone > On May 16, 2018, at 11:05 AM, Roger Dingledine wrote: > >> On Tue, May 15, 2018 at 08:12:50PM -0400, Neel Chauhan wrote: >> Hi tor-relays mailing list, >> >> I have noticed that the Tor consensus server tor26

Re: [tor-relays] DigitalOcean bandwidth billing changes

2018-05-02 Thread Nathaniel Suchy (Lunorian)
They are slowly becoming an AWS Clone - they keep adding more and more services making the UI Confusing. Now they've even copied AWSs bill per GB. What's next? Ralph Seichter: > On 02.05.18 18:17, mick wrote: > >> Following this I went back to Rafael Rosa, the Product Manager at >> DigitalOcean

Re: [tor-relays] dew questions about Tor-relay

2018-05-03 Thread Nathaniel Suchy (Lunorian)
> can i set in my "torrc" file what ip i dont want/want to connect me? You can use your exit policy to control what your exit connects to. As far as I’m aware you can’t control who uses your exit. Sent from my iPhone > On May 3, 2018, at 10:09 AM, Matt Traudt wrote: >

[tor-relays] Tor relay marked as hibernating?

2018-04-28 Thread Nathaniel Suchy (Lunorian)
Hi, The Tor relay https://metrics.torproject.org/rs.html#details/B0BF533DA3BC09DEEB4AF2BEC16FA21063216FE4 of mine is marked as hibernating however I have not set a bandwidth limit. Any idea on why this is happening? Cheers, Nathaniel Suchy signature.asc Description: OpenPGP digital signature