Re: [tor-relays] suspicious "Relay127001" relays

2016-07-06 Thread Ivan Markin
ly (see #19625) and we should stick with things that we know for sure. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] suspicious "Relay127001" relays

2016-07-06 Thread Ivan Markin
oject.org/projects/tor/ticket/19625 Thanks, -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] suspicious "Relay127001" relays

2016-07-07 Thread Ivan Markin
ouble for running an Exit node in some countries but everything is fine without exiting there. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] interesting tor platform string or tor bug?

2016-07-07 Thread Ivan Markin
scriptors > > Could this be a bug in Atlas? Nope, Onionoo returns the same platform line [1]. [1] https://onionoo.torproject.org/details?lookup=7A9A7CD200D288DD7D78542779DE16070BC8BFFD -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torpr

Re: [tor-relays] interesting tor platform string or tor bug?

2016-07-08 Thread Ivan Markin
in8.1 or Win10 and detect Win10 as 6.2 (Win8). [1] https://msdn.microsoft.com/en-us/library/windows/desktop/ms724451%28v=vs.85%29.aspx [2] https://gitweb.torproject.org/tor.git/tree/src/common/compat.c#n2711 -- Ivan Markin ___ tor-relays mailing list tor-re

Re: [tor-relays] suspicious "Relay127001" relays

2016-07-06 Thread Ivan Markin
in quick on egress from to any block out quick on egress from any to }}} -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] assign_to_cpuworker failed

2017-01-22 Thread Ivan Markin
nce of hitting rate-limits (likely RAM usage). Probably there is a memory leakage somewhere that makes everything fail and get process eventually killed by OS. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] assign_to_cpuworker failed

2017-01-24 Thread Ivan Markin
be fixed since it may be a DoS vulnerability (process crash). So if you have some details on this issue please report them to the mentioned ticket. Thanks, -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Atlas: Short term bandwidth charts missing ?

2017-01-19 Thread Ivan Markin
ata; monthly and > yearly charts showing up quite well): > Sorry, if this is my local issue but I just can't find the reason for > it... Not just you. This data is gone. Though Atlas still 'plots' it. See https://trac.torproject.org/projects/tor/ticket/1

Re: [tor-relays] descriptor-id calc tool?

2017-02-28 Thread Ivan Markin
iptor-ids for the future N days for onion address M (for the > pre-prop224 world). FYI https://gist.github.com/nogoegst/895dde228496e04f409fc6d160a5de5a $ go run onion-desc-advance.go -time 1488288001 yrcfcqhja2ide7yh prints descriptor IDs for the given time for replica #1 and #2. HTH -- Ivan Mark

Re: [tor-relays] How to include files into torrc?

2016-09-09 Thread Ivan Markin
David Goulet: > Not possible to "include" sub torrc files unfortunately. One surely can do mkfifo + cat. P.S. Ha-ha. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman

Re: [tor-relays] new warn message: Duplicate rendezvous cookie in ESTABLISH_RENDEZVOUS.

2016-10-07 Thread Ivan Markin
e independent/modified implementation. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] new warn message: Duplicate rendezvous cookie in ESTABLISH_RENDEZVOUS.

2016-10-07 Thread Ivan Markin
S cell to the same relay with the same cookie. Most likely it's behavior of some alternative/modified tor implementation (since it started recently and at almost the same time?). At least I can't find a way little-t-tor is able to do this. -- Ivan Markin _

Re: [tor-relays] list of bridges

2016-09-15 Thread Ivan Markin
Ivan Semenov: > Hello, can I get some vanilla bridges pls Go to https://bridges.torproject.org/ and select 'none' as Pluggable Transport. Voila. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/

Re: [tor-relays] Middle relay

2016-09-16 Thread Ivan Markin
ing "peering policy". If this would be implemented one can restrict connections only to relays in consensus (but not bridges?). [1] https://trac.torproject.org/projects/tor/ticket/19625 -- Ivan Markin ___ tor-relays mailing list tor-rela

Re: [tor-relays] Reasons to avoid being a guard?

2016-09-16 Thread Ivan Markin
danger users by running a Guard relay there. Just a guess. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Guard Flag without stable Flag

2016-08-17 Thread Ivan Markin
g --contains c4208ef65f58836670dab286bad0289259582124 tor-0.2.9.1-alpha So it's just 'moria1'. [1] https://trac.torproject.org/projects/tor/ticket/18624 [2] https://gitweb.torproject.org/tor.git/commit/?id=c4208ef65f58836670dab286bad0289259582124 -- Ivan Markin __

Re: [tor-relays] GeoIP

2016-08-23 Thread Ivan Markin
LL#n44 [3] ​ https://geolite.maxmind.com/download/geoip/database/GeoLite2-City-CSV.zip [4] https://trac.torproject.org/projects/tor/ticket/19437 -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bi

Re: [tor-relays] halp #2

2016-08-23 Thread Ivan Markin
uld be enough. You can keep default torrc if you want. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] HALP!

2016-08-23 Thread Ivan Markin
ely different system (E.g. tor user was `debian-tor` and it's `_tor` on the new one. Also different locations, like Windows/Darwin/BSDs/Linux). Asking for comments before creating a ticket since this idea can be inherently wrong. Thanks, -- Ivan Markin __

Re: [tor-relays] new warn message: Duplicate rendezvous cookie in ESTABLISH_RENDEZVOUS.

2016-10-10 Thread Ivan Markin
hopefully not little-t-tor one(s)] who send such cells. Thanks everybody reporting about this issue! -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] network scan results for CVE-2016-5696 / rfc 5961

2016-11-17 Thread Ivan Markin
b/master/scan_archive/nov17_2016/combined_results.csv -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] OpenWrt

2016-10-31 Thread Ivan Markin
memory while parsing consensus. See this discussion [1]. [1] https://lists.torproject.org/pipermail/tor-dev/2016-May/010973.html -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listin

Re: [tor-relays] 0.2.8.11 bridge + hidden service, restart loop

2016-12-09 Thread Ivan Markin
options. See logs > for details.** -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-09 Thread Ivan Markin
lenge ACK counter values higher than > a million... which would indicate some kind of funny business. It may not indicate this. Since I was able to scan whole Tor network in just 7 minutes (someone can use more than 127 concurrent scans and scan even faster), it may indicate that there i

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-08 Thread Ivan Markin
e tip! Laziness just took over me then. It turns out that vulnerable consensus weight fraction is 0.249602 or 25%. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-08 Thread Ivan Markin
! [*] I think it should be more accurate. [1] https://github.com/nogoegst/grill [2] https://gist.github.com/nogoegst/d2de330b794b47158b4cfbed0987b4de -- Happy life without suffering, Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-08 Thread Ivan Markin
;guard discovery attack based on pure off-path TCP attack" make this *slightly* obvious. So if someone actually got it, it's likely that they're already exploiting it. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] Atlas - location of relay changed

2016-12-10 Thread Ivan Markin
n' relay [2]). [1] https://trac.torproject.org/projects/tor/ticket/19437 [2] https://atlas.torproject.org/#details/BC630CBBB518BE7E9F4E09712AB0269E9DC7D626 -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.o

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread Ivan Markin
e is an awesome The Tor BSD Diversity Project. The instructions for BSD beginners can be found here [1]. [1] https://torbsd.github.io/relay-guides.html -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread Ivan Markin
n number of sent RSTs, probably rate-limited Current (these) definitions are here [1]. But they are a subject of change, because I'm trying to improve scanning method (separating counters for each of bursts). [1] https://github.com/nogoegst/grill/blob/master/verdict/verd

Re: [tor-relays] asymmetry in connections

2016-12-16 Thread Ivan Markin
t ones) per TLS connection if a relay joined the network recently o one has ~7100 [number of relays] TLS connections if their relay is up for quite some time o TLS connection is not going to terminate if no circuits left on it* [*] I may be wrong about it. It holds true from my experience.

Re: [tor-relays] Cloning a relay - duplicate fingerprint

2016-12-17 Thread Ivan Markin
contains long-term relay private key and edited only torrc (nickname, ports, whatever). Try to clear DataDirectory out and restart tor - it should regenerate the keys. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://li

Re: [tor-relays] Cloning a relay - duplicate fingerprint

2016-12-17 Thread Ivan Markin
pushed out from consensus. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] assign_to_cpuworker failed

2017-01-14 Thread Ivan Markin
ctions on your relay (maybe I'm wrong)? -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] confusing error from "tor --verify-config"

2016-12-20 Thread Ivan Markin
Pascal Terjan: > I would suggest running tor --verify-config as debian-tor user > instead of root I would suggest not running tor as root . :) As root you can do: su debian-tor "tor --verify-config" -- Ivan Markin ___ tor-relays

Re: [tor-relays] confusing error from "tor --verify-config"

2016-12-21 Thread Ivan Markin
ting shell should "fix" this: su debian-tor -s /bin/sh -c "tor --verify-config" -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] asymmetry in connections

2016-12-18 Thread Ivan Markin
on! Though I can't see how do these two intersect. What is a path for TLS to close in "a few minutes if there is no traffic"? If there is no traffic (no circuits) on top of a TLS connection it still can be used in next 7 days, right? -- Ivan Markin

Re: [tor-relays] TransPort: Convert iptables to pf

2016-12-21 Thread Ivan Markin
rules for Anonymizing Middlebox (though on modern OpenBSD) quite some time ago and it seemed to work fine. These should not only work locally - it's for entire LAN. Are these ones you tried? -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproje

Re: [tor-relays] Reset torrc file

2016-12-21 Thread Ivan Markin
tation how to deal with config updates. Please drop a hint here if you succeeded! * This never happened to me on many systems as they have some sort of config management. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.

Re: [tor-relays] [tor-r@elays] What's a "useful" relay?

2016-12-23 Thread Ivan Markin
ou have modern ARM then you have NEON so ChaCha20 should be better that AES. That said slow relays may become a bit faster. Location diversity as self-hosting is another argument (recall tons of OVH VPS relays). Some best practices definitely would be awe

Re: [tor-relays] What's a "useful" relay?

2016-12-23 Thread Ivan Markin
ctivity, etc, etc. If you think that your relay is underrated or has poor performance try to adjust your hardware/settings. Anyway almost every relay operator has this kind of "operator anxiety". Don't worry. ;) -- Ivan Markin ___ tor-relays mailing

Re: [tor-relays] Is MaxMemInQueues recognized my tor? (was: A Question about aes-ni and the use of RAM.)

2016-12-22 Thread Ivan Markin
ier versions. You will not see anything in logs until this value isn't good and was adjusted by tor. For details, see compute_real_max_mem_in_queues() function in /src/or/config.c. -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.to

Re: [tor-relays] Is AES-NI enabled in tor? (was: A Question about aes-ni and the use of RAM)

2016-12-22 Thread Ivan Markin
4119/how-can-i-check-if-openssl-is-support-use-the-intel-aes-ni -- Ivan Markin ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

Re: [tor-relays] "[warn] Cannot make an outgoing connection without a DirPort" under BSD

2016-12-24 Thread Ivan Markin
[warn] Cannot make an outgoing connection without a > DirPort. This is probably a bug. Try to switch log level to "info" - tor should provide a more detailed backtrace saying something like "Address came from...". Please don't forget to sanitize log from

Re: [tor-relays] descriptor-id calc tool?

2017-03-02 Thread Ivan Markin
the 3 HSDirs next to it (by sorted fingerprint). tldr: HSDir != IntroPoint. Introduction points are chosen by random by an onion service and unknown in advance. What is known in advance is only the onion address. Descriptor ID determines which HSDirs are responsible for storing corresponding des