[Bug 1222662] Re: Upgrade 2.4 (as recommended by Tor dev) - due to DHE 1024

2013-09-14 Thread Jacob Appelbaum
Hi - Tor (and incidentally a newly minted Debian) developer here - I'd request that you upgrade the package because 0.2.4.x uses ECC which reduces the load on the network. The Tor Network is under very heavy load and older versions of Tor are being used by a botnet:

[Bug 1041141] Re: pidgin crashes with malformed png

2012-08-26 Thread Jacob Appelbaum
This bug appears to actually crash the X server - so it's probably a bug in a few things. Please read the pidgin bug to better understand the issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1041141] [NEW] pidgin crashes with malformed png

2012-08-24 Thread Jacob Appelbaum
*** This bug is a security vulnerability *** Public security bug reported: This is for Pidgin 2.7.11 (libpurple 2.7.11); the package is 'pidgin' version '1:2.7.11-1ubuntu2.2' on Ubuntu Natty. I originally reported this to the Pidgin developers but it appears to also be related to GTK on Natty.

[Bug 1000392] [NEW] pidgin-otr security fix

2012-05-16 Thread Jacob Appelbaum
*** This bug is a duplicate of bug 1000363 *** https://bugs.launchpad.net/bugs/1000363 *** This bug is a security vulnerability *** Public security bug reported: intrigeri has discovered a format string bug in the most recently packaged versions of pidgin-otr; I've tested the patch and

[Bug 1000392] Re: pidgin-otr security fix

2012-05-16 Thread Jacob Appelbaum
*** This bug is a duplicate of bug 1000363 *** https://bugs.launchpad.net/bugs/1000363 This is also a debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=673154 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1000392] Re: pidgin-otr security fix

2012-05-16 Thread Jacob Appelbaum
*** This bug is a duplicate of bug 1000363 *** https://bugs.launchpad.net/bugs/1000363 It appears that this is a dupe but the bug system is crashing when i try to mark it as such: https://bugs.launchpad.net/ubuntu/+source/pidgin-otr/+bug/1000363 ** This bug has been marked a duplicate of

[Bug 885027] Re: SUID Mount Helper has 5 Major Vulnerabilities

2011-11-03 Thread Jacob Appelbaum
Thanks to Ubuntu for not shipping an obviously exploitable component in the face of an arrogant upstream author who puts his users at risk. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/885027 Title:

[Bug 200109] Re: DMA for firewire opens security hole

2011-10-20 Thread Jacob Appelbaum
I've opened a new bug that is related as the situation has changed: https://bugs.launchpad.net/ubuntu/+bug/879087 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/200109 Title: DMA for firewire opens

[Bug 697407] Re: Please update Tor in older versions of Ubuntu

2011-09-28 Thread Jacob Appelbaum
What needs to be done to push this bug forward? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/697407 Title: Please update Tor in older versions of Ubuntu To manage notifications about this bug go

[Bug 781870] Re: 32-bit libraries erroneously load 64-bit libraries

2011-08-06 Thread Jacob Appelbaum
I found that IDA Pro 6.0 worked fine on the previous version of Ubuntu but on 11.04, I had to write a wrapper to work around this bug: cat idaq64.sh #!/bin/bash export GDK_PIXBUF_MODULE_FILE=/usr/lib32/gdk-pixbuf-2.0/2.10.0/loaders.cache ~/bin/ida/idaq64 This seems allow IDA Pro to launch but

[Bug 781870] Re: 32-bit libraries erroneously load 64-bit libraries

2011-08-06 Thread Jacob Appelbaum
I've found that it's is simpler and more stable to build a 32bit Maverick chroot with a few bind mounts for running IDA Pro. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/781870 Title: 32-bit

[Bug 134208] Re: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg

2011-02-12 Thread Jacob Appelbaum
I'm one of the upstream developers and the other upstream developer in the discussion is the main Debian packager. :-) If you want to write a patch and had a good reason, I think we might accept it - otherwise, I suspect we'd rather not add a new dep (lsb- base) just because it looks pretty

[Bug 134208] Re: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg

2011-02-12 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Status: Confirmed = In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/134208 Title: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg --

[Bug 314223] Re: [ubuntu 8.04] tor crashed when working as a server

2011-02-11 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Status: New = Invalid ** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

[Bug 310136] Re: tor increase open files limit

2011-02-11 Thread Jacob Appelbaum
The debian/Ubuntu build should have their ulimit raised automatically. ** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) ** Changed in: tor (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu

[Bug 246811] Re: No obvious way to automatically run / does not run by default

2011-02-11 Thread Jacob Appelbaum
Tor should start by default unless Vidalia is configured to override it. ** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) ** Changed in: tor (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu

[Bug 149679] Re: package tor 0.1.2.17-1 failed to install/upgrade: subprocess post-installation script returned error exit status 1

2011-02-11 Thread Jacob Appelbaum
Is this bug still relevant? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/149679 Title: package tor 0.1.2.17-1 failed to install/upgrade: subprocess post- installation script returned error exit

[Bug 80369] Re: tor postinst script should configure tor to run in a chroot

2011-02-11 Thread Jacob Appelbaum
This will happen if and only if the upstream package (debian) does this by default. ** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) ** Changed in: tor (Ubuntu) Status: Confirmed = Invalid -- You received this bug notification because you

[Bug 134208] Re: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg

2011-02-11 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/134208 Title: /etc/init.d/tor doesn't use log_daemon_msg

[Bug 134208] Re: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg

2011-02-11 Thread Jacob Appelbaum
How important is this? We're currently discussing the issues upstream. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/134208 Title: /etc/init.d/tor doesn't use log_daemon_msg/log_end_msg --

[Bug 355294] Re: Tor and Privoxy improperly configured together by default

2011-02-11 Thread Jacob Appelbaum
socksParentProxy = localhost:9050 socksProxyType = socks5 tunnelAllowedPorts = 1-65535 I believe this should go in the privoxy package and not the Tor package. ** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) ** Changed in: tor (Ubuntu) Status: New

[Bug 697407] Re: Please update Tor in older versions of Ubuntu

2011-02-11 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/697407 Title: Please update Tor in older versions of Ubuntu

[Bug 314585] Re: tor 0.1.2.19-2 (amd64) crash in getinfo_helper_dir - handle_control_getinfo - connection_control_process_inbuf

2011-02-11 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Assignee: (unassigned) = Jacob Appelbaum (jacob-appelbaum) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/314585 Title: tor 0.1.2.19-2 (amd64) crash in getinfo_helper_dir

[Bug 149679] Re: package tor 0.1.2.17-1 failed to install/upgrade: subprocess post-installation script returned error exit status 1

2011-02-11 Thread Jacob Appelbaum
** Changed in: tor (Ubuntu) Assignee: Weems (leoville) = Jacob Appelbaum (jacob-appelbaum) ** Changed in: tor (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
I'd like to confirm this bug too when using an SSH key with no passphrase. I'm able to override the issue by running SSH_AUTH_SOCK=0 ssh -v user@host Description:Ubuntu 10.04.1 LTS Release:10.04 Codename: lucid -- You received this bug notification because you are a member of

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
I should note that this x86_64 and so clearly it's not a big endian bug for my machine. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in ubuntu. https://bugs.launchpad.net/bugs/201786 Title: ssh Agent admitted failure to

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
If I install 'seahorse-plugins', I'm still not able to use this key and account without modifying SSH_AUTH_SOCK. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in ubuntu. https://bugs.launchpad.net/bugs/201786 Title: ssh

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
I'd like to confirm this bug too when using an SSH key with no passphrase. I'm able to override the issue by running SSH_AUTH_SOCK=0 ssh -v user@host Description:Ubuntu 10.04.1 LTS Release:10.04 Codename: lucid -- You received this bug notification because you are a member of

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
I should note that this x86_64 and so clearly it's not a big endian bug for my machine. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/201786 Title: ssh Agent admitted failure to sign using the key

[Bug 201786] Re: ssh Agent admitted failure to sign using the key on big endian machines

2011-01-27 Thread Jacob Appelbaum
If I install 'seahorse-plugins', I'm still not able to use this key and account without modifying SSH_AUTH_SOCK. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/201786 Title: ssh Agent admitted

[Bug 697407] Re: Please update Tor in older versions of Ubuntu

2011-01-23 Thread Jacob Appelbaum
It probably makes sense to use the packages we have on deb.torproject.org; are we cleared to push those even though they're radically different versions? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 689188] Re: Unblock Tor auto-syncing from Debian

2010-12-13 Thread Jacob Appelbaum
Wonderful! Thank you! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/689188 Title: Unblock Tor auto-syncing from Debian -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 689188] [NEW] Unblock Tor auto-syncing from Debian

2010-12-12 Thread Jacob Appelbaum
Public bug reported: Binary package hint: tor Tor synchronization from Debian is currently blocked. Kees suggested that I should formally ask to have Tor unblocked. The specific packages required from Debian are 'tor' and 'tor-geoipdb'; 'torbutton' would also be nice but isn't as pressing.

[Bug 689188] Re: Unblock Tor auto-syncing from Debian

2010-12-12 Thread Jacob Appelbaum
The main blocker for bug #413657 was that we didn't have anyone inside Tor that wanted to ensure that Ubuntu got the attention that it deserved. That has now changed. I'm a Tor developer and I'm also committed to seeing that our Ubuntu support finally returns to a reasonable state of affairs. The

[Bug 689199] Re: SSHFP DNS record for ppa.launchpad.net

2010-12-12 Thread Jacob Appelbaum
If I were to contribute a list of SSHFP DNS records - where should I do that? Should I file them as bugs? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/689199 Title: SSHFP DNS record for

[Bug 413657] Re: Please sync tor 0.2.1.19-1 (universe) from Debian testing (main)

2010-12-12 Thread Jacob Appelbaum
As I've stated in Bug #689188; I'm willing to take over Tor work on Ubuntu. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/413657 Title: Please sync tor 0.2.1.19-1 (universe) from Debian testing

[Bug 689213] Re: PPA sshd configuration

2010-12-12 Thread Jacob Appelbaum
@Jelmer - exactly; it's either a bug in Twisted or a config issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/689213 Title: PPA sshd configuration -- ubuntu-bugs mailing list

[Bug 689199] Re: SSHFP DNS record for ppa.launchpad.net

2010-12-12 Thread Jacob Appelbaum
Is there a list of all Ubuntu SSH services? I'd be happy to scan some netblocks and produce the required SSHFP records for you guys. I'm not clear on the paramiko status on SSHFP; perhaps someone can ask Robey? DNSSEC is not required for SSHFP - it's merely a good idea if you want to seriously

[Bug 689213] Re: PPA sshd configuration

2010-12-12 Thread Jacob Appelbaum
@andrew - I'm not clear on that either - what seems clear is that if it's administratively prohibited, it should probably say so. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/689213 Title: PPA

[Bug 689188] Re: Unblock Tor auto-syncing from Debian

2010-12-12 Thread Jacob Appelbaum
In case it isn't clear, Peter has done a ton of work on the Debian and consequently Ubuntu packaging. We're very grateful for his efforts and we just want to normalize the process for many Ubuntu users. Advanced users will still want to use his alpha builds in the Tor repo; we just want to make it

[Bug 689213] Re: PPA sshd configuration

2010-12-12 Thread Jacob Appelbaum
@Andrew - probably so; I'm glad that you guys are on top of this. Would it be prudent to log the error and the offending activity, perhaps by user? That would at least give you an idea if people are poking at it and decide if it's worth filing a bug upstream? I agree that this is a lot better