<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Anonymous Living</title>
	<atom:link href="http://anonymous.livelyblog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://anonymous.livelyblog.com</link>
	<description>Be Anonymous, Stay Anonymous, Live Anonymous</description>
	<pubDate>Thu, 27 Mar 2008 15:41:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Work on Tor this summer, get paid by Google</title>
		<link>http://anonymous.livelyblog.com/2008/03/27/work-on-tor-this-summer-get-paid-by-google/</link>
		<comments>http://anonymous.livelyblog.com/2008/03/27/work-on-tor-this-summer-get-paid-by-google/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 15:41:35 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2008/03/27/work-on-tor-this-summer-get-paid-by-google/</guid>
		<description><![CDATA[The following e-mail regarding paid-by-google Tor-work this summer appeared on OR-talk today:

Hi folks,We (EFF and Tor working together) have been accepted into Google&#8217;s
Summer of Code 2008. This means they&#8217;ll fund several students to work
with us this summer on projects related to Tor. International students
are welcome too.
The deadline for students submitting applications is _MARCH 31_.
I&#8217;ve put [...]]]></description>
			<content:encoded><![CDATA[<p>The following e-mail regarding paid-by-google Tor-work this summer appeared on OR-talk today:</p>
<hr />
Hi folks,We (EFF and Tor working together) have been accepted into Google&#8217;s<br />
Summer of Code 2008. This means they&#8217;ll fund several students to work<br />
with us this summer on projects related to Tor. International students<br />
are welcome too.</p>
<p>The deadline for students submitting applications is _MARCH 31_.</p>
<p>I&#8217;ve put up a page with more details here:<br />
<a href="https://www.torproject.org/gsoc">&nbsp;<a href="https://www.torproject.org/gsoc</a>&#8221; title=&#8221;https://www.torproject.org/gsoc</a>&#8221; target=&#8221;_blank&#8221;>https://www.torproject.org/gsoc</a></a><br />
and there&#8217;s a big list of potential projects here:<br />
<a href="https://www.torproject.org/volunteer#Projects">&nbsp;<a href="https://www.torproject.org/volunteer#Projects</a>&#8221; title=&#8221;https://www.torproject.org/volunteer#Projects</a>&#8221; target=&#8221;_blank&#8221;>https://www.torproject.org/volunteer#Pro&#8230;</a></p>
<p>Please let us know if you&#8217;re interested, and spread the word. The<br />
more applications we get, the more likely Google is to give us good<br />
students. So if you haven&#8217;t filled up your summer plans yet, consider<br />
spending some time working with us to make Tor better!</p>
<p>Thanks,<br />
&#8211;Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2008/03/27/work-on-tor-this-summer-get-paid-by-google/feed/</wfw:commentRss>
		</item>
		<item>
		<title>State of the .onion</title>
		<link>http://anonymous.livelyblog.com/2008/01/04/state-of-the-onion/</link>
		<comments>http://anonymous.livelyblog.com/2008/01/04/state-of-the-onion/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 21:22:37 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2008/01/04/state-of-the-onion/</guid>
		<description><![CDATA[Tor allows people to run location hidden services. These are services who run on Tor-clients (running as a bridge or server is not required) who allow people to conenct to them through servers in the Tor-network.
The location of the services are location hidden in a way which makes it extremely hard to figure out where [...]]]></description>
			<content:encoded><![CDATA[<p>Tor allows people to run <em>location hidden services</em>. These are services who run on Tor-clients (running as a bridge or server is not required) who allow people to conenct to them through servers in the Tor-network.</p>
<p>The location of the services are location hidden in a way which makes it extremely hard to figure out where in the world they are actually located. This means that they can be run anonymously. How secure they <em>really</em> are is still a subject of debate, and many groups are doing research on this subject. It is pretty safe to assume that it is very very hard to locate a location hidden Tor-service, even thoughthere are research papers who debate how it could, in theory, be done given control of enough Tor-servers, time and resources.</p>
<h2>The state of the .onion</h2>
<p>The location hidden services have addresses who look very much like normal domains, except that they are random text strings (actually a hash of the services private key) who end with the special Tor-domain .onion. You must connect tusing a Tor-client to be able to access these sites. So what kind of .onion sites are there, as of today? What kind of sites do those who want to hide who runs the sites and where in the world they make available?</p>
<h3>Pr0n!</h3>
<p>Pornography seems to be a very popular subject on the .onion, just<br />
like it is on the normal Internet.</p>
<p><a href="http://anegvjpd77xuxo45.onion/pe/">The Another Porn Exchange (APE)</a> and <a href="http://hb4pm4eznzhd6mts.onion/pe/feedback.php">Yet Another Porn Exchange (YAPE)</a>  seems to be very popular.</p>
<h3>Forums</h3>
<p>The various forums are also quite popular. Like <a href="http://l6nvqsqivhrunqvs.onion/?do=main">The Onionforum</a>. People go there and talk about all kinds of things, mostly normal things like politics and the various other subjects who are popular on the normal Internet. There are also some post on subjects who I assume nobody would dare talk about without being anonymous, but this is actually less frequently the case. Most people go there and talk about the same things they talk about in other forums, except that they happen to be anonymous when using this service and happen to not be able to find out who is running the forum.</p>
<p>There&#8217;s also <a href="http://xiwayy2kn32bo3ko.onion/tor/">http://xiwayy2kn32bo3ko.onion/tor/</a>, a forum where people write using small drawings who look like houses, squares, circles and other odd things. There are rumors that people in Asia understand these drawings.</p>
<h3>Documents, books, etc</h3>
<p>Alex Jones of <a href="http://infowars.com/">Infowars.com</a> and <a href="http://www.prisonplanet.com/">PrisonPlanet.com</a> has &#8220;read the federal documents, and know their TOTAL PLAN&#8221;. He is a pretty popular guy because of it, and is even mentioned is various posts the <a href="http://eqt5g4fuenphqinx.onion/">core.onion</a> because of is knowledge of such documents. Many interesting documents are available on various onion sites. <a href="http://am4wuhz3zifexz5u.onion/Library/">The Tor Library</a> has a quite a few. <a href="http://torlandypjxiligx.onion/">Bebop&#8217;s Home in Onionspace</a> has a great collection of cyberpunk (and other) documents. You may also want to read <a href="http://duskgytldkxiuqc6.onion/comsense.html">Thomas Paine&#8217;s Common Sense</a> and  <a href="http://duskgytldkxiuqc6.onion/fedpapers/federa00.htm">The Federalist papers</a>, which were originally published anonymously. There are also Tor mirrors of sites on the normal Internet, such as <a href="http://t3xtfil32qgyzprf.onion/">textfiles.com</a>. A <a href="http://wufojrt7wsb55yum.onion/">interesting document leaked out of the German police</a> is also worth reading. Orwell&#8217;s 1984, and other books, are available at a text files at <a href="http://2evy5quvwdyiyuqr.onion/mirrors/">http://2evy5quvwdyiyuqr.onion/mirrors/</a></p>
<h3>Blogs!</h3>
<p>Blogs, like this one, are read by many people. There are, naturally, many onion blogs too. Like  <a href="http://balrqba4x57ofa6s.onion/">http://balrqba4&#215;57ofa6s.onion/</a>, which is mostly about Tor-related software. <a href="http://xtp4iqreupbd5neb.onion/content/">Monster</a> warns that the Ice-Age is Coming.</p>
<h3>Videos</h3>
<p>Some people do not like WTO, which is understandable since they are powertripping tyrants who want dictatorial control over you and your family. A <a href="http://g55o4txfy5yvxkdq.onion/">mirror of quite a few WTO protest videos</a> exist within in onion-land.</p>
<h3>Chat and talk about how your day was</h3>
<p>People like to talk about their day anonymously. There are many onoin IRC servers. There&#8217;s even a <a href="http://lvquxq7logzivc2g.onion/">web based chat</a>.</p>
<h3>Software</h3>
<p>The <a href="http://mnwmeb5yt7scvnmw.onion/"><em>masked operating system</em></a> can (only?) be downloaded using Tor. There are also various <a href="http://zava6zexitcqdutl.onion/db/">attack and defend</a> tools available. If you find yourself under computer attack by commie nazi then perhaps you should go there and find out what they are using to attack you and how to defend yourself. <a href="http://gdos2zurqy7miigj.onion/pub/">http://gdos2zurqy7miigj.onion/pub/</a> allows you to download GnuPG and other nice things.</p>
<h3>Files&#8230;</h3>
<p>Sites such as <a href="http://utovvyhaflle76gh.onion/">sTORage</a> and the <a href="http://xmetrvh465rhx3yq.onion/">Anonymous Upload Center</a> allow people to upload and download files. All sorts of things are available that those kind of services. All they have in common is that the content serviced as <em>files</em>&#8230;</p>
<h3>Games!</h3>
<p>There are also some pirated consolegames for the MAME arcade machine emulator floating around. I guess it is a good idea to hide who you are when you are making <a href="http://anegvjpd77xuxo45.onion/mamerom/">hundres of pirated MAME ROMS</a> available to the general public - even though there are actually quite a few sites offering the same games on the regular Internet.</p>
<h3>Search</h3>
<p>You can use <a href="http://5kdgyjnpcihfzskc.onion/">Torgle</a>  to search.</p>
<h3>Gone with the wind&#8230;</h3>
<p>It appears that many of the previously popular .onion sites are now gone with the wind. Which is understandable, it is hard to maximise profits now by running these services: How do you get anyone to pay you when the visitors of you site are all Tor-users who are unwilling to tell you who or where they are?</p>
<p>nnqtnsoohprzqcke.onion was a popular .onion-only search-engine based on the datapark motor. It&#8217;s now gone with the wind, just like many other onion sites.</p>
<h3>Interesting? not really..</h3>
<p>Some onions are just plain uninteresting. Like <a href="http://metaq3ayddzzcfzc.onion/">http://metaq3ayddzzcfzc.onion/</a>, which only tells you that &#8220;It works!&#8221;. That&#8217;s probably <em>great</em>, but it&#8217;s really not that <em>interesting</em>.</p>
<h2>Starting points</h2>
<p>The <a href="http://anegvjpd77xuxo45.onion/services/">http://anegvjpd77xuxo45.onion/services/</a> services list periodically checks onion-sites it knows about and lists which are up and which are down. Many people like to add their sites to <a href="http://eqt5g4fuenphqinx.onion/">core.onion</a>, since that is listed in the Tor-page on the heavily-censored NATO (=nazi)  propaganda vessle &#8220;Wikipedia&#8221;. There are &#8220;HiddenServices&#8221; pages <a href="http://rjgcfnw4sd2jaqfu.onion/pantawiki/HiddenServices">here</a>, <a href="http://anegvjpd77xuxo45.onion/wiki/HiddenServices">here</a> and <a href="http://metaq3ayddzzcfzc.onion/wiki/index.php?page=HiddenServices">here</a>.  The <a href="http://5kdgyjnpcihfzskc.onion/">Torgle</a> search engine is also a nice starting point, just type in what you are looking for and it will (mostly) find something about that.</p>
<p>Have fun in onion-land! And remember, think before posting in forums and such. What you say can be used to identify who you are, or where you are, what your interests are and so on regardless of the connection being anonymous or not. If you post your phone number then everybody knows who you are, regardless of how you post it&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2008/01/04/state-of-the-onion/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Video of the Tor-presentation at 24c3 is now available</title>
		<link>http://anonymous.livelyblog.com/2008/01/04/video-of-the-tor-presentation-at-24c3-is-now-available/</link>
		<comments>http://anonymous.livelyblog.com/2008/01/04/video-of-the-tor-presentation-at-24c3-is-now-available/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 20:37:17 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<category><![CDATA[Traffic analysis]]></category>

		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2008/01/04/video-of-the-tor-presentation-at-24c3-is-now-available/</guid>
		<description><![CDATA[A video of the not-so-secret (as A.Y. pointed out) presenation on the future of Tor and the Torproject at the 24c3 conference in Berlin are now available on the various mirrors where the videos from the presenations at that conference can be downloaded. Look for &#8220;24c3-2325-en-current_events_in_tor_development&#8221; on the mirrors listed at 24c3&#8217;s &#8220;Conference Recordings&#8221; page [...]]]></description>
			<content:encoded><![CDATA[<p>A video of the not-so-secret (as <a href="http://anonymous.livelyblog.com/2007/12/29/faster-tor-thanks-to-better-buffer-implementation/#comment-86">A.Y. pointed out</a>) presenation on the future of Tor and the Torproject at the 24c3 conference in Berlin are now available on the various mirrors where the videos from the presenations at that conference can be downloaded. Look for &#8220;24c3-2325-en-current_events_in_tor_development&#8221; on the mirrors listed at 24c3&#8217;s &#8220;<a href="http://events.ccc.de/congress/2007/Conference_Recordings">Conference Recordings</a>&#8221; page if you are interested. The also-not-so-secret slides from the presentation are available at <a href="http://freehaven.net/~arma/slides-24c3.pdf">http://freehaven.net/~arma/slides-24c3.pdf</a>.</p>
<p>Older Tor-presentations (From 23c3 and WTH) can be downloaded from <a href="http://torrentchannel.com/technology">The TorrentChannel&#8217;s Technology page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2008/01/04/video-of-the-tor-presentation-at-24c3-is-now-available/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Faster Tor thanks to better buffer implementation</title>
		<link>http://anonymous.livelyblog.com/2007/12/29/faster-tor-thanks-to-better-buffer-implementation/</link>
		<comments>http://anonymous.livelyblog.com/2007/12/29/faster-tor-thanks-to-better-buffer-implementation/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 00:59:58 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/12/29/faster-tor-thanks-to-better-buffer-implementation/</guid>
		<description><![CDATA[Nick Mathewson, one of Torproject&#8217;s leading developers has spent the holliday&#8217;s &#8220;beating the heck out of the buffer implementation&#8221;. Examples of this can be seen both in the code and on Firespray. This has lead to better RAM management and overall performance improvements in the trunk development version of the Tor software compared to the [...]]]></description>
			<content:encoded><![CDATA[<p>Nick Mathewson, one of <a href="https://www.torproject.org/">Torproject</a>&#8217;s leading developers has spent the holliday&#8217;s &#8220;beating the heck out of the buffer implementation&#8221;. Examples of this can be seen both in the code and <a href="http://bugs.noreply.org/flyspray/index.php?do=details&amp;id=468&amp;area=comments#1358">on Firespray</a>. This has lead to better RAM management and overall performance improvements in the trunk development version of the Tor software compared to the latest 0.2.15 release.</p>
<p>In other related news, Roger Dingledine has now prepared and posted secret Tor-presentation slides from the <a href="http://events.ccc.de/congress/2007/Welcome%21">24th Chaos Communication Congress</a> which was held in Berlin, Germany this week.</p>
<p><img src="http://anonymous.livelyblog.com/files/2007/12/secret-24c3-tor-slides.png" alt="secret-24c3-tor-slides.png" /></p>
<p>These secret slides are now available for your studying pleasure at&nbsp;<a href="http://freehaven.net/~arma/slides-24c3.pdf" title="http://freehaven.net/~arma/slides-24c3.pdf" target="_blank">http://freehaven.net/~arma/slides-24c3.p&#8230;</a></p>
<p>One last thing: Happy new year! <img src='http://anonymous.livelyblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/12/29/faster-tor-thanks-to-better-buffer-implementation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tor 0.2.0.12-alpha is out</title>
		<link>http://anonymous.livelyblog.com/2007/11/21/tor-02012-alpha-is-out/</link>
		<comments>http://anonymous.livelyblog.com/2007/11/21/tor-02012-alpha-is-out/#comments</comments>
		<pubDate>Thu, 22 Nov 2007 01:51:38 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/11/21/tor-02012-alpha-is-out/</guid>
		<description><![CDATA[Official story is:
From: Roger Dingledine &#60;arma@mit.edu&#62;
To: &#160;or-talk at freehaven.net
Date: Today 02:00:48
Tor 0.2.0.10-alpha adds a third v3 directory authority run by Mike Perry,
adds most of Karsten Loesing&#8217;s new hidden service descriptor format, fixes
a bad crash bug and new bridge bugs introduced in 0.2.0.9-alpha, fixes
many bugs with the v3 directory implementation, fixes some minor memory
leaks in previous [...]]]></description>
			<content:encoded><![CDATA[<p>Official story is:</p>
<p>From: Roger Dingledine &lt;arma@mit.edu&gt;<br />
To: &nbsp;<a href="mailto:or-talk@freehaven.net" title="mailto:or-talk@freehaven.net">or-talk at freehaven.net</a><br />
Date: Today 02:00:48</p>
<p>Tor 0.2.0.10-alpha adds a third v3 directory authority run by Mike Perry,<br />
adds most of Karsten Loesing&#8217;s new hidden service descriptor format, fixes<br />
a bad crash bug and new bridge bugs introduced in 0.2.0.9-alpha, fixes<br />
many bugs with the v3 directory implementation, fixes some minor memory<br />
leaks in previous 0.2.0.x snapshots, and addresses many more minor issues.</p>
<p>Tor 0.2.0.11-alpha fixes some build problems with the previous<br />
snapshot. It also includes a more secure-by-default exit policy for<br />
relays, fixes an enormous memory leak for exit relays, and fixes another<br />
bug where servers were falling out of the directory list.</p>
<p>Tor 0.2.0.12-alpha fixes some more build problems as well as a few<br />
minor bugs.</p>
<p>&nbsp;<a href="https://www.torproject.org/download.html" title="https://www.torproject.org/download.html" target="_blank">https://www.torproject.org/download.html</a></p>
<p>Changes in version 0.2.0.12-alpha - 2007-11-16<br />
This twelfth development snapshot fixes some more build problems as<br />
well as a few minor bugs.</p>
<p>o Compile fixes:<br />
- Make it build on OpenBSD again. Patch from tup.<br />
- Substitute BINDIR and LOCALSTATEDIR in scripts. Fixes<br />
package-building for Red Hat, OS X, etc.</p>
<p>o Minor bugfixes (on 0.1.2.x):<br />
- Changing the ExitPolicyRejectPrivate setting should cause us to<br />
rebuild our server descriptor.</p>
<p>o Minor bugfixes (on 0.2.0.x):<br />
- When we&#8217;re lacking a consensus, don&#8217;t try to perform rendezvous<br />
operations. Reported by Karsten Loesing.<br />
- Fix a small memory leak whenever we decide against using a<br />
newly picked entry guard. Reported by Mike Perry.<br />
- When authorities detected more than two relays running on the same<br />
IP address, they were clearing all the status flags but forgetting<br />
to clear the &#8220;hsdir&#8221; flag. So clients were being told that a<br />
given relay was the right choice for a v2 hsdir lookup, yet they<br />
never had its descriptor because it was marked as &#8216;not running&#8217;<br />
in the consensus.<br />
- If we&#8217;re trying to fetch a bridge descriptor and there&#8217;s no way<br />
the bridge authority could help us (for example, we don&#8217;t know<br />
a digest, or there is no bridge authority), don&#8217;t be so eager to<br />
fall back to asking the bridge authority.<br />
- If we&#8217;re using bridges or have strictentrynodes set, and our<br />
chosen exit is in the same family as all our bridges/entry guards,<br />
then be flexible about families.</p>
<p>o Minor features:<br />
- When we negotiate a v2 link-layer connection (not yet implemented),<br />
accept RELAY_EARLY cells and turn them into RELAY cells if we&#8217;ve<br />
negotiated a v1 connection for their next step. Initial code for<br />
proposal 110.</p>
<p>Changes in version 0.2.0.11-alpha - 2007-11-12<br />
This eleventh development snapshot fixes some build problems with<br />
the previous snapshot. It also includes a more secure-by-default exit<br />
policy for relays, fixes an enormous memory leak for exit relays, and<br />
fixes another bug where servers were falling out of the directory list.</p>
<p>o Security fixes:<br />
- Exit policies now reject connections that are addressed to a<br />
relay&#8217;s public (external) IP address too, unless<br />
ExitPolicyRejectPrivate is turned off. We do this because too<br />
many relays are running nearby to services that trust them based<br />
on network address. Bugfix on 0.1.2.x.</p>
<p>o Major bugfixes:<br />
- Fix a memory leak on exit relays; we were leaking a cached_resolve_t<br />
on every successful resolve. Reported by Mike Perry; bugfix<br />
on 0.1.2.x.<br />
- On authorities, never downgrade to old router descriptors simply<br />
because they&#8217;re listed in the consensus. This created a catch-22<br />
where we wouldn&#8217;t list a new descriptor because there was an<br />
old one in the consensus, and we couldn&#8217;t get the new one in the<br />
consensus because we wouldn&#8217;t list it. Possible fix for bug 548.<br />
Also, this might cause bug 543 to appear on authorities; if so,<br />
we&#8217;ll need a band-aid for that. Bugfix on 0.2.0.9-alpha.</p>
<p>o Packaging fixes on 0.2.0.10-alpha:<br />
- We were including instructions about what to do with the<br />
src/config/fallback-consensus file, but we weren&#8217;t actually<br />
including it in the tarball. Disable all of that for now.</p>
<p>o Minor features:<br />
- Allow people to say PreferTunnelledDirConns rather than<br />
PreferTunneledDirConns, for those alternate-spellers out there.</p>
<p>o Minor bugfixes:<br />
- Don&#8217;t reevaluate all the information from our consensus document<br />
just because we&#8217;ve downloaded a v2 networkstatus that we intend<br />
to cache. Fixes bug 545; bugfix on 0.2.0.x.</p>
<p>Changes in version 0.2.0.10-alpha - 2007-11-10<br />
This tenth development snapshot adds a third v3 directory authority<br />
run by Mike Perry, adds most of Karsten Loesing&#8217;s new hidden service<br />
descriptor format, fixes a bad crash bug and new bridge bugs introduced<br />
in 0.2.0.9-alpha, fixes many bugs with the v3 directory implementation,<br />
fixes some minor memory leaks in previous 0.2.0.x snapshots, and<br />
addresses many more minor issues.</p>
<p>o New directory authorities:<br />
- Set up ides (run by Mike Perry) as the third v3 directory authority.</p>
<p>o Major features:<br />
- Allow tunnelled directory connections to ask for an encrypted<br />
&#8220;begin_dir&#8221; connection or an anonymized &#8220;uses a full Tor circuit&#8221;<br />
connection independently. Now we can make anonymized begin_dir<br />
connections for (e.g.) more secure hidden service posting and<br />
fetching.<br />
- More progress on proposal 114: code from Karsten Loesing to<br />
implement new hidden service descriptor format.<br />
- Raise the default BandwidthRate/BandwidthBurst to 5MB/10MB, to<br />
accommodate the growing number of servers that use the default<br />
and are reaching it.<br />
- Directory authorities use a new formula for selecting which nodes<br />
to advertise as Guards: they must be in the top 7/8 in terms of<br />
how long we have known about them, and above the median of those<br />
nodes in terms of weighted fractional uptime.<br />
- Make &#8220;not enough dir info yet&#8221; warnings describe *why* Tor feels<br />
it doesn&#8217;t have enough directory info yet.</p>
<p>o Major bugfixes:<br />
- Stop servers from crashing if they set a Family option (or<br />
maybe in other situations too). Bugfix on 0.2.0.9-alpha; reported<br />
by Fabian Keil.<br />
- Make bridge users work again &#8212; the move to v3 directories in<br />
0.2.0.9-alpha had introduced a number of bugs that made bridges<br />
no longer work for clients.<br />
- When the clock jumps forward a lot, do not allow the bandwidth<br />
buckets to become negative. Bugfix on 0.1.2.x; fixes bug 544.</p>
<p>o Major bugfixes (v3 dir, bugfixes on 0.2.0.9-alpha):<br />
- When the consensus lists a router descriptor that we previously were<br />
mirroring, but that we considered non-canonical, reload the<br />
descriptor as canonical. This fixes bug 543 where Tor servers<br />
would start complaining after a few days that they don&#8217;t have<br />
enough directory information to build a circuit.<br />
- Consider replacing the current consensus when certificates arrive<br />
that make the pending consensus valid. Previously, we were only<br />
considering replacement when the new certs _didn&#8217;t_ help.<br />
- Fix an assert error on startup if we didn&#8217;t already have the<br />
consensus and certs cached in our datadirectory: we were caching<br />
the consensus in consensus_waiting_for_certs but then free&#8217;ing it<br />
right after.<br />
- Avoid sending a request for &#8220;keys/fp&#8221; (for which we&#8217;ll get a 400 Bad<br />
Request) if we need more v3 certs but we&#8217;ve already got pending<br />
requests for all of them.<br />
- Correctly back off from failing certificate downloads. Fixes<br />
bug 546.<br />
- Authorities don&#8217;t vote on the Running flag if they have been running<br />
for less than 30 minutes themselves. Fixes bug 547, where a newly<br />
started authority would vote that everyone was down.</p>
<p>o New requirements:<br />
- Drop support for OpenSSL version 0.9.6. Just about nobody was using<br />
it, it had no AES, and it hasn&#8217;t seen any security patches since<br />
2004.</p>
<p>o Minor features:<br />
- Clients now hold circuitless TLS connections open for 1.5 times<br />
MaxCircuitDirtiness (15 minutes), since it is likely that they&#8217;ll<br />
rebuild a new circuit over them within that timeframe. Previously,<br />
they held them open only for KeepalivePeriod (5 minutes).<br />
- Use &#8220;If-Modified-Since&#8221; to avoid retrieving consensus<br />
networkstatuses that we already have.<br />
- When we have no consensus, check FallbackNetworkstatusFile (defaults<br />
to $PREFIX/share/tor/fallback-consensus) for a consensus.  This way<br />
we start knowing some directory caches.<br />
- When we receive a consensus from the future, warn about skew.<br />
- Improve skew reporting: try to give the user a better log message<br />
about how skewed they are, and how much this matters.<br />
- When we have a certificate for an authority, believe that<br />
certificate&#8217;s claims about the authority&#8217;s IP address.<br />
- New &#8211;quiet command-line option to suppress the default console log.<br />
Good in combination with &#8211;hash-password.<br />
- Authorities send back an X-Descriptor-Not-New header in response to<br />
an accepted-but-discarded descriptor upload.  Partially implements<br />
fix for bug 535.<br />
- Make the log message for &#8220;tls error. breaking.&#8221; more useful.<br />
- Better log messages about certificate downloads, to attempt to<br />
track down the second incarnation of bug 546.</p>
<p>o Minor features (bridges):<br />
- If bridge users set UpdateBridgesFromAuthority, but the digest<br />
they ask for is a 404 from the bridge authority, they now fall<br />
back to trying the bridge directly.<br />
- Bridges now use begin_dir to publish their server descriptor to<br />
the bridge authority, even when they haven&#8217;t set TunnelDirConns.</p>
<p>o Minor features (controller):<br />
- When reporting clock skew, and we know that the clock is _at least<br />
as skewed_ as some value, but we don&#8217;t know the actual value,<br />
report the value as a &#8220;minimum skew.&#8221;</p>
<p>o Utilities:<br />
- Update linux-tor-prio.sh script to allow QoS based on the uid of<br />
the Tor process. Patch from Marco Bonetti with tweaks from Mike<br />
Perry.</p>
<p>o Minor bugfixes:<br />
- Refuse to start if both ORPort and UseBridges are set. Bugfix<br />
on 0.2.0.x, suggested by Matt Edman.<br />
- Don&#8217;t stop fetching descriptors when FetchUselessDescriptors is<br />
set, even if we stop asking for circuits. Bugfix on 0.1.2.x;<br />
reported by tup and ioerror.<br />
- Better log message on vote from unknown authority.<br />
- Don&#8217;t log &#8220;Launching 0 request for 0 router&#8221; message.</p>
<p>o Minor bugfixes (memory leaks):<br />
- Stop leaking memory every time we parse a v3 certificate. Bugfix<br />
on 0.2.0.1-alpha.<br />
- Stop leaking memory every time we load a v3 certificate. Bugfix<br />
on 0.2.0.1-alpha. Fixes Bug 536.<br />
- Stop leaking a cached networkstatus on exit.  Bugfix on<br />
0.2.0.3-alpha.<br />
- Stop leaking voter information every time we free a consensus.<br />
Bugfix on 0.2.0.3-alpha.<br />
- Stop leaking signed data every time we check a voter signature.<br />
Bugfix on 0.2.0.3-alpha.<br />
- Stop leaking a signature every time we fail to parse a consensus or<br />
a vote.  Bugfix on 0.2.0.3-alpha.<br />
- Stop leaking v2_download_status_map on shutdown.  Bugfix on<br />
0.2.0.9-alpha.<br />
- Stop leaking conn-&gt;nickname every time we make a connection to a<br />
Tor relay without knowing its expected identity digest (e.g. when<br />
using bridges). Bugfix on 0.2.0.3-alpha.</p>
<p>- Minor bugfixes (portability):<br />
- Run correctly on platforms where rlim_t is larger than unsigned<br />
long, and/or where the real limit for number of open files is<br />
OPEN_FILES, not rlim_max from getrlimit(RLIMIT_NOFILES). In<br />
particular, these may be needed for OS X 10.5.</p>
<p>Official website:&nbsp;<a href="https://www.torproject.org/" title="https://www.torproject.org/" target="_blank">https://www.torproject.org/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/11/21/tor-02012-alpha-is-out/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tor v0.1.2.18 said to be coming soon</title>
		<link>http://anonymous.livelyblog.com/2007/10/23/tor-v01218-said-to-be-coming-soon/</link>
		<comments>http://anonymous.livelyblog.com/2007/10/23/tor-v01218-said-to-be-coming-soon/#comments</comments>
		<pubDate>Wed, 24 Oct 2007 01:13:51 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/10/23/tor-v01218-said-to-be-coming-soon/</guid>
		<description><![CDATA[From OR-Talk,
0.1.2.18 is getting close to ready; please test it
From: Roger Dingledine
To: or-talk
Date: 2007-10-16 06:32
Hi folks,
We&#8217;re getting close to having 0.1.2.18 ready. I&#8217;ve put snapshots at
&#160;https://tor.eff.org/dist/tor-0.1.2.17-de&#8230;
&#160;https://tor.eff.org/dist/tor-0.1.2.17-de&#8230;
&#160;https://tor.eff.org/dist/vidalia-bundles&#8230;
&#160;https://tor.eff.org/dist/vidalia-bundles&#8230;
&#160;https://tor.eff.org/dist/vidalia-bundles&#8230;
&#160;https://tor.eff.org/dist/vidalia-bundles&#8230;
&#160;https://tor.eff.org/dist/win32/tor-0.1.2&#8230;
&#160;https://tor.eff.org/dist/win32/tor-0.1.2&#8230;
&#160;https://tor.eff.org/dist/osx/Tor-0.1.2.1&#8230;
&#160;https://tor.eff.org/dist/osx/Tor-0.1.2.1&#8230;
Please grab it, try it out, and let us know whether we broke anything.
Thanks,
&#8211;Roger
Partial list of changes in version 0.1.2.18 - 2007-10-??

Major bugfixes (crashes):

    - If a connection is shut [...]]]></description>
			<content:encoded><![CDATA[<p>From OR-Talk,</p>
<p>0.1.2.18 is getting close to ready; please test it<br />
From: Roger Dingledine<br />
To: or-talk<br />
Date: 2007-10-16 06:32</p>
<p>Hi folks,</p>
<p>We&#8217;re getting close to having 0.1.2.18 ready. I&#8217;ve put snapshots at</p>
<p>&nbsp;<a href="https://tor.eff.org/dist/tor-0.1.2.17-dev.tar.gz" title="https://tor.eff.org/dist/tor-0.1.2.17-dev.tar.gz" target="_blank">https://tor.eff.org/dist/tor-0.1.2.17-de&#8230;</a><br />
&nbsp;<a href="https://tor.eff.org/dist/tor-0.1.2.17-dev.tar.gz.asc" title="https://tor.eff.org/dist/tor-0.1.2.17-dev.tar.gz.asc" target="_blank">https://tor.eff.org/dist/tor-0.1.2.17-de&#8230;</a></p>
<p>&nbsp;<a href="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14.exe" title="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14.exe" target="_blank">https://tor.eff.org/dist/vidalia-bundles&#8230;</a><br />
&nbsp;<a href="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14.exe.asc" title="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14.exe.asc" target="_blank">https://tor.eff.org/dist/vidalia-bundles&#8230;</a></p>
<p>&nbsp;<a href="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14-tiger.dmg" title="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14-tiger.dmg" target="_blank">https://tor.eff.org/dist/vidalia-bundles&#8230;</a><br />
&nbsp;<a href="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14-tiger.dmg.asc" title="https://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-dev-0.0.14-tiger.dmg.asc" target="_blank">https://tor.eff.org/dist/vidalia-bundles&#8230;</a></p>
<p>&nbsp;<a href="https://tor.eff.org/dist/win32/tor-0.1.2.17-dev-win32.exe" title="https://tor.eff.org/dist/win32/tor-0.1.2.17-dev-win32.exe" target="_blank">https://tor.eff.org/dist/win32/tor-0.1.2&#8230;</a><br />
&nbsp;<a href="https://tor.eff.org/dist/win32/tor-0.1.2.17-dev-win32.exe.asc" title="https://tor.eff.org/dist/win32/tor-0.1.2.17-dev-win32.exe.asc" target="_blank">https://tor.eff.org/dist/win32/tor-0.1.2&#8230;</a></p>
<p>&nbsp;<a href="https://tor.eff.org/dist/osx/Tor-0.1.2.17-dev-tiger-universal-Bundle.dmg" title="https://tor.eff.org/dist/osx/Tor-0.1.2.17-dev-tiger-universal-Bundle.dmg" target="_blank">https://tor.eff.org/dist/osx/Tor-0.1.2.1&#8230;</a><br />
&nbsp;<a href="https://tor.eff.org/dist/osx/Tor-0.1.2.17-dev-tiger-universal-Bundle.dmg.asc" title="https://tor.eff.org/dist/osx/Tor-0.1.2.17-dev-tiger-universal-Bundle.dmg.asc" target="_blank">https://tor.eff.org/dist/osx/Tor-0.1.2.1&#8230;</a></p>
<p>Please grab it, try it out, and let us know whether we broke anything.</p>
<p>Thanks,<br />
&#8211;Roger</p>
<p>Partial list of changes in version 0.1.2.18 - 2007-10-??</p>
<ul>
<li>Major bugfixes (crashes):
<ul>
<li>    - If a connection is shut down abruptly because of something that</li>
<li>      happened inside connection_flushed_some(), do not call</li>
<li>      connection_finished_flushing(). Should fix bug 451:</li>
<li>      &#8220;connection_stop_writing: Assertion conn-&gt;write_event failed&#8221;</li>
<li>      Bugfix on 0.1.2.7-alpha.</li>
<li>    - Fix possible segfaults in functions called from</li>
<li>      rend_process_relay_cell().</li>
</ul>
</li>
<li>  o Major bugfixes (other):
<ul>
<li>    - Stop publishing a new server descriptor just because we get a</li>
<li>      HUP signal. This led (in a roundabout way) to some servers getting</li>
<li>      dropped from the networkstatus lists for a few hours each day.</li>
<li>    - Hidden services were choosing introduction points uniquely by</li>
<li>      hexdigest, but when constructing the hidden service descriptor</li>
<li>      they merely wrote the (potentially ambiguous) nickname.</li>
<li>    - Clients now use the v2 intro format for hidden service</li>
<li>      connections: they specify their chosen rendezvous point by identity</li>
<li>      digest rather than by (potentially ambiguous) nickname. These</li>
<li>      changes could speed up hidden service connections dramatically.</li>
<li>    - When looking for a circuit to cannibalize, consider family as well</li>
<li>      as identity. Fixes bug 438. Bugfix on 0.1.0.x (which introduced</li>
<li>      circuit cannibalization).</li>
</ul>
</li>
<li>Minor bugfixes:
<ul>
<li>Don&#8217;t try to access (or alter) the state file when running &#8211;list-fingerprint or &#8211;verify-config or &#8211;hash-password. (Resolves bug 499.)</li>
<li>When generating information telling us how to extend to a given router, do not try to include the nickname if it is absent. (Resolves bug 467.)</li>
<li>Fix a user-triggerable segfault in expand_filename(). (There isn&#8217;t a way to trigger this remotely.)</li>
<li>When sending a status event to the controller telling it that an OR address is readable, set the port correctly. (Previously we were reporting the dir port.)</li>
<li>Fix a minor memory leak whenever a controller sends the PROTOCOLINFO command. Bugfix on 0.1.2.17.</li>
<li>When loading bandwidth history, do not believe any information in the future. Fixes bug 434.</li>
<li>When loading entry guard information, do not believe any information in the future.</li>
<li>When we have our clock set far in the future and generate an onion key, then re-set our clock to be correct, we should not stop the onion key from getting rotated.</li>
<li>On some platforms, accept() can return a broken address. Detect this more quietly, and deal accordingly. Fixes bug 483.</li>
<li>It&#8217;s not actually an error to find a non-pending entry in the DNS cache when canceling a pending resolve. Don&#8217;t log unless stuff is fishy. Resolves bug 463.</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/10/23/tor-v01218-said-to-be-coming-soon/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Important to know: Attacking the Tor Control Port with Java</title>
		<link>http://anonymous.livelyblog.com/2007/10/23/important-to-know-attacking-the-tor-control-port-with-java/</link>
		<comments>http://anonymous.livelyblog.com/2007/10/23/important-to-know-attacking-the-tor-control-port-with-java/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 23:48:41 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Anonymity Essentials]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/10/23/important-to-know-attacking-the-tor-control-port-with-java/</guid>
		<description><![CDATA[On 3 October 2007, Sun announced several critical security updates for
the Java Runtime Environment.  In particular, describes how network access restrictions can be circumvented to connect to arbitrary hosts by utilizing DNS rebinding.  The paper at Stanford University&#8217;s Protecting Browsers from DNS Rebinding Attacks page summarizes some of the current research into the [...]]]></description>
			<content:encoded><![CDATA[<p>On 3 October 2007, Sun <a href="http://blogs.sun.com/security/entry/sun_alert_103073_multiple_security">announced several critical security updates for<br />
the Java Runtime Environment</a>.  In particular, <a href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103078-1">describes how network access restrictions can be circumvented</a> to connect to arbitrary hosts by utilizing DNS rebinding.  The paper at <a href="http://crypto.stanford.edu/dns/">Stanford University&#8217;s Protecting Browsers from DNS Rebinding Attacks page</a> summarizes some of the current research into the issues of DNS rebinding.</p>
<p>Java exposes a programmatic sockets interface, and a malicious applet can construct properly formed control port commands.  If the control port is enabled with the NULL authentication and accessible to the web browser, the malicious applet can authenticate and send arbitrary commands.</p>
<p>To summarize, Tor users with the following conditions may be at risk:</p>
<ul>
<li>vulnerable version of Java enabled in web browser</li>
<li>control port enabled with NULL authentication and accessible</li>
</ul>
<p>Use of proxy switching browser add-ons (e.g., Torbutton, FoxyProxy)<br />
may increase this risk if the Java Virtual Machine can perform<br />
arbitrary DNS resolution through the native operating system resolver.</p>
<p>Possible workarounds:</p>
<ul>
<li>disable Tor control port</li>
<li>if control port is required, use &#8216;HashedControlPassword&#8217; option</li>
<li>disable Java in the web browser and/or uninstall from OS</li>
<li>If Java is required, consider a virtual machine solution such as <a href="http://janusvm.peertech.org/">JanusVM</a> or firewalled environment that only allows DNS requests through web browser</li>
</ul>
<p>The latest Java downloads are available at <a href="http://java.com/%20or%20http://java.sun.com/javase/downloads/">http://java.com/ or&nbsp;<a href="http://java.sun.com/javase/downloads/</a>&#8221; title=&#8221;http://java.sun.com/javase/downloads/</a>&#8221; target=&#8221;_blank&#8221;>http://java.sun.com/javase/downloads/</a...</a> or from your operating system vendor (or not, depending on how differently you think).</p>
<p>Additional details and demonstration code at <a href="http://pseudo-flaw.net/tor/attacking-tor-control-port-with-java/">http://pseudo-flaw.net/tor/attacking-tor-control-port-with-java/</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/10/23/important-to-know-attacking-the-tor-control-port-with-java/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Admitted: Old Tor-versions are totally insecure</title>
		<link>http://anonymous.livelyblog.com/2007/09/07/admitted-old-tor-versions-are-totally-insecure/</link>
		<comments>http://anonymous.livelyblog.com/2007/09/07/admitted-old-tor-versions-are-totally-insecure/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 19:23:46 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/09/07/admitted-old-tor-versions-are-totally-insecure/</guid>
		<description><![CDATA[The developers of the network security tool Tor issued a warning telling all users to upgrade early August 2007. Tor-developer Roger Dingledine has now disclosed what was wrong with previous version of Tor in regard to basic security. It turns out that evil attacker running a Tor exit node or a website could simply POST [...]]]></description>
			<content:encoded><![CDATA[<p>The developers of the network security tool <a href="https://tor.eff.org/">Tor</a> issued <a href="http://anonymous.livelyblog.com/2007/08/02/tor-users-must-immediately-upgrade-to-v01216/">a warning telling all users to upgrade</a> early August 2007. Tor-developer Roger Dingledine has now disclosed what was wrong with previous version of Tor in regard to basic security. It turns out that evil attacker running a Tor exit node or a website could simply POST to Tor&#8217;s controlport and thereby completely destroy the users security.Official story as admitted in OR-Talk confession <a href="http://archives.seul.org/or/announce/Sep-2007/msg00000.html">Tor security advisory: cross-protocol http form attack</a> is this:</p>
<blockquote><p> # Subject: Tor security advisory: cross-protocol http form attack<br />
# From: Roger Dingledine<br />
# Date: Sat, 1 Sep 2007 14:31:54 -0400</p>
<p>On Thu, Aug 02, 2007 at 06:19:18PM -0400, Roger Dingledine wrote:<br />
&gt; Tor 0.1.2.16 fixes a critical security vulnerability that allows a<br />
&gt; remote attacker in certain situations to rewrite the user&#8217;s torrc<br />
&gt; configuration file. This can completely compromise anonymity of users<br />
&gt; in most configurations, including those running the Vidalia bundles,<br />
&gt; TorK, etc. Or worse.</p>
<p>Here are the further details that we promised:</p>
<p>In a nutshell, a malicious website or Tor exit node can give the Tor<br />
user a page that includes a POST element directed to Tor&#8217;s control port<br />
(localhost:9051). Tor binds its control port only to localhost to avoid<br />
letting untrusted people send it commands, but the attacker skips past<br />
this protection by making the browser do the connection. And the user<br />
doesn&#8217;t even have to click on anything if she&#8217;s got javascript enabled.</p>
<p>This particular attack worked because Tor&#8217;s control protocol gave an<br />
error message on unrecognized commands but didn&#8217;t hang up. So all the<br />
http headers from the POST were unrecognized commands, and eventually<br />
we got to the payload &#8212; which contains recognized commands &#8212; and it<br />
went bad from there.</p>
<p>Jochen Topf wrote a fine paper describing this attack in 2001:<br />
&nbsp;<a href="http://www.remote.org/jochen/sec/hfpa/index.html" title="http://www.remote.org/jochen/sec/hfpa/index.html" target="_blank">http://www.remote.org/jochen/sec/hfpa/in&#8230;</a><br />
Thanks to Kyle Williams and Martin Peck who independently rediscovered<br />
the attack in the context of Tor.</p>
<p>The 0.1.2.16 and 0.2.0.4-alpha versions of Tor patched this particular<br />
problem by hanging up if the first command wasn&#8217;t a successful<br />
&#8216;authenticate&#8217; command. The recently released 0.1.2.17 and 0.2.0.6-alpha<br />
versions of Tor now enable application-level authentication by default<br />
in the Windows and OS X bundles, which should stop a broad class of<br />
related attacks. Everyone should upgrade.</p>
<p>Yay full disclosure,<br />
&#8211;Roger</p></blockquote>
<p>The evidence is overwhelming and can not be denied: Using old versions of the free software network security package &#8220;Tor&#8221; is bad for you and gives you lousy security. It is admitted. You really should download a new version from <a href="https://tor.eff.org/">https://tor.eff.org/</a> and upgrade and share this free software with all your friends.</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/09/07/admitted-old-tor-versions-are-totally-insecure/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tor users must IMMEDIATELY upgrade to v0.1.2.16</title>
		<link>http://anonymous.livelyblog.com/2007/08/02/tor-users-must-immediately-upgrade-to-v01216/</link>
		<comments>http://anonymous.livelyblog.com/2007/08/02/tor-users-must-immediately-upgrade-to-v01216/#comments</comments>
		<pubDate>Fri, 03 Aug 2007 00:12:16 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/08/02/tor-users-must-immediately-upgrade-to-v01216/</guid>
		<description><![CDATA[The&#8217;re actually announceing it, they&#8217;ve already put it in place and you and your familly are now granted access to Tor version 0.1.2.16 by the Tor developers.
You must buy it now
Official Tor story regarding security of current versions of Tor and good reasons to upgrade is this:
 Tor 0.1.2.16 fixes a critical security vulnerability that [...]]]></description>
			<content:encoded><![CDATA[<p>The&#8217;re actually announceing it, they&#8217;ve already put it in place and you and your familly are now granted access to Tor version 0.1.2.16 by the Tor developers.</p>
<h2>You must buy it now</h2>
<p>Official Tor story regarding security of current versions of Tor and good reasons to upgrade is this:</p>
<blockquote><p><strong> Tor 0.1.2.16 fixes a critical security vulnerability that allows a<br />
remote attacker in certain situations to rewrite the user&#8217;s torrc<br />
configuration file. This can completely compromise anonymity of users<br />
in most configurations, including those running the Vidalia bundles,<br />
TorK, etc. Or worse.</strong></p>
<p>Users who do not have ControlPort enabled are secure; if you are not<br />
sure, you should upgrade and you should probably overwrite your torrc<br />
file with the default when you upgrade. More details will be posted over<br />
the next few days.</p>
<p><a href="https://tor.eff.org/download.html">https://tor.eff.org/download.html</a></p>
<p>We have Vidalia bundles for OS X Tiger on the website now. The recommended<br />
workaround for Windows users is either to wait until we have a Vidalia<br />
bundle ready, or do separate installs of the Win32 &#8220;expert&#8221; package from<br />
&nbsp;<a href="https://tor.eff.org/download-windows" title="https://tor.eff.org/download-windows" target="_blank">https://tor.eff.org/download-windows</a><br />
and the Windows Vidalia-only package from<br />
&nbsp;<a href="http://vidalia-project.net/download.php" title="http://vidalia-project.net/download.php" target="_blank">http://vidalia-project.net/download.php</a></p>
<p>Changes in version 0.1.2.16 - 2007-08-01<br />
o Major security fixes:<br />
- Close immediately after missing authentication on control port;<br />
do not allow multiple authentication attempts.</p></blockquote>
<h2>Immediate danger indicated</h2>
<p>Unofficial developer on IRC story regarding the new version is this:</p>
<blockquote><p>02:06 &lt; xiando&gt; I read the annoucement. It says immediate danger for all tor users. very bad. news at 11.<br />
02:07 &lt; nickm&gt; yup. all users who don&#8217;t upgrade.  quite bad.  upgrade upgrade upgrade.</p></blockquote>
<p>You upgrade your Tor immediately by downloading from <a href="https://tor.eff.org/download.html">https://tor.eff.org/download.html</a> (or svn update)</p>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/08/02/tor-users-must-immediately-upgrade-to-v01216/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tor needs bridge support testers</title>
		<link>http://anonymous.livelyblog.com/2007/08/01/tor-needs-bridge-support-testers/</link>
		<comments>http://anonymous.livelyblog.com/2007/08/01/tor-needs-bridge-support-testers/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 19:00:10 +0000</pubDate>
		<dc:creator>anonymous</dc:creator>
		
		<category><![CDATA[Surveillance]]></category>

		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://anonymous.livelyblog.com/2007/08/01/tor-needs-bridge-support-testers/</guid>
		<description><![CDATA[Tor v0.2.0.3-alpha has a new killer feature against blocking which may prove to be extremely cool. It allows you to run as a bridge which can be used by other people who want to connect to the Tor-network.
Those who configure their Tor-clients as Bridges pass traffic between end-users and the Tor-network.
People who can&#8217;t get to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://anonymous.livelyblog.com/2007/07/30/tor-v0203-alpha/" rel="bookmark" title="Permanent Link to Tor v0.2.0.3-alpha">Tor v0.2.0.3-alpha</a> has a new killer feature against <em>blocking</em> which may prove to be extremely cool. It allows you to <em>run as a bridge</em> which can be used by other people who want to connect to the Tor-network.</p>
<p>Those who configure their Tor-clients as Bridges pass traffic between end-users and the Tor-network.</p>
<p>People who can&#8217;t get to the Tor-network because <em>the main Tor-network is blocked</em> can connect to <em>a bridge</em> (which hopefully <em>isn&#8217;t blocked</em>) and use that to get to a uncencored version of the Internet.</p>
<h2>Tor is the adversary</h2>
<p>Bridges makes it <em>so much harder</em> to block people from the Tor-network. If your corporation, school, government or anyone else says that</p>
<blockquote><p>&#8220;Tor is bad and privacy is bad and anonymity is bad and <em>we need to turn it all off</em> and <em>we do not want you or your familiy to have access to this technology&#8221;</em></p></blockquote>
<p>and they <em>block you</em> from connecting to all known Tor-servers then <em>all you have to do is to find someone who is running a bridge</em> and use that to get to the Tor-network. The <em>adversary</em> can just download a complete list of all Tor-servers <em>and block them</em>. It is that much harder for <em>the adversary</em> to figure out that some computer on some ADSL somewhere <em>is a bridge</em> when there is no huge list which includes it.</p>
<h1>Official &#8220;please test this&#8221; story</h1>
<p>The official Roger Dingledine story regarding this is:</p>
<blockquote><p>Hi folks,</p>
<p>The upcoming 0.2.0.3-alpha release has a couple new features from the<br />
blocking-resistance design we&#8217;re working on. I&#8217;m going to write down more<br />
details about how it works soon, but I wanted to give people a chance<br />
to play with it (and report problems) now that it&#8217;ll be out in a release.</p>
<p>For background on the design, see<br />
&nbsp;<a href="https://tor.eff.org/svn/trunk/doc/design-paper/blocking.html" title="https://tor.eff.org/svn/trunk/doc/design-paper/blocking.html" target="_blank">https://tor.eff.org/svn/trunk/doc/design&#8230;</a></p>
<p>In short, the new Tor release lets you run a relay that isn&#8217;t in the<br />
main directories (known as a bridge), and you can configure your client<br />
by giving it a set of bridge addresses to use as your first hop into<br />
the Tor network and as your source of directory information. There&#8217;s no<br />
support in Vidalia for it yet, and the design is still in flux, but here<br />
are some tips to get you started.</p>
<p>(Warning: these instructions are geared for people who are comfortable<br />
editing their torrc and messing around with Tor. If it breaks and<br />
you think it&#8217;s a bug, please let me know; if you just fail to get it<br />
working, wait for a few more releases and it&#8217;ll be easier. Also, note<br />
that these features alone do not provide very good blocking-resistance;<br />
more features are on the way still.)</p>
<p>Thanks!<br />
&#8211;Roger</p>
<p>********* Part one: using a bridge when you&#8217;re a client *****</p>
<p>Add these lines to your torrc file:</p>
<p>UseBridges 1<br />
TunnelDirConns 1<br />
Bridge 128.31.0.34:9009 4C17 FB53 2E20 B2A8 AC19 9441 ECD2 B017 7B39 E4B1</p>
<p>You can specify as many Bridge lines as you like, one for each bridge<br />
you&#8217;d like to use. You can leave out the key if you don&#8217;t know it or<br />
don&#8217;t care:</p>
<p>Bridge 128.31.0.34:9009</p>
<p>******** Part two: setting up your own bridge ***********</p>
<p>Configure yourself as if you were a normal Tor server. Make sure to<br />
define a DirPort. Then add this line to your torrc file:</p>
<p>PublishServerDescriptor 0</p>
<p>This makes you into a Tor server that doesn&#8217;t advertise on the main<br />
directory authorities. You should tell people your IP address and ORPort<br />
(and optionally your identity fingerprint) and they can write their own<br />
Bridge lines as in &#8220;Part one&#8221; above.</p>
<p>Optionally, you may want to set</p>
<p>RelayBandwidthRate 50 KB<br />
RelayBandwidthBurst 50 KB</p>
<p>instead of the more traditional BandwidthRate and BandwidthBurst options,<br />
so you can use your bridge as a Tor client too and not get hit by your<br />
own rate limiting.</p>
<p>********Part three: a bridge directory authority *********</p>
<p>For the adventurous, I&#8217;m also running a temporary bridge directory<br />
authority. If you want your bridge to publish to this bridge authority,<br />
use these lines in your torrc:</p>
<p>PublishServerDescriptor bridge<br />
dirserver moria1 v1 orport=9001 128.31.0.34:9031 FFCB 46DB 1339 DA84 674C 70D7 CB58 6434 C437 0441<br />
dirserver moria2 v1 orport=9002 128.31.0.34:9032 719B E45D E224 B607 C537 07D0 E214 3E2D 423E 74CF<br />
dirserver tor26 v1 orport=443 86.59.21.38:80 847B 1F85 0344 D787 6491 A548 92F9 0493 4E4E B85D<br />
dirserver lefkada orport=443 140.247.60.64:80 38D4 F5FC F7B1 0232 28B8 95EA 56ED E7D5 CCDC AF32<br />
dirserver dizum 194.109.206.212:80 7EA6 EAD6 FD83 083C 538F 4403 8BBF A077 587D D755<br />
dirserver moria5 orport=9005 bridge no-v2 128.31.0.34:9035 F812 FCC1 E3EB E2E8 1C09 E516 E51A F9BF AFE3 3974</p>
<p>The first line specifies to publish to all authorities of type &#8216;bridge&#8217;,<br />
and the last line specifies a new dirserver of type bridge. The others<br />
are just repeating the current dirservers so we don&#8217;t lose them when we<br />
define a new one. I promise I&#8217;ll have a better interface for this soon. <img src='http://anonymous.livelyblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Then clients that use your bridge can add</p>
<p>UpdateBridgesFromAuthority 1</p>
<p>to their torrc, and now even if your IP:port change (for example you&#8217;re<br />
on a dynamic IP address), they&#8217;ll still be able to find you again.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://anonymous.livelyblog.com/2007/08/01/tor-needs-bridge-support-testers/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
