log☇︎
900+ entries in 0.691s
thestringpuller: I've always wondered when the first cash only exchange will pop on Tor.
ascii_field: 'In a terse statement Wednesday, Carnegie Mellon wrote that its Software Engineering Institute hadn’t received any direct payment for its Tor research from the FBI or any other government funder. But it instead implied that the research may have been accessed by law enforcement through the use of a subpoena. “In the course of its work, the university from time to time is served with subpoenas requesting informat
ascii_field: http://www.wired.com/2015/11/carnegie-mellon-denies-fbi-paid-for-tor-breaking-research
asciilifeform: ^ this is sop and it is how they typically bust 1,001 'tor onion' boxes after popping ~one~
assbot: Logged on 17-11-2015 22:38:39; ascii_field: (is a specially crafter derplinux pre-impregnated with tor, faux pgp, etc)
ascii_field: (is a specially crafter derplinux pre-impregnated with tor, faux pgp, etc) ☟︎
mircea_popescu: "PGP is not as important as people think. As long as both parties use an encrypted email (and connect with a VPN, TOR, TAILS, whatever) you're fine. This is because if they get access to the webmail all information is decrypted either using automatic PGP decryption (eg: Countermail) or locally on their computer (somewhere this information is going to be stored)."
assbot: Logged on 16-11-2015 23:53:33; BingoBoingo: And Tor is unsafer than ever http://www.csoonline.com/article/3004648/security-awareness/after-paris-isis-moves-propaganda-machine-to-darknet.html
BingoBoingo: No, spin up more tor nodes for ISIS
BingoBoingo: And Tor is unsafer than ever http://www.csoonline.com/article/3004648/security-awareness/after-paris-isis-moves-propaganda-machine-to-darknet.html ☟︎
testingthisstuff: adlai, mircea_popescu: thank you. i don't mind being my real self. i want to get into the WoT and start participating, looking for the best ways. always thought tor was a good idea but it seems not. I'll start reading at least 6 months of logs, as per the instructions, to catch up
adlai: there's a difference between "we don't support tor becgause they suck at <reasons>" and "we don't support tor because 'reasons'"
adlai: testingthisstuff: also fyi, even the tor developers admit to the ease (~$1M) with which a large-scale sybil attack can be mounted against the network
adlai: testingthisstuff: tor doesn't work on freenode, they actively prevent it
kakobrekla: tor isnt something you want to be using.
testingthisstuff: mircea_popescu, thanks, I'm lurking and, at the same time, trying to find out how to connect to freenode with Tor.
ascii_field: 'C&C servers are located on the Tor network; the malware communicates with the C&Cs via public tor2web services.'
ascii_field: unaffected whilst logged in, but still using tor). It was also not a case of tor vs non-tor (US tor exits
asciilifeform: 'Cybersecurity con artists are as bad by deluding their visitors and customers about how to protect themselves with encryption, Tor, anonymization, OTR, secret chats, deep web, blah, blah. All these con artists gin their own logs of trusting-users data, then either hand it over to authorities, sell it covertly, share with cohorts and standards orgs, write papers and give speeches soliciting customers, testify in Congress and c
gribble: 8 Ways To Do Ghostbusters 3 Correctly - Tor.com: <http://www.tor.com/2013/03/01/8-ways-to-do-ghostbusters-3-correctly/>; Shawn Mendes Selfie Magcon Boys Pillow Case - Wanelo: <https://wanelo.com/p/33812687/shawn-mendes-selfie-magcon-boys-pillow-case>; Win tickets to FreakNight 2015 | Consequence of Sound: <http://consequenceofsound.net/2015/09/win-tickets-to-freaknight-2015/>
gribble: 8 Ways To Do Ghostbusters 3 Correctly - Tor.com: <http://www.tor.com/2013/03/01/8-ways-to-do-ghostbusters-3-correctly/>; Trading Faces - Ghostbusters Wiki - Wikia: <http://ghostbusters.wikia.com/wiki/Trading_Faces>; Stash Bag Pillow Case - ThisIsWhyImBroke.com: <http://www.thisiswhyimbroke.com/stash-bag-pillow-case>
mircea_popescu: "Sure, go ahead and "challenge gatekeepers" with your TOR blacklists and awesome ~0% of network mining power.
mircea_popescu: and this is not (one of the) tor deanonymization tricks.
ascii_field: ‘releasing node’. S generates a pair of public keys to encrypt the return data then inserts the public key into the routing information for each node...' << tor, snore.
assbot: Logged on 22-09-2015 15:52:38; shinohai: http://www.dailydot.com/politics/bitcoin-anonymity-trr-encryption-tor/ <<< asciilifeform will LOVE this one.
assbot: The future of Bitcoin could be as anonymous and private as Tor ... ( http://bit.ly/1OOmAWp )
shinohai: http://www.dailydot.com/politics/bitcoin-anonymity-trr-encryption-tor/ <<< asciilifeform will LOVE this one. ☟︎
assbot: First Library to Support Tor Anonymous Internet Browsing Effort Stops After DHS Email - ProPublica ... ( http://bit.ly/1ULaooS )
ascii_field: 'Reproducible builds are already a staple of Bitcoin and the Tor Project.' << ahahahahahahaha
deedbot-: [Qntra] Agora Marketplace Suspends Operations Citing Potential Tor Attack - http://qntra.net/2015/08/agora-marketplace-suspends-operations-citing-potential-tor-attack/
mircea_popescu: in the ever-amusing tor saga, http://pastebin.ca/3129249
asciilifeform: 'Just so you know this stuff about Tor has me worried... Please don't make this public, but my day job involves intelligence, and I'm in a relatively high position. You know, I went into the job years ago with very different thoughts about it than I do now. The last, well, decade really has changed a lot of minds in this field, in totally different ways. Myself I am on the side of Snowden and Assange, but... lets just say when
asciilifeform: 'The third part was triggering bans on proxies VPNs and tor exit nodes, making as many file requests as possible so that users will not be able to use them to safely access websites. It involved using or circumventing the .htaccess file I am not sure which. "The goal is to divert bandwidth strangle traffic and get them to block their own users."'
ascii_field: (two separate departments of muppetronics. as in tor.)
asciilifeform: https://github.com/bitcoinxt/bitcoinxt/commit/73c9efe74c5cc8faea9c2b2c785a2f5b68aa4c23#diff-20ca0fc983bf911ac1076a201d6cd491R4 << ban list, supposedly of 'tor' users, but dynamically updated at all times.
mircea_popescu: "Connections are made over clearnet even when using a proxy or onlynet=tor, which leaks connections on the P2P network with the real location of the node. Knowledge of this traffic along with uptime metrics from bitnodes.io can allow observers to easily correlate the location and identity of persons running Shitcoin-XT nodes."
assbot: [bitcoin-dev] Bitcoin XTs Tor IP blacklist downloading system has significant privacy leaks. ... ( http://bit.ly/1J3dCOY )
mircea_popescu: "Peer priorities are based on matching the connecting IP against a set of IP groups. For now, the only IP group is one that gives Tor exits a score of -10."
assbot: Crypto activists announce vision for Tor exit relay in every library | Ars Technica ... ( http://bit.ly/1Dguuow )
shinohai: http://arstechnica.com/tech-policy/2015/07/crypto-activists-announce-vision-for-tor-exit-relay-in-every-library/ <<< yeah, let's encourage people to use a tor node located in a place that are generally funded by guv'ments.
assbot: Logged on 31-07-2015 03:53:10; asciilifeform: coderwill: on top of the thousand and one other sins, tor linked in ssl at the height of 'heartbleed' - something which pretty much nobody is speaking of today
mats: coderwill: it is an open secret that Tor is broken
decimation: it looks to me that they are whining about tor because it makes their job harder
decimation: wtf how is that proof of anything re: tor?
asciilifeform: coderwill: on top of the thousand and one other sins, tor linked in ssl at the height of 'heartbleed' - something which pretty much nobody is speaking of today ☟︎
asciilifeform: plus his tor article (don't have the link handy atm)
assbot: Logged on 04-10-2013 15:21:32; mircea_popescu: i'm with asciilifeform's suggestion : that pps is prima facie evidence that the nsa is in fact currently decoding ALL traffic passing through all tor nodes, linking it to originating ips and storing this mess.
lobbesbot: New post: http://nosuchlabs.com/rss Phuctored RSA Modulus, GCD=3 (randomnoize (Tor relay operator) ; randomnoize (Tor relay operator) ; ) <http://nosuchlabs.com/gpgkey/9319605DD9BFB5972272003BC0D6D2E999783C7256A75BF1BE08178A359F9542#105DED03AF97CA6EDB6C41B47B7947A3B987A055C2756723E9C5671609CADB38>
lobbesbot: New post: http://nosuchlabs.com/rss Phuctored RSA Modulus, GCD=3 (randomnoize (Tor relay operator) ; randomnoize (Tor relay operator) ; ) <http://nosuchlabs.com/gpgkey/9319605DD9BFB5972272003BC0D6D2E999783C7256A75BF1BE08178A359F9542#105DED03AF97CA6EDB6C41B47B7947A3B987A055C2756723E9C5671609CADB38>
assbot: Feds bust through huge Tor-hidden child porn site using questionable malware | Ars Technica ... ( http://bit.ly/1JxNYBF )
asciilifeform: http://arstechnica.com/tech-policy/2015/07/feds-bust-through-huge-tor-hidden-child-porn-site-using-questionable-malware << possibly interesting, from same fishwrap
decimation: I think ascii is proposing something like tor except everyone knows everyone else, and routes accordingly
asciilifeform: and since we aren't a usg wankatron like tor, there is no reason for all of the 'gates' to be publicly advertised
jurov: how does the gate look? like tor enter node?
asciilifeform: (there is a kind of 'valley' in between the ordinary weaponry and the 'glass' - e.g., tor diddles which would 'expire' immediately if publicly revealed, but are good for plenty of 'parallel construction' meanwhile, etc.)
ascii_field: https://lists.torproject.org/pipermail/tor-talk/2015-April/037549.html << lulzy
ascii_field: same crud as 'tor'
asciilifeform: just like tor dies if the directory servers are ever unplugged.
asciilifeform: decimation: looks like a cheap clone of tor-onion
assbot: Logged on 24-06-2015 02:49:18; asciilifeform: https://chloe.re/2015/06/20/a-month-with-badonions << lulzy. but for some reason author did not consider the possibility that isps snort downstream from known tor exits
punkman: didn't those guys fund Tor as well?
decimation: in retrospect, using 'tor' was a giveaway
asciilifeform: https://chloe.re/2015/06/20/a-month-with-badonions << lulzy. but for some reason author did not consider the possibility that isps snort downstream from known tor exits ☟︎
shinohai: @ asciilifeform therefore I post for newcomers to understand why tor is smacktarded.
assbot: Logged on 20-06-2015 20:31:36; shinohai: Interesting read: https://securelist.com/analysis/publications/70673/uncovering-tor-users-where-anonymity-ends-in-the-darknet/
assbot: Uncovering Tor users: where anonymity ends in the Darknet - Securelist ... ( http://bit.ly/1Gz2OsY )
shinohai: Interesting read: https://securelist.com/analysis/publications/70673/uncovering-tor-users-where-anonymity-ends-in-the-darknet/ ☟︎
asciilifeform associates tor mainly with spammers
shinohai: tor. sitting around on internet forums doing buying drugs with btc and hating on the government.
asciilifeform: rather than tor per se
asciilifeform: tor is this thing where tcp is bounced via three machines, selected by shitgnomiferous mega-turd of a client, over ssl (ditto)
asciilifeform: and wai wat, wtf, how does one 'lurk around tor'
assbot: Logged on 06-06-2015 16:05:26; shinohai: I hav lurked around tor but their is little excitement there for me. Mostly space cadets and libertarians of the worst kind.
asciilifeform: i don't give a fuck how many gold rings tor users are wearing.
shinohai: I hav lurked around tor but their is little excitement there for me. Mostly space cadets and libertarians of the worst kind. ☟︎
mircea_popescu: for instance, im not on tor, have occasionally derped on imageboards. same of you i would guess.
asciilifeform: mircea_popescu: entirely different animals. there are folks using tor exits who -really- ought to know better.
mircea_popescu: just sayin, people imagining pointing out to idiot tor users how insecure that shit is would persuade anyone ? shit, hola got 8 million users with 8 million exploitable holes in it.
asciilifeform: say, it watches for the 'captcha' that google virtually always throws at tor users
shinohai: tor is kinda flawed in that respect.
asciilifeform: shinohai: since you did link it... here's a mega-question for 'tor' enthusiasts. what's to stop a 'malicious' (diddles traffic) node from routing its circuits -back into tor-, and having some other exit end up looking like the guilty party ?
shinohai: https://github.com/bitcoin/bitcoin/blob/v0.11.0rc1/doc/release-notes.md#privacy-stream-isolation-for-tor
mircea_popescu: http://log.bitcoin-assets.com/?date=26-05-2015#1145941 << from the crypts of the lost : "Can you run Monero miner through TOR? If yes, what change would need to made to the bat file on the opening page? I'm using Windows. thanks" ☝︎
copypaste: true. well, 8chan lets you post over Tor.
copypaste: yes, basically Tor but a much larger network
mircea_popescu: copypaste o wow, leveraged tor ?
jurov: by the way, mircea_popescu: is BISP okay with tor exit nodes?
jurov: tor cloud, independent fabs, whatever
decimation: what, the tor cloud?
decimation: in the tor cloud case, one cannot simply 'run an ec2 host' for nearly free like one can crib another's c code
assbot: Anonymous Tor Cloud project closes down ... ( http://bit.ly/1E0TsBy )
jurov: heh, just got this tab open: http://betanews.com/2015/05/09/anonymous-tor-cloud-project-closes-down/
mircea_popescu: Palfrader is iirc the tor derp
williamdunne: Before I think it was data allowance, price, location and if they allow tor or not
assbot: Logged on 18-04-2015 04:56:33; Citizenfive: I'd bet on Bitcoin's security (code-wise) over Tor or anything else, just because of that
Citizenfive: But not Tor, maybe. Perhaps something new. But Tor-like.
Citizenfive: Hence, maybe — holyfuckwhatanidea — financially incentivize Tor scrutinization at the protocol level? O.O
Citizenfive: I'd bet on Bitcoin's security (code-wise) over Tor or anything else, just because of that ☟︎
Citizenfive: Well those are among the most widely used and studied things in all of cryptoland. Vs. everything else, i.e. some arbitrary piece of FOSS something. Stuff like Tor is what gives everyone a false sense that everyone is all over everything in FOSSland
ben_vulpes: tor: Quality: C code. One implementation, but well funded dev and lots of scrutiny. Good. << such kek