Re: [tor-dev] Help me guague how full your plate is via regular check-in conversations

2013-11-20 Thread Phill Whiteside
Hi Tom, being the admin for groups is a thankless task! I've mentioned a couple of times that the tor project does have availability of a spare VM with unique IPv4 for testing on. This offer has never been taken up. I'm a tester, not a coder, as I already run a relay I'm not sure what else I can d

Re: [tor-dev] [resent] [tor-assistants] Help me guague how full your plate is via regular check-in conversations

2013-11-20 Thread isis agora lovecruft
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Resending because I just realised that tor-assistants@ bounced my mail last time. Tom Lowenthal transcribed 1.3K bytes: > Hello fighters for freedom, > > When applying for grants, planning future work, and otherwise thinking > about what capacity

Re: [tor-dev] Apple App Store Redux

2013-11-20 Thread Adam Shostack
On Mon, Nov 18, 2013 at 02:07:26PM -0500, Nathan Freitas wrote: | >>> Getting TBB into the App Store would definitely help increase | >>> its visibility on the OSX side. However, I am not really in | >>> favour of giving a US company a list of all users having | >>> downloaded TBB plus information

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Nick Mathewson
On Wed, Nov 20, 2013 at 11:02 AM, Nick Mathewson wrote: > Hi, all! > > Here's Incidentally, the canonical location for proposals is the torspec repository. Since this email went out, I've applied some fixes to the proposal to fix up some mistakes in it, and more mistakes I made. The latest versi

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Paul Syverson
Thanks Esfandiar. I had to run off for an hour and inadevertently sent my message before I had finished composing it, leaving a munged impression. My intended point was that the whole story has quite a bit to it beyond simply tweaking MQV. As you noted, that story has even more to it than what I s

Re: [tor-dev] Apple App Store Redux

2013-11-20 Thread Griffin Boyce
Sorry for taking so long to respond to this thread. Responses are (mostly) inline below. At a training event a couple of days ago, a user was sketched out by the warning her Mac gave her -- in spite of the advance notice she'd been given by the trainers. Erinn Clark wrote: > Please see Ralf's

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Esfandiar Mohammadi
Am 20.11.2013 um 18:19 schrieb Paul Syverson : > These authors found a > vulnerability in that protocol, improved on it, and proved their > protocol secure. Actually, Ian Goldberg, Douglas Stebila, and Berkant Ustaoglu found the vulnerability in Lasse and Paul's protocol [1], improved it, and pr

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Paul Syverson
On Wed, Nov 20, 2013 at 08:36:30AM -0800, Watson Ladd wrote: > Is it just me, or is this protocol MQV with the client generating a > fake long term key? Well yeah sort of, but the "details" are crucial. In "Improving efficiency and simplicity of Tor circuit establishment and hidden services" (avai

Re: [tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Watson Ladd
Is it just me, or is this protocol MQV with the client generating a fake long term key? Sincerely, Watson Ladd ___ tor-dev mailing list tor-dev@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev

[tor-dev] Proposal 223: Ace: Improved circuit-creation key exchange

2013-11-20 Thread Nick Mathewson
Hi, all! Here's Esfandiar Mohammadi's proposal for the Ace handshake. It should have been added as a numbered proposal back in July; I think I lost track of everything while the dev meeting was happening. Please let me know if you have more proposals that should be assigned numbers but haven't go