Re: [tor-dev] Some initial analysis on the new "Triple Handshake Attack" and Tor

2014-03-04 Thread Watson Ladd
On Tue, Mar 4, 2014 at 7:05 AM, Nick Mathewson wrote: > On Mon, Mar 3, 2014 at 10:37 PM, Watson Ladd wrote: > >> How about 6: Tor server to server connections should use >> ECDHE+ChaCha20 or GCM_AES ciphersuites only? >> This closes the UKS hole that enabled this attack to happen, and >> probably

Re: [tor-dev] globe compass integration

2014-03-04 Thread Sathyanarayanan Gunasekaran
Hey Christian, On Tue, Mar 4, 2014 at 2:28 PM, Christian wrote: > Hi, > in the last couple of days I thought about a topic for a gsoc application. > > After getting ideas from Karsten and Sathya, I started making a rough > roadmap of things that I want to do for globe, in the next couple of > mon

Re: [tor-dev] Proposal 220 (revised): Migrate server identity keys to Ed25519

2014-03-04 Thread George Kadianakis
Nick Mathewson writes: > I've revised proposal 220 based on commentary from Roger. The biggest > changes is tweaking all of the things called "certificates" to make > them actually follow the same format to greatest the extent possible. > > To see diffs, you can use git, or browse the gitweb sit

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread David Goulet
On 04 Mar (10:46:06), David Goulet wrote: > On 04 Mar (10:30:40), Nick Mathewson wrote: > > On Tue, Mar 4, 2014 at 10:13 AM, David Goulet wrote: > > > On 04 Mar (08:36:13), Nick Mathewson wrote: > > >> On Mar 4, 2014 4:26 AM, "Lunar" wrote: > > >> > > > >> > David Goulet: > > >> > > After a big c

[tor-dev] globe compass integration

2014-03-04 Thread Christian
Hi, in the last couple of days I thought about a topic for a gsoc application. After getting ideas from Karsten and Sathya, I started making a rough roadmap of things that I want to do for globe, in the next couple of months (and maybe use it as a idea for a gsoc topic). - add new onionoo feature

Re: [tor-dev] Interested in GSoC - Hidden Service Naming or Hidden Service Searching

2014-03-04 Thread George Kadianakis
Jeremy Rand writes: > Hi George, thanks for the reply. > > On 03/02/2014 06:27 AM, George Kadianakis wrote: >> I'd like to see human-readable names in HSes, but I'm not very >> familiar with Namecoin. I don't want to discourage you from working on >> this, but I'm not sure if I would be a good me

[tor-dev] (no subject)

2014-03-04 Thread Samual Carman
-- hello i have some questioner regarding helping the development of tor contact me off list if possible thank yuo the wyer ___ tor-dev mailing list tor-dev@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev

Re: [tor-dev] Coordination of censorship analysis tool

2014-03-04 Thread John Mood
Hi Piotr, This page should help: https://www.torproject.org/getinvolved/volunteer#project-tor On 04/03/14 15:17, sarni...@student.agh.edu.pl wrote: Hi everyone, could you provide some information about your progress on the project? I am interested in developing the tool, but I don't want to

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread David Goulet
On 04 Mar (10:30:40), Nick Mathewson wrote: > On Tue, Mar 4, 2014 at 10:13 AM, David Goulet wrote: > > On 04 Mar (08:36:13), Nick Mathewson wrote: > >> On Mar 4, 2014 4:26 AM, "Lunar" wrote: > >> > > >> > David Goulet: > >> > > After a big code review from Nick and help from a lot of people > >>

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread Nick Mathewson
On Tue, Mar 4, 2014 at 10:13 AM, David Goulet wrote: > On 04 Mar (08:36:13), Nick Mathewson wrote: >> On Mar 4, 2014 4:26 AM, "Lunar" wrote: >> > >> > David Goulet: >> > > After a big code review from Nick and help from a lot of people >> > > contributing and testing, this is the release candidat

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread David Goulet
On 04 Mar (08:36:13), Nick Mathewson wrote: > On Mar 4, 2014 4:26 AM, "Lunar" wrote: > > > > David Goulet: > > > After a big code review from Nick and help from a lot of people > > > contributing and testing, this is the release candidate 4 for the new > > > torsocks. > > > > I was about to push t

[tor-dev] Coordination of censorship analysis tool

2014-03-04 Thread sarnicki
Hi everyone, could you provide some information about your progress on the project? I am interested in developing the tool, but I don't want to duplicate your work. Thanks, Piotr ___ tor-dev mailing list tor-dev@lists.torproject.org https://lists.to

Re: [tor-dev] Some initial analysis on the new "Triple Handshake Attack" and Tor

2014-03-04 Thread Nick Mathewson
On Mon, Mar 3, 2014 at 10:37 PM, Watson Ladd wrote: > How about 6: Tor server to server connections should use > ECDHE+ChaCha20 or GCM_AES ciphersuites only? > This closes the UKS hole that enabled this attack to happen, and > probably is a good idea anyway. To make sure I understand, it's the

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread Nick Mathewson
On Mar 4, 2014 4:26 AM, "Lunar" wrote: > > David Goulet: > > After a big code review from Nick and help from a lot of people > > contributing and testing, this is the release candidate 4 for the new > > torsocks. > > I was about to push the new version to Debian experimental, but it just > breaks

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread Jacob Appelbaum
I think that torsocks shouldn't break your use of ssh - it closely matches many other uses of ssh or similar programs. All the best, Jacob On 3/4/14, Lunar wrote: > David Goulet: >> After a big code review from Nick and help from a lot of people >> contributing and testing, this is the release c

Re: [tor-dev] [RELEASE] Torsocks 2.0.0-rc4

2014-03-04 Thread Lunar
David Goulet: > After a big code review from Nick and help from a lot of people > contributing and testing, this is the release candidate 4 for the new > torsocks. I was about to push the new version to Debian experimental, but it just breaks my SSH configuration too badly. The new version forbid