Re: [tor-talk] Tor's critique of Ultrasurf: A reply from the Ultrasurf developers

2012-04-18 Thread Jacob Appelbaum
On 04/18/2012 02:07 PM, Kyle Williams wrote: > So I guess nobody remembers or knows about my brief 15 minutes at Blackhat > a few years back where I warned about much more than what is being > disclosed here in regards to Ultrasurf or GIFC. > > Here's the Audit I did from years ago. > http://www.j

Re: [tor-talk] wget - secure?

2012-04-18 Thread Ondrej Mikle
On 04/18/2012 11:40 PM, torsi...@tormail.net wrote: >> On Wed, Apr 18, 2012 at 4:56 AM, Maxim Kammerer wrote: >>> On Wed, Apr 18, 2012 at 11:37, Robert Ransom >>> wrote: Which version of wget did you audit? What information leaks did you check for during your audit? > Hi, > > How can

Re: [tor-talk] wget - secure?

2012-04-18 Thread torsiris
> On Wed, Apr 18, 2012 at 4:56 AM, Maxim Kammerer wrote: >> On Wed, Apr 18, 2012 at 11:37, Robert Ransom >> wrote: >>> Which version of wget did you audit?  What information leaks did you >>> check for during your audit? Hi, How can I check what information wget is transmitting? I used wireshark

Re: [tor-talk] Tor's critique of Ultrasurf: A reply from the Ultrasurf developers

2012-04-18 Thread Kyle Williams
So I guess nobody remembers or knows about my brief 15 minutes at Blackhat a few years back where I warned about much more than what is being disclosed here in regards to Ultrasurf or GIFC. Here's the Audit I did from years ago. http://www.janusvm.com/Ultrasurf_audit.zip Includes Video's of the a

Re: [tor-talk] wget - secure?

2012-04-18 Thread Joseph Lorenzo Hall
On Wed, Apr 18, 2012 at 4:56 AM, Maxim Kammerer wrote: > On Wed, Apr 18, 2012 at 11:37, Robert Ransom wrote: >> Which version of wget did you audit?  What information leaks did you >> check for during your audit? > > I should have known I would get useless replies with zero informative > content

Re: [tor-talk] wget - secure?

2012-04-18 Thread proper
If you want to to do thoroughly like Robert Ransom, it all comes back to this ticket. https://trac.torproject.org/projects/tor/ticket/5553 __ powered by Secure-Mail.biz - anonymous and secure e-mail accounts. ___

Re: [tor-talk] wget - secure?

2012-04-18 Thread unknown
In theory smart adversary can reduce anonimity set with statisticaly profiling any non-TBB downloaders on the service side or through intercepting exit node traffic. Wget'll get a different responce than standart TBB or another downloaders to cookies and active elements injection, fonts manipula

Re: [tor-talk] Tor's critique of Ultrasurf: A reply from the Ultrasurf developers

2012-04-18 Thread Gregory Maxwell
On Wed, Apr 18, 2012 at 5:54 AM, Tichodroma wrote: > Hi, > might be of interest: > http://ultrasurf.us/Ultrasurf-response-to-Tor-definitive-review.html This is of more interest then their 'response' itself: http://b.averysmallbird.com/entries/the-need-for-community-participation-and-clear-disclos

[tor-talk] Tor's critique of Ultrasurf: A reply from the Ultrasurf developers

2012-04-18 Thread Tichodroma
Hi, might be of interest: http://ultrasurf.us/Ultrasurf-response-to-Tor-definitive-review.html Tichodroma -- XMPP: tichodr...@jabber.ccc.de IRC: Tichodroma ___ tor-talk mailing list tor-talk@lists.torproject.org https://lists.torproject.org/cgi-bin/m

[tor-talk] Updated Tor Cloud images, and action required

2012-04-18 Thread Runa A. Sandvik
Hi everyone, The Tor Cloud [1] images for all the seven regions have been updated to include the latest cloud image for stable Ubuntu release 10.04 LTS (Lucid Lynx). These new images are available on the Tor Cloud website. If you are already running a Tor Cloud bridge, you will need to either man

Re: [tor-talk] wget - secure?

2012-04-18 Thread Maxim Kammerer
On Wed, Apr 18, 2012 at 11:37, Robert Ransom wrote: > Which version of wget did you audit?  What information leaks did you > check for during your audit? I should have known I would get useless replies with zero informative content to that summary. Wget does not resolve hostnames when it uses a p

Re: [tor-talk] wget - secure?

2012-04-18 Thread Robert Ransom
On 2012-04-18, Maxim Kammerer wrote: > TL;DR: wget is 100% safe to use with Tor and it does not leak DNS > (also true for curl, by the way). Which version of wget did you audit? What information leaks did you check for during your audit? Which SSL library did you configure wget to use? Which

Re: [tor-talk] Unable to launch amazon TOR cloud instances

2012-04-18 Thread Runa A. Sandvik
On Wed, Apr 18, 2012 at 3:05 AM, wrote: > Hello, Hi, > While I was managing my Amazon account I was doing some routine > terminations of bridges in preparation to launch fresh instances from the > https://cloud.torproject.org/ website. Now for some reason whenever on > click on any of the publi

Re: [tor-talk] wget - secure?

2012-04-18 Thread coderman
On Tue, Apr 17, 2012 at 10:52 PM, Maxim Kammerer wrote: > ... > My tests show that wget does not leak DNS requests when HTTP(S) > proxies are specified via environment variables. if: 1. using environment variables correctly 2. using command line parameters correctly set http_proxy but not HTTPS_