Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - astor

Pages: 1 ... 9 10 [11] 12 13 ... 208
151
Security / Re: Disabling images as a reasonable security precaution
« on: September 05, 2013, 10:37 am »
Browsing in incognito mode is the way to go. Besides what you mentioned, it speeds up page load times, sometimes quite noticeably, and the photos rarely match the product anyway. Even if they were real photos of a real product at one time, many are months old and no longer illustrate the product being sold, and many are stock images to begin with.

152
So that'd be better than just taking snapshots?   Because I'd be able to easily transfer them anywhere?  Or is there another reason?

You can do that too, but I always do it immediately after a fresh install so I have a known clean copy. At some point you may realize your VM is screwed up and you may not be able to determine when that happened.

153
Security / Re: Dissent: accountable anonymous group communication
« on: September 05, 2013, 05:02 am »
Right now a few people are working on coding a system like this with me. I think we should go public with the code that is already done and show it to people here, and invite people like Astor, SS, ECC_ROT13 etc to participate and audit what is done. We still have unanswered questions, we still have parts to code. Would anybody be interested in seeing the code that is done so far and helping contribute to the project in an organized fashion? What we are working on is not illegal and is not being built for illegal communities, it is merely software for use by those who like the features. But I personally see nothing wrong with including people from this forum, although some others working on it may be hesitant for it to have any apparent connection to illegal activity (because why make something that is not illegal linked to criminals). Unfortunately I already kind of fucked that up by being involved with it and having the original idea for it :P.

Fuckin A, absolutely! Could we invite other people over time, like get a few invites per week, to see how the system scales?

Oh well, I guess we'll worry about that later.

BTW, is this the system that could evolve into a market with bitcoin/zerocoin integration?

154
Also, export your Lubuntu Workstation now as a VirtualBox appliance so you have a clean copy. If it gets fucked up in the future, you can delete it and reimport the appliance. It will take a lot less time than reinstalling Lubuntu.

155
Did some reading on the Whonix site, yet I'm still left with a few questions.  Forgive my ignorance...

So I Imported the Whonix gateway and have another VM Distro already in VirtualBox.  My thinking is:

Overview:                               VM Distro<-------------->Whonix Gate<---------------------->Host<-------------------->Router/Modem<--->Tor
Network settings:            Internal Adapter<------->[Internal <--->Nat]<---->VirtualBox Host only adapter<---->Router/Modem<--->Tor


Is my thinking here sound?  Your settings above... gateway/netmask/ip/dns... I'm assuming those are what the VM distro must have, correct?  Not the Internal Adapter or VB Host Only Adapter.

Right, I forgot to mention that when you create the Lubutu (or whatever) VM that will be the Workstation, change the networking to internal bridge and select Whonix, which should be a drop down option after you import the Gateway. Then when you boot Lubuntu or whatever live distro, go to the ethernet network settings and enter that info. Should work instantly.

You don't have to mess with anything on the Gateway.

Quote
To use, I just start the Whonix Gate VM, let it sit there, take no action, input nothing?  Just wait for it to connect to Tor?

Yes, start the Gateway and 20-30 seconds later, start the Workstation.

Quote
And if I understand this correctly, using the VM distro behind the Whonix Gate only protects me from malware I may possibly download, correct?  But I was always under the impression that the act of downloading itself would unmask my modem's external IP anyhow?... rendering all this moot.  No?

No, the applications or malware running inside the VM see a virtual machine with fake serial numbers for the virtual hardware.

That is why they recommend running the Workstation in a VM even if you use physical isolation, ie running the Gateway on a separate computer.

Quote
Watching my firewall I noticed VBoxNetFlt.sys connecting to some place in Romania 109.163.234.39 (even when VBox wasn't running) ... I got curious and blocked it.  When I do that, it blocks me from accessing even non-tor/TBB/Whonix internet connections... why does it automatically have to route ALL my traffic through this one place in Romania???  Going to my host's network adapter, I unchecked "VirtualBox Bridged Networking Driver".  It cost me a BSOD losing this very post I was in the midst of writing... but now with that done, I'm able to surf the clearweb etc. without having to go through that place in Romaina.  This makes no sense to me why it's VirtualBox's default.  Seems dangerous to me. 

That's a Tor relay:  http://torstatus.blutmagie.de/router_detail.php?FP=6225fcfd48db3ddc78405f2e6af4cb15b056d846

It also has the entry guard flag, so it was most likely one of your Tor Gateway's entry guards. Are you absolutely SURE the Gateway wasn't running, because whenever people tell me they are 100% sure of something, it turns out that 95% of the time they are wrong.

Quote
Any other settings I'm missing here?  Suggestions? (besides get rid of windows)

You are well protected even if you run JavaScript, Java and Flash, but you should still disable them anyway unless you really need them.

It's also a good idea to add NoScript and HTTP Everywhere to the browser, and change the user agent to the same thing as TBB so you don't stick out from the crowd.

Quote
I feel like I'm flying blind using this... if I miss one setting I can be totally fucking myself. (Romanian IP?) I think this ignorance/lack of familiarity with Linux is what keeps people away.

Change your start page to check.torproject.org or wtfismyip.com. That way you can always check that it's working, but if it's configured properly, you won't be able to connect to anything except through Tor. Late you might consider using the stream isolation feature for different apps.

156
Security / Re: how to get pgp
« on: September 05, 2013, 03:52 am »
If you're on Windows or 32 bit Linux, this tutorial is pretty good:

http://dkn255hz262ypmii.onion/index.php?topic=206998.msg1487769#msg1487769

157
Security / Re: Dissent: accountable anonymous group communication
« on: September 05, 2013, 03:48 am »
The karma system on this forum is a WOT of sorts. Your proposal would make it actually useful, as opposed to the vanity that it is now.

For example, by blocking all users who have net -20 karma or lower, I would catch almost everyone that I would like to ignore.

I think it's an excellent idea.

Anyone who wants to read everything can go ahead.

158
Security / Re: Tor is under attack
« on: September 05, 2013, 02:34 am »
There is finally a small downtick in the number of directly connecting clients in the experimental estimation method:

https://metrics.torproject.org/users.html#userstats

Does that mean anything yet? I don't know.

159
Security / Re: Dissent: accountable anonymous group communication
« on: September 05, 2013, 02:27 am »
Something like the Web of Trust (WoT) concept is great, but taken too far, it prevents new members from joining unless they know an existing member.  That might be great for a handful of forum types (carders, CP, etc), but not for the ones I'd be interested in.

The only real downsides to a WoT concept are the technical difficulties with making it easy to manage, and the fact that the more flood/DoS/spam a group gets, the harder it is for new members to be trusted and have people see what they have to say (because people will grow to have digitially "distrustful" settings, and new users who don't know someone will have difficulty bridging that gap).

A WOT or a whitelist is basically an invite-only forum. kmf's unique take on it is that everyone builds their own invite-only forum. As you point out, one issue is how do you find new people and content?

I think a whitelist is too restrictive. I'm actually fine with 95% of people who post on this forum, for example. I'd just like an ignore function that works. When you add someone to the ignore list, it would hide the following:

1. Any thread started by that person
2. Any post by that person in other people's threads
3. Any post that quotes that person
4. PMs from that person

The Philosophy, Economics and Justice subforum would be pretty empty for me in that case, but at least I would enjoy the content that I did see. :)


160
Security / Re: Dissent: accountable anonymous group communication
« on: September 05, 2013, 01:13 am »
Astor why would your forum be healthier? Why do you even want to run a centralized forum? Wouldn't it be better if everybody networks with who they want to, and the only forum is the way the threads are organized by the individual user? You seem to advocate for a hierarchical system where some designated person is in charge of what can be said, I am advocating for a non-hierarchical system where every individual is in charge of what they see. I could outsource this to you and you censor spam, or I could just not select to listen to people who spam.

Like I said, that sounds good to me, but my comments were based on the way most forums work. If I could granularly choose which parts of a forum to see, I would do it. There is an ignore feature on this forum, but it appears to be nonfunctional. I've added people like joywind and tedrux to it, but I still see their posts.

161
Security / Re: Dissent: accountable anonymous group communication
« on: September 05, 2013, 01:07 am »
I am not a free speech absolutist, I think that you have the right to tell people not to scream stuff on your lawn. I think in the cyber environment though that it is better if we allow people to remove their own perception of people screaming on their lawn. It is more like someone is screaming on your lawn, but you and everybody else can block out all perceptions of them. So if you don't want them screaming on your lawn, you press a magic button and they vanish from your own perception without a trace, but other people can decide for themselves if they want to hear and see the screaming on your lawn or not. In the cyber environment we can give much more fine grained control to people and I think this is superior. I don't imagine a single forum with leaders and such, I imagine a shared forum-space where every user is the leader of their own perception.

That sounds good to me, but will it protect against flooding of the network that ends up censoring all the good speech? We are witnessing it now with the botnet or whatever it is. I wasn't able to connect to the forum for about a day and it's still intermittent for me, so I am being censored by 2 million idiots shouting circuits into the network, even though I can't see them.

162
Silk Road discussion / Re: Difficulty accessing Tor hidden services
« on: September 04, 2013, 11:41 pm »
I'd like to test a theory. For the people who have had no / few problems in the last couple of days, are you using bridges or regular entry guards?

163
Security / Re: Dissent: accountable anonymous group communication
« on: September 04, 2013, 10:47 pm »
Hows this, spamming is not speech and is a form of censorship, blocking all other communications to proffer your own.

Spamming, like all advertising, is a form of speech. These things are not mutually exclusive. When you shout at the top of your lungs, other people can't hear me, so your speech censors my speech. Your own argument proves that in order to have useful speech you have to censor that shitty speech that would otherwise drown out everything else, which is what I call noise.

Quote
Calling a forum "your property" just because you run it is like the government saying that it can do what it wants with your property because it owns it.

You own the forum because you legitimately paid for the server that runs it, and yes you can do whatever you want with it. I am not your slave. I don't have to let you do anything with my property.

But if your argument is true, that's cool. I'll be crashing on your couch tonight. I mean, you can't just kick me off and do whatever you want with it just because you "own" it.

Quote
Trolls offer dissenting opinions that reflect the underlying problem in the issue, hence why people get pissed about it.

LOL, I bet you think you are some kind of intellectual revolutionary.

Quote
This is still a form of contribution whether or not you see any value in it. Editing and removing discussion because it doesnt fit in with YOUR view of how things should be done is classic fascism, everything must be done towards a specific end and everything else must be suppressed. Read a history book and tell us how thats worked out for various countries over the years.

Nazis AND Fascism, we are on a roll. Is that your great contribution to this debate?

There's a difference between dissenting opinion and trolls. You can offer a dissenting opinion in a way that is edifying to other people. How many people here have been enlightened by trolls?

Trolls are noise. The majority of trolls here don't offer an "opinion" that challenges status quo assumptions, they instigate in order to get a reaction, because they are bored little boys in their basements.


164
Security / Re: Dissent: accountable anonymous group communication
« on: September 04, 2013, 03:02 pm »
OK, and now for the kicker :

Every healthy community and discourse REQUIRES  BANNING DRUGS.

Spoken like a true nazi eh.

This once again has nothing to do with the government. Any business owner with half a brain would ban drug use on the job, while you can do whatever the fuck you want on your property.

In my last few posts, I have made several arguments and used specific examples to back them up, and you've addressed none of that. Your only response was to repeat mindless mantras that you've been brainwashed with ("derp, anyone against free speech is Nazi!"). Nothing you've said has been edifying or advanced the conversation, which is why I say you are the noise.


165
Security / Re: Dissent: accountable anonymous group communication
« on: September 04, 2013, 02:08 pm »
Nobody is allowed to shout nonsense on my lawn. I have every right to censor them by kicking them off my property. Censorship is compatible with anti-statism, because it is subjugated by property rights. There are also perfectly legitimate laws that censor speech, particularly when it causes direct harm, such as yelling fire in a crowded theater and causing a stampede that causes physical injury to people, or libeling someone and destroying their life through false accusations. Yes, there many good reasons to censor, and the free speech absolutists have an childish understanding of free speech and censorship.

Pages: 1 ... 9 10 [11] 12 13 ... 208