Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - astor

Pages: 1 ... 15 16 [17] 18 19 ... 208
241
Silk Road discussion / Re: Forbes interviews Dread Pirate Roberts
« on: August 24, 2013, 08:28 am »
Haha, touche! ;)  But as a totally non-anonymous member, I have no need to use Tor for the forums. ::)

If onion.to can replace every instance of .onion with .onion.to, then it can read your password when you enter it in too.

So you're trusting that the onion.to admin is a good person and doesn't hack your account, spam, post cp on your behalf, etc. Also, I hope you don't use that password anywhere else.


242
Silk Road discussion / Re: Forbes interviews Dread Pirate Roberts
« on: August 24, 2013, 05:37 am »

This post by Gary Oak summed it up nicely at the time: https://dkn255hz262ypmii.onion.to/index.php?topic=94549.msg669172#msg669172

The hyper-secure astor uses tor2web?  :o ;D

Anyone here not using onion.to can see that the original link I posted is straight .onion. Perhaps you only revealed your own insecure practices via a proxy rewrite. ;)


243
I am very fond of SS.

People like him are why I continue to have a sliver of hope. It is impossible to find someone who does not judge; or only give a shit about themselves.

Too bad I have yet to find that outside of here, I have yet to find someone who is not an asshole who would fuck you over for next to nothing.
Does anyone ever actually take what you have to say to heart? They only do what society tells a "loving" person to do and say oh I am so sorry here is my shoulder to cry on. But deep down they don't give a shit. At least assholes who tell you straight up that they do not care about you or your problems are not being brainwashed fakers.

Humans who actually give a shit about what is going in a "friend's" head/life are extinct. Fuck society, Fuck people.

Cheers to SS.

SS is one of the best people in our community. Cheers.

244
Ok ...I will admit it. I, like StExo  do a bit of misinformation here and there myself as it is good practice since I'm terrible at adjusting my writing styles constantly if I change nicknames or whatever, So when I decided to open my vendor account I got rid of my old forum nickname...I was Guru.

We may have our disagreements, but I admire your wit. :)

245
Silk Road discussion / Re: Forbes interviews Dread Pirate Roberts
« on: August 23, 2013, 10:47 pm »
Do be careful of not getting too "personally" involved in the outward side of the site - letting your personality come across too much (as much as we appreciate your likeable personality). Surely exposing more of yourself can only be a bad thing.

I like the new, engaged DPR. It's like the pre-4/20 DPR came back. The year between is what had the old timers wondering and worrying.

This post by Gary Oak summed it up nicely at the time: http://dkn255hz262ypmii.onion/index.php?topic=94549.msg669172#msg669172

The more DPR talks, the more there seems to be a community vibe.

246
Security / Re: CCleaner 3 or 7 passes enough?
« on: August 23, 2013, 10:02 pm »
PCs used to come with Windows installation disks. If you fucked up your computer, you could do a clean reinstall. This was the case up until about Windows Vista, I believe. Around that time they stopped shipping installation disks and put a rescue partition on the drive instead. The rescue partition only works if there's a recognizable Windows install on one of the other partitions. So you can't do a random write over the Windows partition and reinstall Windows. If you write over the whole drive, the rescue partition is gone too. If you create a backup disk, you run the risk of backing up the files that you want to destroy. So there is no way to securely reinstall the copy of Windows that you paid for (ie, with that license).

I suspect that's not an accident.

247
Security / Re: CCleaner 3 or 7 passes enough?
« on: August 23, 2013, 09:54 pm »
Thank you so much astor! If I could give you karma I would.

Only 2 more questions

1. How do I get a clean copy of my windows os?

Well, that's the hard part. :)

You can either get a pirated copy and risk being identified for copyright violation, or buy a legit copy.

It's interesting that Windows doesn't let you make a clean installation disk. You *must* copy the entire contents of your hard drive onto a backup installation image. I wonder why that is.

Quote
2. Do I need the window os if I just use a usb for a different os? Can I just nuke my computer and use the usb afterward with no windows?

After nuking the hard drive, you could install any OS you want. You could not install anything and run Tails off a DVD or USB, then connect the backup USB and copy your important files into the Tails persistent volume.

248
Security / Re: How to purchase VPN with BTC anonymously?
« on: August 23, 2013, 09:46 pm »
How do you point the browser at a random web proxy?

Pick one of these web proxies and enter the URL of the site you want to reach: http://www.publicproxyservers.com/proxy/list_rating1.html

Different proxies offer different features. Not all of them will proxy SSL connections, for example. Some of them will include headers that tell the destination site the connection is being proxied. You want a proxy marked as "HiAn" on that list (high anonymity, ie, the X-Forwarded-For header is not set).

You can google for other web sites that list thousands of web proxies like that.

249
Security / Re: How to purchase VPN with BTC anonymously?
« on: August 23, 2013, 09:40 pm »
What do you mean run the VPN over TOR?    Do you mean buy the VPN using TOR to connect to the website?

No, I mean proxy the VPN connection over Tor.

If you connect to the VPN server directly over clearnet, they know your IP address, so it's not anonymous. Thus paying with bitcoins is pointless.

250
@Psyche
Maybe this is less about forcing users to use PGP but more about preventing the FBI/NSA harrassing him. If he can't decrypt the emails there is no point in targeting him.

I believe that is exactly why they want to drop all unencrypted emails.

where is the login page of http://365u4txyqfy72nul.onion/mail/ ?

From the looks of it, there's no webmail. just pop and imap.

It's the second link I posted: http://365u4txyqfy72nul.onion/wmail/notice.html


I like that they put the Postfix configuration files on Github, so anyone can run a gateway. There could be multiple gateways relaying for multiple hidden service email providers, so there isn't a central point of failure like Tormail.

251
Security / Re: How to purchase VPN with BTC anonymously?
« on: August 23, 2013, 06:52 pm »
Unless you run the VPN over Tor, it's useless to pay "anonymously".

A VPN over Tor gives you a persistent exit node that makes you more vulnerable to deanonymization. If you need a non-exit node IP, point the Tor Browser at a random web proxy and use a different one each time.

252
Security / Re: CCleaner 3 or 7 passes enough?
« on: August 23, 2013, 06:48 pm »
There is no such thing as  a safe way to lose data by using nsa, one or 7 times, it doesn't matter.
The more the better.

There is a lot of evidence that contradicts your claim.

According to the 2006 NIST Special Publication 800-88 Section 2.3 (p. 6): "Basically the change in track density and the related changes in the storage medium have created a situation where the acts of clearing and purging the media have converged. That is, for ATA disk drives manufactured after 2001 (over 15 GB) clearing by overwriting the media once is adequate to protect the media from both keyboard and laboratory attack."

The National Institute of Standards and Technology is a government agency that makes recommendations to government and industry. Secure data erasure is important, for example, to comply with HIPAA, the medical privacy law. Hospitals must destroy medical records when their computers are decommissioned. They must wipe their hard drives. If they threw away a bunch of computers with insecurely erased hard drives and someone was able to recover patient records, that would be a massive violation of federal law. That's why it's unlikely that NIST is lying about their recommendation in order to screw us.

According to the 2006 Center for Magnetic Recording Research Tutorial on Disk Drive Data Sanitization Document (p. 8): "Secure erase does a single on-track erasure of the data on the disk drive. The U.S. National Security Agency published an Information Assurance Approval of single pass overwrite, after technical testing at CMRR showed that multiple on-track overwrite passes gave no additional erasure."

Again, this Information Assurance Approval by the NSA is for other government agencies. They are unlikely to be lying to them.

I posted the entire CMRR white paper here: http://dkn255hz262ypmii.onion/index.php?topic=99520.msg699299#msg699299

Further analysis by Wright et al. seems to also indicate that one overwrite is all that is generally required.

http://link.springer.com/chapter/10.1007%2F978-3-540-89862-7_21


Perhaps the best evidence that the NSA doesn't have magic technology to recover files after random writes is this:

A forensics expert testified in the Bradley Manning trial that, "the hard drive on Manning's computer had been securely erased in January 2010. "Everything from early January is gone"'.

http://www.theguardian.com/world/blog/2011/dec/19/bradley-manning-pre-trial-hearing-live-updates

Bradley Manning is the highest profile person to be prosecuted by the US government in the last 5 years. If they had the ability to recover data from his computer after it was securely erased, they would have used it. They didn't use it because it doesn't exist. Or if it does exist and Manning wasn't worth the trouble of using it on, none of us are either.

I should point out that Manning tried several times to securely erase his hard drives. One of those times was a zero write and they were able to recover data from that, so we should consider zero writes to be insecure. However, one random write is sufficient to make data unrecoverable.

253
Security / Re: CCleaner 3 or 7 passes enough?
« on: August 23, 2013, 06:02 pm »
I have been using windows in the past.
It seems that I should wipe my entire drive.
I have a few questions

1. Do I need to save my os and files on a disc?

The disk image backup feature on Windows is retarded. You'll be backing up and reinstalling the very files you want to destroy, since you'll be backing up all the caches and log files. You should individually backup the most important files, wipe the drive and do a clean reinstall of the OS, then copy the backup over.

Quote
2. How do you accomplish ^^

Get a thumb drive. Use Truecrypt to encrypt the whole thing. Copy over your important files.

Quote
3. Then you Dban the drive? Or nuke it?

Yep, DBAN has a one-click nuke option, just make sure the thumb drive isn't plugged in or it will nuke that too. :)

Quote
4. Then install windows as normally? If you even want it back?

Install it from a normal installation disk, not a backup image of your drive.

Quote
5. What are these nightcrawler links?

Key servers. If you don't know what they are, don't use them.

254
Silk Road discussion / Re: Never mind.
« on: August 20, 2013, 07:04 pm »
I posted once about it a while ago, but there in no official policy.  right now what we do is archive the data after 4 months.  archiving basically strips out all info except what is needed for the stats and keeps the database lean.  I removed the "all-time" column after reading this thread to avoid further issues.  It's kind of unimportant for judging a buyer and I think it is nicer on the eyes/mind to have 3 instead of 4 data points to look at anyway.

But the data is not stripped of identifying info as long as the account is active. That's pretty clear from the total vendors stats.

So I stand by my recommendation earlier in this thread. If you don't want to accumulate a long trail of evidence, create a new account.

255
Silk Road discussion / Re: feedback system overhaul
« on: August 20, 2013, 06:59 pm »
Who cares about this new discussion system when the feedback that already exists is ignored for so long.

Goldmax was allowed to scam for 12 or 13 days. How long will PlanetExpress be allowed to scam? How much more feedback do you need to act in a timely manner?

Faster banning of scammers. That's the new feature we need.

Pages: 1 ... 15 16 [17] 18 19 ... 208