HN user

bauruine

1,009 karma

I manage one of the larger Tor relay families https://tuxli.org/

contact: hn@tuxli.ch

Posts3
Comments342
View on HN

Isn't that propagating with around the speed of light? Switzerland is only about 1 light ms wide so even if they only have one master clock instead of one per train station the latency should be negligible especially in the 1950s.

it costs me nothing to change my vocabulary

It cost reddit a 3 hour outage.

The nodeSelector and peerSelector for the route reflectors target the label `node-role.kubernetes.io/master`. In the 1.20 series, Kubernetes changed its terminology from “master” to “control-plane.” And in 1.24, they removed references to “master,” even from running clusters. This is the cause of our outage.

https://old.reddit.com/r/RedditEng/comments/11xx5o0/you_brok...

True but a server that wants to "deanonymize" you can just reject each key till he has all the default keys and the ones you added to your ssh agent.

You can try it yourself [0] returns all the keys you send and even shows you your github username if one of the keys is used there.

[0] ssh whoami.filippo.io

ssh by default sends all your public keys to a server. Yes you can limit some keys to specific hosts but it's very easy to dox yourself.

He uses the keys of his non-exit relay to directly connect from his workstation to an exit relay pretending to be the relay on his VPS. But yeah he could just use the VPS for wireguard which would be way easier.

I'm in Europe so I don't get less than 20Mbit/s on any circuit but I asume he could have got the same speed by just selecting a few local, fast nodes as bridge.

Releasing it is just murder by neglect so people don't feel bad about themself that they actually killed their pet just because "they can't care" for it anymore aka they don't want to deal with the minor inconvenience of caring for a pet anymore. Or worse they become a pest that wipes out whole local ecosystems.

Sure but from your link

The PBL detects end-user IP address ranges which should not be attempting to directly deliver unauthenticated SMTP email to any Internet mail server. All the email originated by an IP listed in PBL is expected to be submitted - using authentication - to a SMTP server which delivers it to destination

Means in practice port 25 (unauthenticated) and port 587 (authenticated)

Blending in with the crowd doesn't work. If you use Chrome on Windows you're part of a very large group and "don't stick out". But it's also very easy to fingerprint so you're also part of the "theturtletalks" group with the size of one.

Tor does this sort of although not like you think. It's used as a bridge transport.

https://blog.torproject.org/introducing-webtunnel-evading-ce...

WebTunnel is a censorship-resistant pluggable transport designed to mimic encrypted web traffic (HTTPS) inspired by HTTPT. It works by wrapping the payload connection into a WebSocket-like HTTPS connection, appearing to network observers as an ordinary HTTPS (WebSocket) connection. So, for an onlooker without the knowledge of the hidden path, it just looks like a regular HTTP connection to a webpage server giving the impression that the user is simply browsing the web.

You don't have to run an exit. A middle node is as important as an exit. And running a non-exit relay is pretty hassle free. You will get blocked by some sites, especially banks and governments unfortunately so be aware of that if you want to run one at home. There is a list for ISPs that allow Tor nodes [0] but diversity is important so if you know an ISP with generous traffic allotments that's better. Just check the TOS that they don't explicitly forbid running a relay. Or you could run a bridge to help censored users connect to Tor.

There is also some information on the community site about running and setting up all kinds of relays or bridges [1]

[0] https://community.torproject.org/relay/community-resources/g...

[1] https://community.torproject.org/relay/