HN user

gexcolo

156 karma

vc@cock.li https://vc.gg/

Posts0
Comments26
View on HN
No posts found.

I'm the author of this post. What people who are unaware of the layout of the congress center don't realize is that the video starts when we were leaving. The door "inside" is actually to get "outside". I was told to leave in 5 minutes, I stayed where I was maybe 2 minutes and started walking (I'm not leaving anything out, it was just more of the first audio recording), and then was prevented from leaving the event by masked thugs who pretend to be real security guards on paper.

People assume I did something to deserve this, and I can live with that. But in reality it was nothing more than the list of domain names I own. I did my best to describe that here.

Sure, the mail storage currently takes up 1.01TB, using dovecot's mdbox. This mail store started in January 2016, after the service got raided twice by german authorities[0] (at request of u.s. gov), otherwise it would be larger.

I'm not going to run like per-user stats but I know historically there's been about 11kb per E-mail on average, so that's about 90 million mails stored. The MTA itself sends and receives a bit over 20 million E-mails annually, so the extra from that is probably from the mailing list I run on the same server (where each message only counts as 1 for statistical purposes)

How I prevent outgoing abuse is a black box, but I do it well enough that mail from my server almost never ends up in spam. But given that it's a free service I definitely don't have the budget to warm up and dynamically scatter mail across IP space to maximize deliverability. Cool technique, though!

[0] https://archive.is/etfDM

[0] https://archive.is/etfDM

I run an E-mail server with over 250,000 users. I started by following some generic "dovecot+postfix+mysql" tutorial on howtoforge and I'm still using mostly the same setup over 4 years later.

Then your email doesn't work and you could be missing out on important communications

Pretty much every E-mail server will retry sending your E-mail for a long time (like 2 days is default on postfix). Once your mail server comes back up all of your E-mail you missed during the downtime will come in slowly as messages are retried

you're scrambling to figure out how the spammers managed to exploit your setup this time

Any tutorial should point you in the right direction restricting open relay on your mail server, just basically requiring authentication to send E-mail outside of your server.

I started writing an SMTP protocol handler in Haskell

Do you have any link to your progress? Postfix's configuration definitely shows age, but all of the options do important things that you could actually want to change. It seems other MTAs either have just as complicated configuration (to do the same things), or have stunted functionality.

being secure and resistant to attacks by default

I agree about sensible and more secure defaults in configuration. But the application security of postfix and dovecot are both pretty robust[0][1]. Considering they are 19 and 15 years old, both applications have seen several developer-lifetimes of effort.

we need more guides like this for us poor souls who do go down this route

I agree, though mediocre howtoforge tutorials seem to have worked fine for this poor soul.

[0] https://www.cvedetails.com/product/14794/Postfix-Postfix.htm...

[1] https://www.cvedetails.com/vendor/6485/Dovecot.html

I use PGP every day. Who messages me, how often, and at what times, is still private information and I should have a say in where and how that happens. My PGP-encrypted conversations tend to be much more sensitive than any other medium I use.

The cryptography is almost certainly not broken. That does not mean it won't be broken in the future. I would have the same concern if my TLS-encrypted traffic was being saved. If my ISP was saving TLS traffic or my XMPP provider (the one that I don't host, anyway) was saving OTR conversations, I would be equally concerned.

Even worse, actually. TLS (usually, nowadays) and OTR both employ forward secrecy. PGP does not, at least traditionally.

What bugs me about the direction Keybase is going is that they still have not implemented a way of disabling the ability for users to send me encrypted messages.

I do not want Keybase to hoard encrypted messages I will never be able to read because I do not want to install their application on my computer. My Github issue for this has gone largely ignored:

https://github.com/keybase/keybase-issues/issues/2808

I am thinking I am long overdue to placeholder my account until this is solved. I already have 10 encrypted messages I will never be able to read. I joined Keybase as a public key repository with external verification support, not for them to store private conversations -- encrypted or not.

Location: U.S. citizen living in Bucharest, Romania

Remote: Yes

Willing to relocate: If not in U.S.

Technologies: Linux (openvpn, postfix/dovecot/spamassassin, mysql, nginx), devops/automation (ansible, capistrano), security (burp, snort, nmap), Python, PHP, Bash

(many many more not listed here)

Résumé/CV: https://vc.gg/ (autoplay video), real resume by request

Email: vc@cock.li

I'm an experienced linux system administrator currently employed for a U.S. company. In my spare time I run a public E-mail provider with 132,000 users, and a VPS provider with >$1K MRR. I'm interested in positions in the security or sysadmin space, with bonus points for companies providing services that respect users' privacy, or provide a tangibly beneficial product or service as part of their business model. I'm also open to development work but only as an aside. Sysadmin first, programmer second. A sense of humor is required as my side projects aren't exactly politically correct, though I keep work and my personal ventures completely separate.

Due to my work providing privacy-oriented services, I recently had $2,000 worth of electronics seized at the U.S. border because I refused to decrypt my electronic devices. Because of this, relocating to the U.S. is not an option.

This is probably because I had set up DNSSEC on my nameservers, but my registrar doesn't yet support DNSSEC for .li. I plan on moving to another registrar once the domain is closer to expiry. I guess I'll try to do something sooner than that to remove the DNSSEC entries that my nameserver is returning.

I'm the author of the OP's post. When I left the U.S. one of the questions that I was asked (that I refused to answer) was whether I used any social media and what the accounts were. The sites that they listed as examples were Facebook and WhatsApp, which I found particularly interesting.

are you up at night wondering if you've made a novice error and a user or someone who dislikes one of your users is rooting around in your hardware up to no good?

I dropped a database on accident yesterday because I assumed that replication was broken (it wasn't). If someone has managed to root my servers I hope they clean stuff up a bit.

And is there any profit to be made at your current size for your revenue?

Cock.li operates not-for-profit, making it a break-even operation that operates financially separate from cockbox. Cockbox took about $2-3K of investment to get going on rented IP space, total to date I have invested about $9K on server hardware to support up to 180 "slots" (sold GB of memory aka $10MRR) and IP space to support a bit more than that (1x/24 aka 255 IPv4 addresses and a /48 IPv6). Considering ongoing expenses are hardware replacements and colocation costs, profit margins are very high.

I run https://box.cock.li/ , a VPS provider that caters to shitposters and people that kind of like that eerie feeling that your server could shut down at any moment.

I don't really have any idea what I'm doing, but I don't really know how to run a mail server either but I seem to be doing okay with https://cock.li/ (this is where most of my customers are from)

It's currently at about $2K total revenue, and once this transfer of IP space finishes I can properly scale to about $1.8K MRR.

If memory serves me correctly, RMS doesn't actually manage his own website. He has a number of volunteers that help update the website and post political notes. Those notes are likely a message from him to his volunteers, or the volunteers reminding themselves.

"Mr. Canfield" here,

I don't know if I would say I was "trusting of authorities" but I'm definitely distrusting now. I didn't bother with FDE because I figured it was more trouble than it was worth for a server that I ultimately don't own and can't control or protect against the oodles of key recovery attacks I'd have to worry about. In the event of a seizure I don't want to be like "hey uh they might have gotten everything maybe not!" so it's just not something I bothered with.

The situation is different now though as the service is being colocated instead of hosted on a rented server, which gives me a lot more freedom what can be done to secure the server against data theft. I'm also hosting with a privacy-conscious host (FlokiNET) I know will cooperate with me and fight bullshit government requests if/when they arrive (not saying what happened with Germany is bullshit, it's yet to be seen and I've been advised not to speculate).

Data theft aside, the service is in a more secure position it's ever been in. There's comfort in that, at least...

[dead] 12 years ago

This is fake. You can read the source code of the page to see.

Can we get this removed from the front page?