Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178970 > unrolled thread

tor -- way OT

Started byGlenn English <ghe2001@gmail.com>
First post2017-03-17 19:30 +0100
Last post2017-03-19 20:50 +0100
Articles 10 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  tor -- way OT Glenn English <ghe2001@gmail.com> - 2017-03-17 19:30 +0100
    Re: tor -- way OT Reco <recoverym4n@gmail.com> - 2017-03-17 20:10 +0100
      Re: tor -- way OT Teemu Likonen <tlikonen@iki.fi> - 2017-03-17 20:50 +0100
        Re: tor -- way OT Reco <recoverym4n@gmail.com> - 2017-03-17 21:00 +0100
    Re: tor -- way OT Peter Ludikovsky <peter@ludikovsky.name> - 2017-03-18 09:30 +0100
      Re: tor -- way OT GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-18 18:30 +0100
        Re: tor -- way OT Glenn English <ghe2001@gmail.com> - 2017-03-18 21:00 +0100
          Re: tor -- way OT GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-18 22:50 +0100
        Re: tor -- way OT Latincom <latincom@vcn.bc.ca> - 2017-03-19 11:50 +0100
          Re: tor -- way OT GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-19 20:50 +0100

#178970 — tor -- way OT

FromGlenn English <ghe2001@gmail.com>
Date2017-03-17 19:30 +0100
Subjecttor -- way OT
Message-ID<tm4Ns-29P-29@gated-at.bofh.it>
I'm trying to use the Tor Browser. They don't seem to have any support
(beyond an FAQ) on their site, so I'm asking here.

Jessie and XFCE on a Supermicro workstation connected through a T1.

I installed Tor a few days ago and it was working fine -- Gmail said
it was having authentication problems and that I was using Firefox on
Winders in Paris. Just what I'd hoped for.

Then I installed privoxy and set the regular browser (Firefox) to use
it. Tor started saying it couldn't find the proxy it'd been configured
to use. Tor hadn't been configured to do any such thing, but I looked
at the config to make sure.

Firefox is the same -- no proxy. It used to use privoxy, but I turned it off

I removed Tor (Aptitude purge) and reinstalled (with Aptitude), and it
connected to DuckDuckGo, Amazon, and Newegg (maybe others, I haven't
tried). But it couldn't find the proxy when I pointed at local sites
and the virtuals on my server (again, maybe others).

So I removed privoxy, and now Tor can't even connect to its own network.

Anybody seen this, have an idea, know a fix?? Is there some kind of
(defective) interaction between the Tor and Firefox configs?

--
Glenn English

[toc] | [next] | [standalone]


#178972

FromReco <recoverym4n@gmail.com>
Date2017-03-17 20:10 +0100
Message-ID<tm5qb-2HS-19@gated-at.bofh.it>
In reply to#178970
	Hi.

On Fri, 17 Mar 2017 12:28:33 -0600
Glenn English <ghe2001@gmail.com> wrote:

> I'm trying to use the Tor Browser. They don't seem to have any support
> (beyond an FAQ) on their site, so I'm asking here.
> 
> Jessie and XFCE on a Supermicro workstation connected through a T1.
> 
> I installed Tor a few days ago and it was working fine -- Gmail said
> it was having authentication problems and that I was using Firefox on
> Winders in Paris. Just what I'd hoped for.
> 
> Then I installed privoxy and set the regular browser (Firefox) to use
> it. Tor started saying it couldn't find the proxy it'd been configured
> to use. Tor hadn't been configured to do any such thing, but I looked
> at the config to make sure.

A big red "you're doing it wrong" sign flashes in my head as I read
this.

First things first. Tor provides you with SOCKS5 proxy server already.
Why bother chaining it with conventional HTTP proxy?

Second thought. While Tor has some (limited) ability to work via proxy
[1], it is by no means required to force Tor to use one.

 
> Firefox is the same -- no proxy. It used to use privoxy, but I turned it off 
> I removed Tor (Aptitude purge) and reinstalled (with Aptitude), and it
> connected to DuckDuckGo, Amazon, and Newegg (maybe others, I haven't
> tried). 

It's not a valid test as it does not prove anything. Try [2]. If you
see security.debian.org - you're set.


> But it couldn't find the proxy when I pointed at local sites
> and the virtuals on my server (again, maybe others).
> 
> So I removed privoxy, and now Tor can't even connect to its own network.
> 
> Anybody seen this, have an idea, know a fix?? Is there some kind of
> (defective) interaction between the Tor and Firefox configs?

Sure. Deinstall/purge current Tor and privoxy.
Install Debian's version of Tor. It should start itself.
Point your Firefox to SOCKS5 proxy located at localhost port 9050.
That all you (ever) need, judging from your timezone.

Do not mix HTTP proxy into your setup. You won't gain anything short of
complicating your setup.

Reco

[1] https://www.torproject.org/docs/faq.html.en#NeedToUseAProxy
[2] http://sgvtcaew4bxjd7ln.onion/

[toc] | [prev] | [next] | [standalone]


#178976

FromTeemu Likonen <tlikonen@iki.fi>
Date2017-03-17 20:50 +0100
Message-ID<tm62R-2ZV-7@gated-at.bofh.it>
In reply to#178972

[Multipart message — attachments visible in raw view] — view raw

Reco [2017-03-17 22:05:45+03] wrote:

> Sure. Deinstall/purge current Tor and privoxy. Install Debian's
> version of Tor. It should start itself. Point your Firefox to SOCKS5
> proxy located at localhost port 9050. That all you (ever) need,
> judging from your timezone.
>
> Do not mix HTTP proxy into your setup. You won't gain anything short
> of complicating your setup.

In practice the Tor network, especially hidden services, work badly
without a http proxy. It has been a while since I last tried but I
always ended up setting up polipo http proxy.

-- 
/// Teemu Likonen   - .-..   <https://keybase.io/tlikonen> //
// PGP: 4E10 55DC 84E9 DFF6 13D7 8557 719D 69D3 2453 9450 ///

[toc] | [prev] | [next] | [standalone]


#178977

FromReco <recoverym4n@gmail.com>
Date2017-03-17 21:00 +0100
Message-ID<tm6cy-33T-7@gated-at.bofh.it>
In reply to#178976
On Fri, 17 Mar 2017 21:48:02 +0200
Teemu Likonen <tlikonen@iki.fi> wrote:

> Reco [2017-03-17 22:05:45+03] wrote:
> 
> > Sure. Deinstall/purge current Tor and privoxy. Install Debian's
> > version of Tor. It should start itself. Point your Firefox to SOCKS5
> > proxy located at localhost port 9050. That all you (ever) need,
> > judging from your timezone.
> >
> > Do not mix HTTP proxy into your setup. You won't gain anything short
> > of complicating your setup.
> 
> In practice the Tor network, especially hidden services, work badly
> without a http proxy. It has been a while since I last tried but I
> always ended up setting up polipo http proxy.

I'm using Tor just right now via SOCK5, and that includes several kinds
of L7 including HTTP. Care to elaborate what exactly should 'work
badly' for me? 

Reco

[toc] | [prev] | [next] | [standalone]


#178987

FromPeter Ludikovsky <peter@ludikovsky.name>
Date2017-03-18 09:30 +0100
Message-ID<tmhUm-3ul-5@gated-at.bofh.it>
In reply to#178970

[Multipart message — attachments visible in raw view] — view raw

Hello,

First things first: AFAIK, just installing privoxy doesn't make it use
Tor, it just acts as a regular proxy. Visit [1] to see if you're using
Tor or not. In order to enable chaining through Tor you'll have to have
a line like
  forward-socks5	/	<ip>:<port>
An example line, as well as a documentation for it, is in
/etc/privoxy/config, starting at or around line 1238. Also there, you'll
find examples on how to exempt your local network(s), as Tor will never
be able to reach them.

Or, you could install the torbrowser-launcher[2] package, which contains
everything preconfigured for browsing.

Regards,
/peter

[1] https://check.torproject.org/
[2] https://packages.debian.org/jessie/torbrowser-launcher

Am 17.03.2017 um 19:28 schrieb Glenn English:
> I'm trying to use the Tor Browser. They don't seem to have any support
> (beyond an FAQ) on their site, so I'm asking here.
> 
> Jessie and XFCE on a Supermicro workstation connected through a T1.
> 
> I installed Tor a few days ago and it was working fine -- Gmail said
> it was having authentication problems and that I was using Firefox on
> Winders in Paris. Just what I'd hoped for.
> 
> Then I installed privoxy and set the regular browser (Firefox) to use
> it. Tor started saying it couldn't find the proxy it'd been configured
> to use. Tor hadn't been configured to do any such thing, but I looked
> at the config to make sure.
> 
> Firefox is the same -- no proxy. It used to use privoxy, but I turned it off
> 
> I removed Tor (Aptitude purge) and reinstalled (with Aptitude), and it
> connected to DuckDuckGo, Amazon, and Newegg (maybe others, I haven't
> tried). But it couldn't find the proxy when I pointed at local sites
> and the virtuals on my server (again, maybe others).
> 
> So I removed privoxy, and now Tor can't even connect to its own network.
> 
> Anybody seen this, have an idea, know a fix?? Is there some kind of
> (defective) interaction between the Tor and Firefox configs?
> 
> --
> Glenn English
> 

[toc] | [prev] | [next] | [standalone]


#178995

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-03-18 18:30 +0100
Message-ID<tmqkW-1az-5@gated-at.bofh.it>
In reply to#178987
READ THE MANUALS  ;)  :P  (just kidding!)

Various steps

1  About vpn and reaching the tor gate, your ISP may be able to see that
you are reaching out to make a connection to the various gates/nodes and
you may not want that, as ISPs are passing all personal information to
big-Sister.  And you "may" not want them to do so.  They pick on your
attempt to connect from their own DNS that you normally use.  It seems
as someone vigorously is supplying all ISPs in the world with a daily
updated list of known tor exit-entry-nodes.  So change your DNS servers
to what is assumed to be a safe net of DNS servers that do not log your
DNS requests.  I did say assumed, didn't I?

wiki.opennicproject.org/GettingStarted/#hn_Ubuntu_Linux
servers.opennicproject.org/  (Choose 3-4 from the list and check monthly
for dropped servers and try the ones closest to you, although the
furthest may only be a few hundred milliseconds away).

2  If you can afford a VPN service good for you.  For the less
privileged (like 96% of the planet) there is calyx.net and bitmask.net
https://bitmask.net/en/install/linux#debian-packages
or you can download a standalone package.  There is also a testing-beta
0.9.4 version.  This is a project by Leap.se and has made this open
source code available and is begging to be forked.  It is like openVPN
for dummies (like some of us).

3  tor by torproject.org is open and free just like Debian
That is why Debian only works with torproject and not just any other tor
software.  And all of them will tell your they work better!  Tor is a
network which you need special configuration to enter (and exit) safely.
Everything you wanted to know and were afraid to ask:
https://onion.debian.org/

Once you get tor running and install tor-browser you may also add the
torproject.org repository as well.  Since you are using it you might as
well use onion addresses to replace all repositories (Debian and Tor)

*** ... once you have the "apt-transport-tor" package installed, the
following entries should work in your sources list for a stable system:
(change the stretch to jessie stable testing sid ... or what you have)

deb
1 tor+http://vwakviie2ienjx6t.onion/debian stretch main
deb
2 tor+http://vwakviie2ienjx6t.onion/debian stretch-updates main
deb
3 tor+http://sgvtcaew4bxjd7ln.onion/debian-security stretch/updates    main
deb
4 tor+http://vwakviie2ienjx6t.onion/debian stretch-backports main
deb
5 tor+http://sdscoq7snqtznauu.onion/torproject.org/ testing main

Remember the tor-transport package mentioned above is essential for any
of them to work and a live tor connection.  If tor daemon has stopped
all those addresses will run into an error.
You can also add the deb tor+http://debian...  or any other non onion
address and that works too.


4  And if all this wasn't enough ..... there is MORE!  Try
sandboxed-tor-browser in its 3rd current beta version.  It is just like
the tails tor-browser that can not see beyond its own sandbox (the
Amnesia sandboxed disk within your disk).

5  None of this stuff make any sense if you are enabling scripts and
going to googlefatsbookyoohooemesen ... crap sites!  You are defeating
the purpose of anonymity and privacy.  Do not abuse sensible freedom!
All debian websites do not require any scripts to be accessed and read.
Most respected websites (non-invasive) are the same way.  Those you can
not reach (it gets cloudy out-there) you don't want to read any way.

6  If you want to test your browser for torification use
check.torproject.org
If you want to check the configuration of other browsers and their
effective ability to cover themselves use eff.mozilla
https://panopticlick.eff.org/ but it doesn't mean much as it is compared
with a huge amount of non-tor browsers.

This project browserprint.info seems to be doing part of the same and
more but more directed to tor browsers.  The score is getting better
with every new edition of tor-browser.  The more unique your fingerprint
the easier for little-big-sisters to tell who you might be and what are
you up to.  So, you want to blend in with the fish, not stick out.  You
might hear that "the old tor was better than the new one, I am sticking
with the older version" and that is crap.  As 99% are updating to the
latest your trusty old tor-browser will stick out like a shore thumb!

7  If you are using icedove/thunderbird for mail disable all your
plugins and install tor-birdie which prohibits your mail-system to
communicate without tor.  Nothing comes-in nothing comes-out if the tor
connection has been dropped.

8  There is also tor-chatting and messaging and all kinds of other stuff
I do not use.

9  Don't expect Neo to come, save yourself!

Peter Ludikovsky:
> Hello,
> 
> First things first: AFAIK, just installing privoxy doesn't make it use
> Tor, it just acts as a regular proxy. Visit [1] to see if you're using
> Tor or not. In order to enable chaining through Tor you'll have to have
> a line like
>   forward-socks5	/	<ip>:<port>

I used socks5://127.0.0.1:9050 on midori and the score sucked on the
above mentioned uniqueness profiler.

> Or, you could install the torbrowser-launcher[2] package, which contains
> everything preconfigured for browsing.

It is the only safe way to go, any deviation from the prescribed is
risking anonymity.  You might as well not use any of this stuff.

> Regards,
> /peter
> 
> [1] https://check.torproject.org/
> [2] https://packages.debian.org/jessie/torbrowser-launcher

Read this too:
https://guardianproject.info/2016/07/31/howto-get-all-your-debian-packages-via-tor-onion-services/

> Am 17.03.2017 um 19:28 schrieb Glenn English:
>> I'm trying to use the Tor Browser. They don't seem to have any support
>> (beyond an FAQ) on their site, so I'm asking here.
>>
>> Jessie and XFCE on a Supermicro workstation connected through a T1.
>>
>> I installed Tor a few days ago and it was working fine -- Gmail said
>> it was having authentication problems and that I was using Firefox on
>> Winders in Paris. Just what I'd hoped for.

Get some real mail and leave the G for nonsense ...  Once your real
location and identity is recorded ... any attempts to identify or cover
yourself up from such companies are meaningless.  Just separate your
private life from the "open and free" commercial services.  Move on,
there is nothing to see there :)

>> So I removed privoxy, and now Tor can't even connect to its own network.

Just do a reinstall by forget the standalone apps, do it through apt
apt-get synaptic system installation.  Make sure you get all the gpg
keyring stuff done right.  Once the system has safely got tor-daemon
running the first attempt to start the browser will open up a gui with
options (make sure you enable the sound part :) it will download the
browser safely through tor, which means it verifies its structure hasn't
been altered on its way to you.

Imagine living in a country that is not as free as the US (goughh,..
ghhgh.. bwwraaahhh..) that even reaching a tor gateway needs some bridge
somewhere because all other entry points are blocked by the government's
networking.  If government agents and large corporation executives
wouldn't rely so much to the safety of this network it wouldn't exist.
They don't want their anonymity but they sure do want their own.

Peace (by any means necessary)
kAt

PS  Do not watch Snowden videos with Tor ...  with your Gmail logged in!

-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [next] | [standalone]


#179003

FromGlenn English <ghe2001@gmail.com>
Date2017-03-18 21:00 +0100
Message-ID<tmsG5-2No-3@gated-at.bofh.it>
In reply to#178995
On Sat, Mar 18, 2017 at 11:19 AM, GiaThnYgeia
<GiaThnYgeia@openmailbox.org> wrote:

> READ THE MANUALS  ;)  :P  (just kidding!)

Wow! Thanks for so much advice from the list.

<FWIW, FYI>
Everybody said to get rid of privoxy, so I did -- there was no privoxy
on the machine Tor was on, but there was on the server across the room
that this machine has no business talking to, except to send and fetch
email. But that somehow seems to have made Tor start working again. I
don't quite believe that getting rid of privaxy over there had
anything to do with this machine. Maybe the Tor network was just a
little bent or something the other day.

Anyway, if you can read this, Gmail's running again on Tor. Tor's a
little laid back this afternoon -- enough that Google whined about the
speed. But that's what I expected. Somebody in Gondwanaland's on a
dialup.
</FWIW, /FYI>

To those concerned about the 'G' word, I'm using Gmail while I get the
domain working again. I just moved, and things aren't yet what they
have been. Email claims to be up, but I don't quite trust it yet.

Thanks again for all the help. It seems to be doing  OK with just the
vanilla Aptitude install. No SOCKS, no reinstall; just no privoxy (on
the other side of the room).

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#179004

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-03-18 22:50 +0100
Message-ID<tmuox-43H-1@gated-at.bofh.it>
In reply to#179003
Glenn English:
> On Sat, Mar 18, 2017 at 11:19 AM, GiaThnYgeia
> <GiaThnYgeia@openmailbox.org> wrote:
> 
>> READ THE MANUALS  ;)  :P  (just kidding!)
> 
> Wow! Thanks for so much advice from the list.
> 
> <FWIW, FYI>
> Everybody said to get rid of privoxy, so I did -- there was no privoxy
> on the machine Tor was on, but there was on the server across the room
> that this machine has no business talking to, except to send and fetch
> email. But that somehow seems to have made Tor start working again. I
> don't quite believe that getting rid of privaxy over there had
> anything to do with this machine. Maybe the Tor network was just a
> little bent or something the other day.

This is part of the privoxy config instructions:
#  5.2. forward-socks4, forward-socks4a, forward-socks5 and forward-socks5t
#  =========================================================================
#
#  Specifies:
#
#      Through which SOCKS proxy (and optionally to which parent HTTP
#      proxy) specific requests should be routed.
#
#  Type of value:
#
#      target_pattern socks_proxy[:port] http_parent[:port]
#
#      where target_pattern is a URL pattern that specifies to which
#      requests (i.e. URLs) this forward rule shall apply. Use / to
#      denote "all URLs". http_parent and socks_proxy are IP
#      addresses in dotted decimal notation or valid DNS names (
#      http_parent may be "." to denote "no HTTP forwarding"), and
#      the optional port parameters are TCP ports, i.e. integer
#      values from 1 to 65535
#
#  Default value:
#
#      Unset
#
#  Effect if unset:
#
#      Don't use SOCKS proxies.
#
#  Notes:
#
#      Multiple lines are OK, they are checked in sequence, and the
#      last match wins.
#
#      The difference between forward-socks4 and forward-socks4a is
#      that in the SOCKS 4A protocol, the DNS resolution of the
#      target hostname happens on the SOCKS server, while in SOCKS 4
#      it happens locally.
#
#      With forward-socks5 the DNS resolution will happen on the
#      remote server as well.
#
#      forward-socks5t works like vanilla forward-socks5 but lets
#      Privoxy additionally use Tor-specific SOCKS extensions.
#      Currently the only supported SOCKS extension is optimistic
#      data which can reduce the latency for the first request made
#      on a newly created connection.
#
#      socks_proxy and http_parent can be a numerical IPv6 address
#      (if RFC 3493 is implemented). To prevent clashes with the port
#      delimiter, the whole IP address has to be put into brackets.
#      On the other hand a target_pattern containing an IPv6 address
#      has to be put into angle brackets (normal brackets are
#      reserved for regular expressions already).
#
#      If http_parent is ".", then requests are not forwarded to
#      another HTTP proxy but are made (HTTP-wise) directly to the
#      web servers, albeit through a SOCKS proxy.
#
#  Examples:
#
#      From the company example.com, direct connections are made to
#      all "internal" domains, but everything outbound goes through
#      their ISP's proxy by way of example.com's corporate SOCKS 4A
#      gateway to the Internet.
#
#        forward-socks4a   /              socks-gw.example.com:1080
www-cache.isp.example.net:8080
#        forward           .example.com   .
#
#      A rule that uses a SOCKS 4 gateway for all destinations but no
#      HTTP parent looks like this:
#
#        forward-socks4   /               socks-gw.example.com:1080  .
#
#      To chain Privoxy and Tor, both running on the same system, you
#      would use something like:
#
#        forward-socks5t   /               127.0.0.1:9050 .
#
#      Note that if you got Tor through one of the bundles, you may
#      have to change the port from 9050 to 9150 (or even another
#      one). For details, please check the documentation on the Tor
#      website.
#
#      The public Tor network can't be used to reach your local
#      network, if you need to access local servers you therefore
#      might want to make some exceptions:
#
#        forward         192.168.*.*/     .
#        forward            10.*.*.*/     .
#        forward           127.*.*.*/     .
#
#      Unencrypted connections to systems in these address ranges
#      will be as (un)secure as the local network is, but the
#      alternative is that you can't reach the local network through
#      Privoxy at all. Of course this may actually be desired and
#      there is no reason to make these exceptions if you aren't sure
#      you need them.
#
#      If you also want to be able to reach servers in your local
#      network by using their names, you will need additional
#      exceptions that look like this:
#
#       forward           localhost/     .
#
#


> Anyway, if you can read this, Gmail's running again on Tor. Tor's a

It's almost like a contradiction in terms ... like an anarchist
dictatorship ...  that people voted for!

> Thanks again for all the help. It seems to be doing  OK with just the
> vanilla Aptitude install. No SOCKS, no reinstall; just no privoxy (on
> the other side of the room).

If gmail is running on tor then socks5 is your proxy to the gmail
server.  I assume you mean webmail not pop/imap server.  If the later is
true and it is configured to run through this socks5 proxy of tor, then
OK.  If not, you are bypassing tor and connecting to pop/imap directly
with out this tor proxy.


-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [next] | [standalone]


#179010

FromLatincom <latincom@vcn.bc.ca>
Date2017-03-19 11:50 +0100
Message-ID<tmGzo-4lF-25@gated-at.bofh.it>
In reply to#178995
On Sat, 18 Mar 2017 17:19:00 +0000, GiaThnYgeia wrote:

> READ THE MANUALS  ;)  :P  (just kidding!)
> 
> Various steps
> 
> 1  About vpn and reaching the tor gate, your ISP may be able to see that
> you are reaching out to make a connection to the various gates/nodes and
> you may not want that, as ISPs are passing all personal information to
> big-Sister.  And you "may" not want them to do so.  They pick on your
> attempt to connect from their own DNS that you normally use.  It seems
> as someone vigorously is supplying all ISPs in the world with a daily
> updated list of known tor exit-entry-nodes.  So change your DNS servers
> to what is assumed to be a safe net of DNS servers that do not log your
> DNS requests.  I did say assumed, didn't I?
> 
> wiki.opennicproject.org/GettingStarted/#hn_Ubuntu_Linux
> servers.opennicproject.org/  (Choose 3-4 from the list and check monthly
> for dropped servers and try the ones closest to you, although the
> furthest may only be a few hundred milliseconds away).
> 
> 2  If you can afford a VPN service good for you.  For the less
> privileged (like 96% of the planet) there is calyx.net and bitmask.net
> https://bitmask.net/en/install/linux#debian-packages or you can download
> a standalone package.  There is also a testing-beta 0.9.4 version.  This
> is a project by Leap.se and has made this open source code available and
> is begging to be forked.  It is like openVPN for dummies (like some of
> us).
> 
> 3  tor by torproject.org is open and free just like Debian That is why
> Debian only works with torproject and not just any other tor software. 
> And all of them will tell your they work better!  Tor is a network which
> you need special configuration to enter (and exit) safely.
> Everything you wanted to know and were afraid to ask:
> https://onion.debian.org/
> 
> Once you get tor running and install tor-browser you may also add the
> torproject.org repository as well.  Since you are using it you might as
> well use onion addresses to replace all repositories (Debian and Tor)
> 
> *** ... once you have the "apt-transport-tor" package installed, the
> following entries should work in your sources list for a stable system:
> (change the stretch to jessie stable testing sid ... or what you have)
> 
> deb 1 tor+http://vwakviie2ienjx6t.onion/debian stretch main deb 2
> tor+http://vwakviie2ienjx6t.onion/debian stretch-updates main deb 3
> tor+http://sgvtcaew4bxjd7ln.onion/debian-security stretch/updates   
> main deb 4 tor+http://vwakviie2ienjx6t.onion/debian stretch-backports
> main deb 5 tor+http://sdscoq7snqtznauu.onion/torproject.org/ testing
> main
> 
> Remember the tor-transport package mentioned above is essential for any
> of them to work and a live tor connection.  If tor daemon has stopped
> all those addresses will run into an error.
> You can also add the deb tor+http://debian...  or any other non onion
> address and that works too.
> 
> 
> 4  And if all this wasn't enough ..... there is MORE!  Try
> sandboxed-tor-browser in its 3rd current beta version.  It is just like
> the tails tor-browser that can not see beyond its own sandbox (the
> Amnesia sandboxed disk within your disk).
> 
> 5  None of this stuff make any sense if you are enabling scripts and
> going to googlefatsbookyoohooemesen ... crap sites!  You are defeating
> the purpose of anonymity and privacy.  Do not abuse sensible freedom!
> All debian websites do not require any scripts to be accessed and read.
> Most respected websites (non-invasive) are the same way.  Those you can
> not reach (it gets cloudy out-there) you don't want to read any way.
> 
> 6  If you want to test your browser for torification use
> check.torproject.org If you want to check the configuration of other
> browsers and their effective ability to cover themselves use eff.mozilla
> https://panopticlick.eff.org/ but it doesn't mean much as it is compared
> with a huge amount of non-tor browsers.
> 
> This project browserprint.info seems to be doing part of the same and
> more but more directed to tor browsers.  The score is getting better
> with every new edition of tor-browser.  The more unique your fingerprint
> the easier for little-big-sisters to tell who you might be and what are
> you up to.  So, you want to blend in with the fish, not stick out.  You
> might hear that "the old tor was better than the new one, I am sticking
> with the older version" and that is crap.  As 99% are updating to the
> latest your trusty old tor-browser will stick out like a shore thumb!
> 
> 7  If you are using icedove/thunderbird for mail disable all your
> plugins and install tor-birdie which prohibits your mail-system to
> communicate without tor.  Nothing comes-in nothing comes-out if the tor
> connection has been dropped.
> 
> 8  There is also tor-chatting and messaging and all kinds of other stuff
> I do not use.
> 
> 9  Don't expect Neo to come, save yourself!
> 
> Peter Ludikovsky:
>> Hello,
>> 
>> First things first: AFAIK, just installing privoxy doesn't make it use
>> Tor, it just acts as a regular proxy. Visit [1] to see if you're using
>> Tor or not. In order to enable chaining through Tor you'll have to have
>> a line like
>>   forward-socks5	/	<ip>:<port>
> 
> I used socks5://127.0.0.1:9050 on midori and the score sucked on the
> above mentioned uniqueness profiler.
> 
>> Or, you could install the torbrowser-launcher[2] package, which
>> contains everything preconfigured for browsing.
> 
> It is the only safe way to go, any deviation from the prescribed is
> risking anonymity.  You might as well not use any of this stuff.
> 
>> Regards,
>> /peter
>> 
>> [1] https://check.torproject.org/
>> [2] https://packages.debian.org/jessie/torbrowser-launcher
> 
> Read this too:
> https://guardianproject.info/2016/07/31/howto-get-all-your-debian-
packages-via-tor-onion-services/
> 
>> Am 17.03.2017 um 19:28 schrieb Glenn English:
>>> I'm trying to use the Tor Browser. They don't seem to have any support
>>> (beyond an FAQ) on their site, so I'm asking here.
>>>
>>> Jessie and XFCE on a Supermicro workstation connected through a T1.
>>>
>>> I installed Tor a few days ago and it was working fine -- Gmail said
>>> it was having authentication problems and that I was using Firefox on
>>> Winders in Paris. Just what I'd hoped for.
> 
> Get some real mail and leave the G for nonsense ...  Once your real
> location and identity is recorded ... any attempts to identify or cover
> yourself up from such companies are meaningless.  Just separate your
> private life from the "open and free" commercial services.  Move on,
> there is nothing to see there :)
> 
>>> So I removed privoxy, and now Tor can't even connect to its own
>>> network.
> 
> Just do a reinstall by forget the standalone apps, do it through apt
> apt-get synaptic system installation.  Make sure you get all the gpg
> keyring stuff done right.  Once the system has safely got tor-daemon
> running the first attempt to start the browser will open up a gui with
> options (make sure you enable the sound part :) it will download the
> browser safely through tor, which means it verifies its structure hasn't
> been altered on its way to you.
> 
> Imagine living in a country that is not as free as the US (goughh,..
> ghhgh.. bwwraaahhh..) that even reaching a tor gateway needs some bridge
> somewhere because all other entry points are blocked by the government's
> networking.  If government agents and large corporation executives
> wouldn't rely so much to the safety of this network it wouldn't exist.
> They don't want their anonymity but they sure do want their own.
> 
> Peace (by any means necessary)
> kAt
> 
> PS  Do not watch Snowden videos with Tor ...  with your Gmail logged in!

Really nice post, thanks:
I have one [OT] question, i use Wheezy at work, but i tested Kodachi a 
Debian derivative, and it took the HWID! Is it a security problem? Well, 
a second question, are you saying, that when i use Tails, i must not 
permit scrips? 

Lat

[toc] | [prev] | [next] | [standalone]


#179017

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-03-19 20:50 +0100
Message-ID<tmOZX-1WN-3@gated-at.bofh.it>
In reply to#179010
Latincom:
> 
> Really nice post, thanks:
> I have one [OT] question, i use Wheezy at work, but i tested Kodachi a 
> Debian derivative, and it took the HWID! Is it a security problem? Well, 
> a second question, are you saying, that when i use Tails, i must not 
> permit scrips? 

Some of those systems are meant to run live or in vm and not installed
on the hd.  I don't know about Kodachi but tails is basically a debian
package hardened into a live system with networking restricted through
tor.  It allows you to make a conscious decision and use the "unsafe"
browser, which is more unsafe than tbb with scripts enabled.  So I will
propose to you to ask yourself, are those who you trust requiring you to
enable scripts to read their information or participate in a forum?
So, what is it they don't understand?  Aaaahhh!!  Stick with debian!
>From your debian repository you can install forum, webmail, webpage,
servers that function perfectly without scripts.  So the question that
comes to mind is does it have to be this way?
enlacezapatista.ezln.org.mx/2013/01/27/them-and-us-v-the-sixth#it
doesn’t have to be this way


I am not 100% sure of the internals of all this, I say what I trully can
understand.  Can you mount your hard drive through the use of tails?
Can you read data off of it?  If by enabling scripts you indirectly
allowing an application to open ports on networking that were otherwise
shut.  Then data from you hd could  potentially pass through on the
network.  What may be encrypted beyond your machine or your lan is not
encrypted within your machine.  You can read it.  And you can never ever
be sure who is on the other side of the connection ... can you bet your
children that wikipedia today is what it was and it is not a wikipedia
to you looking like a wikipedia?

There is no limit to how paranoid you may get in digital systems when
even your physical surroundings provide plenty of grounds to be paranoid
about.  You just take some "relative" good measures appropriate for your
use based on a general consensus of those who deal with "the problem".
Your definition of the problem is the definition of what you consider
safe.  Some distrust big-profitable corporations and distrust
governments.  Some are exactly the opposite.  Some don't trust either
but consider their political/religious safe-heavens to trust.  And then
there are those that do not really trust anything and anybody, and
although I feel bad for them they have already lost in their own
personal nightmare game.  So, how many lights do you see Jean-Luc?  Stay
with us!

There is what some may call ethical hacking which has stricter moral
code than the Vatican, Jerusalem or Mecca combined. And then there is
the scum of the earth who deal in child exploitation, of lives and
exchange of contraband that benefit from all this.  To answer some of
these questions is to provide the child molester or the non-adult
traffickers and poison distributors the tools to be more effective.
Which is a moral dilemma.  You can destroy a life with a hammer and the
hammer is perfectly legal and socially acceptable, as a tool.

> Lat

kAt

-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web