Sunday, 18 November 2007

Potential Firefox Leak

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

As Matt reported in his/her/their blog there are interesting privacy-implications for torbutton-users with the way firefox loads favicons.

Usually I would link but because the article is in torland I repost it here:



Potential Firefox Leak (18 November 2007)
I have discovered a potential leak with any version of firefox (current version as of writing is 2.0.0.9).
The Problem:
Every time you switch tabs, firefox will automatically load the favicon.ico for web sites that did not have one the first time it tried retrieving it (if it's not there the first time, why would it be there later?). If you have multiple tabs open -- some initially loaded with tor enabled (torbutton) and some loaded with tor disabled -- every time you alt+tab or click on a different tab with Tor disabled, firefox is automatically (and without your knowledge) connecting to each site that did NOT have an icon on its initial load. This means that you are revealing your IP address to anyone when you have tor disabled, even when you don't reload any tabs or visit any web sites. Additionally, if you do the inverse (tor enabled with a few non-tor tabs open) you will be revealing that you use tor to any web sites you normally have tor off for.

This problem is not a bug in torbutton, but a bug in firefox that was probably there at one point as a "feature," but is effectively useless.

Workaround:
Close all tabs before toggling torbutton!

Mozilla developers: You can remove that stupid and pointless repeated favicon.ico loading. If it wasn't there 30 seconds ago, why the hell would it be there now? Load it only when the web site is initially loaded and when the tab is refreshed.

- --Matt

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD4DBQFHZ6cSLAZ+Vq4hPgARAoRRAKDc9YKJntY2doXyAoMM3O1nmLIpBACVFxXf
OHgxnM3ja9bGS1R0RD5bGg==
=9L31
-----END PGP SIGNATURE-----

Sunday, 16 September 2007

Mixminion 0.0.8alpha3 releases

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Today version 0.0.8alpha3 of the Mixminion type III remailer was released.

A few bugs that could crash your server where fixed.

- From the announcement:

NEW IN VERSION 0.0.8alpha3:
- Create .mixminion directory even when we try to lock before accessing
it: This prevents "update-servers" from crashing when run without
a .mixminion directory.
- Don't die when gzip compression on a downloaded directory is corrupt.
- Don't die when an incoming connection closes before we can get its
address.
- Do not believe any path specifier that results in an impossibly short
path.
- Bump preferred openssl version to 0.9.8e.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6bnLAZ+Vq4hPgARAmmvAKC8XCDGrA3NJGLqCYr4YDew/4DDgQCfalj1
HqloLpkcNSzcXG/3+xXRzd4=
=crc2
-----END PGP SIGNATURE-----

Thursday, 19 July 2007

new Frost-Release

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

A new release of Frost, the anonymous message-board and file-sharing via the Freenet-Project has been released today.

The website states "This release introduces new features and many fixes. You really should update."...so you should do so. ;)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6bbLAZ+Vq4hPgARAs54AJ0Z/6imTJ2zlXKm/77QpHeFWC5glACfe6Pp
/L5+nsKJ+u1kDzeim5W5c5g=
=oMDZ
-----END PGP SIGNATURE-----

Wednesday, 13 June 2007

Hawala - anonymous money transmission

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

We/I would like to draw your attention to the following articles
as they address the often discussed topic of anonymous money-transmission.
Advantages:
usually anonymous
better exchange-rates
lower fees
sometimes faster
sometimes more reliable
(compared to traditional banks)

Names to look for:
Hawala

Synonym:
Hundi
havala

Alternatives:
Asia: chop
Asia: chit
Asia: flying money
Kolumbia: The columbian system

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6bPLAZ+Vq4hPgARAnDwAKCu4n2uHn7IrX4yRAcp6Ne69OdZ1QCfTY52
Od1eGUAeXoEpL9exuGBq3I0=
=lO0P
-----END PGP SIGNATURE-----

Monday, 11 June 2007

eyeOS

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

A few days ago we found a very nice service allowing us to use
desktop-like application in a browser anonymously.
It works a bit faster then google and you don't have to have
a google-account with cookies and everything.

You can use it on your own php-webspace if you find
one of the many small free-hosters or use the hosted
eyeOS on the developers page.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6atLAZ+Vq4hPgARAquMAKCdj2/Q2EyTbLB4hxo9jG2jVhfEvQCg3ru5
aHkd90igEl6OolhGjDdEvCI=
=KMyq
-----END PGP SIGNATURE-----

trying for php+mysql-hosting

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

To see if we/I can offer anonymous php- and database-backed services
I/we are currently trying to register at 110mb.com .
Registration is only open at random times to limit the number of registrations.
Same with uttx.net.
Thus we will have to wait....


..stay tuned.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6acLAZ+Vq4hPgARAgt4AJ9VG7FVO3cGFxFkLSIUVljnqTaB6QCfRays
6ubZA7hsFGNid8t4uhFaFGY=
=n26D
-----END PGP SIGNATURE-----

Friday, 1 June 2007

german election-computers unsafe

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Chaos Computer Club germany just published a paper (in german) about how the german version of the nedap election-computer could be hacked, how ineffective the security of the elections was and that the last elections can very well be completely manipulated and we have no way to know.

Sorry, german only.




Here are the final words of the report:

11. Fazit
Die Analyse der NEDAP-Wahlcomputer hat zu einer Widerlegung der Behauptungen des Herstellers, des BMI und der PTB über die Sicherheit des Systems geführt. Im Rahmen der Untersuchungen wurden mehrere sehr unterschiedliche Angriffsklasse
n gefunden und implementiert, die jede für sich genommen schon zur Rücknahme der Bauartzulassung hätte führen müssen.


  • Die Untersuchung hat gezeigt, daß: · die Software der Wahlcomputer problemlos manipulierbar ist, · Manipulationen an
    der Hardware einfach möglich sind,

  • · die Programmier- und Auswertesoftware in einfacher Weise angreifbar ist,

  • · die Zulassungs- und Prüfverfahren ungeeignet sind, Manipulationen aufzudecken,

  • · die Annahmen des BMI und der PTB über mögliche Wahlfälscher unrealistisch sind,

  • · die aus diesen Annahmen resultierenden Anforderungen und Maßnahmen (,,geschützte Umgebungen") unwirksam sind,

  • · Versiegelungen und Plomben keinen wirksamen Schutz bieten,

  • · dem Wähler eine effektive Kontrolle und Verifikation der Wahl nicht mehr möglich ist,

  • · neue Risiken und Angriffsmethoden fortlaufend entstehen,

  • · im internationalen Vergleich eher die Abschaffung als die Einführung von Wahlcomputern als sinnvoll erachtet wird und

  • · eine Manipulation der Wahlcomputer zur Bundestagswahl 2005 nicht mit Sicherheit ausgeschlossen werden kann.



Die Untersuchung zeigt exemplarisch die prinzipiellen Schwierigkeiten bei der Verwendung von Wahlcomputern, unabhängi
g von der Bauart. Keines der Probleme ist auf technischem Wege mit ausreichender Zuverlässigkeit lösbar, da mehr technische Sicherheitsmaßnahmen zwangsläufig zu komplexeren Systemen führen, die von noch weniger Menschen verifiziert wer
den können. Wenn der geringe Nutzen und die erheblichen Risiken objektiv gegenübergestellt werden, erscheint es sinnvoll, von der Nutzung von Wahlcomputern zukünftig abzusehen und beim nachvollziehbaren und bewährten Wahlverfahren mit
Papier und Stift zu bleiben.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: http://firegpg.tuxfamily.org

iD8DBQFHZ6aRLAZ+Vq4hPgARAk6FAKCt3dYxH67hkOa4evlR8rRwoc62OgCfar+M
zO9OFXwhxD/ZLolFr0dB5oY=
=pZpZ
-----END PGP SIGNATURE-----