Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jlund
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
jlund
11y ago
Helping people get around the Great Firewall was one of the main reasons I started working on Streisand[1]. OpenVPN (wrapped in stunnel), Shadowsocks, and Tor (with obfsproxy) are all still highly effective. The setup process is completely
32.
▲
by
jlund
11y ago
I wanted this article to be about encryption.
33.
▲
by
jlund
12y ago
Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal. In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successf
34.
▲
by
jlund
12y ago
That's like saying that SSH isn't more secure than Telnet unless you personally drive to the data center and verify the fingerprints of every single server by hand. In reality, TOFU is a form of key verification and it is highly e
35.
▲
by
jlund
12y ago
You can install Signal on a WiFi-only iPad and use any phone number to register. This will also be the case for the upcoming desktop client.
36.
▲
by
jlund
12y ago
TOFU has proven to be quite resilient against MITM attacks. Do you think it's a stretch to say that SSH is secure?
37.
▲
by
jlund
12y ago
MMS messages are sent and received by your cellular carrier.
38.
▲
by
jlund
12y ago
Signal ties into your phone's existing address book. You can add someone new using the iOS Contacts application.
39.
▲
by
jlund
12y ago
Keys are trusted on first use, similar to SSH. The app also provides an interface you can use to verify fingerprints: https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-...
40.
▲
by
jlund
12y ago
The DigitalOcean provisioning issue was recently fixed, and creating new droplets is working properly. Making the mirroring segment more resilient to failures is high on my list of priorities. Thanks for the positive feedback!
41.
▲
by
jlund
12y ago
That's correct. Android will warn you if the signatures don't match too. Even if we're in the full-on conspiracy theory territory of Google disabling that core security feature, impersonating a third-party developer, and drop
42.
▲
by
jlund
12y ago
Except for the fact that Google does not have the signing keys that are used for the TextSecure binaries. They cannot silently distribute a binary that has been tampered with. This distributed trust system is one of Android's strengths
43.
▲
by
jlund
12y ago
It works great on micro instances. That's actually the default option for new EC2 instances that it creates.
44.
▲
by
jlund
12y ago
I honestly hadn't even heard of AAA in the context of RADIUS before reading about it on Wikipedia just now. I only tangentially know about RADIUS from seeing it in various WiFi control panels over the years. I considered using Squid so
45.
▲
by
jlund
12y ago
Thank you. I'm using Ansible's vars_prompt functionality to ask for these values. I'm not sure if there is a way to skip a prompt if the information is already available. I don't think there is right now, but Ansible is
46.
▲
by
jlund
12y ago
I haven't ever done anything with port knocking before, but it's a neat idea that could also be entertaining. It's worth pointing out that most of the services Streisand sets up have already been configured with countermeasur
47.
▲
by
jlund
12y ago
That would be extremely cool. Maybe someday! I meant that people can easily start more servers when a censorship event happens.
48.
▲
by
jlund
12y ago
You are very welcome! Please let me know if you have any feedback or suggestions after you give it a shot. It sounds like you might be in a country where deep packet inspection is happening, and you are exactly the type of person I am hopin
49.
▲
by
jlund
12y ago
Yes. OpenVPN (wrapped in stunnel), OpenSSH, Shadowsocks, and Tor (with the obfs3 and ScrambleSuit pluggable transports) are all effective against the Great Firewall. Streisand sets up and configures all of them.
50.
▲
by
jlund
12y ago
No problem. I totally understand. I intentionally made it really easy to override the default values that I chose for port numbers. It wouldn't be difficult to mix those up in the future, if necessary. I did my very best to make sure t
51.
▲
by
jlund
12y ago
Thanks! Bandwidth usage would probably become a limiting factor before CPU. It also depends on which mix of services was being used. The services are all lightweight enough that I don't think you'd have any issue with lots and lot
52.
▲
by
jlund
12y ago
Very cool! I'll try to find some time to test the other providers, and assuming everything looks good then I can add a link to this in the README.
53.
▲
by
jlund
12y ago
Ha! This is going to be stuck in my head all day now.
54.
▲
by
jlund
12y ago
It sets up a new server running L2TP/IPsec, OpenSSH, OpenVPN, Shadowsocks, Stunnel, and a Tor bridge. It also generates custom configuration instructions for all of these services. At the end of the run you are given an HTML file with
55.
▲
by
jlund
12y ago
Thanks for the feedback! I'm excited to see how people use this and what new features might be helpful for them. I will be sure to incorporate that information into the README.
56.
▲
by
jlund
12y ago
I just pushed a fix for this. If you pull, you should be good to go. The bug was introduced in the new version of Ansible that came out two days ago. I didn't catch it because I hadn't updated quite yet. Sorry about that! Edit: I&
57.
▲
by
jlund
12y ago
I will add this to the README. Thanks!
58.
▲
by
jlund
12y ago
That's a great idea. Ansible doesn't natively support those providers through an official API yet, but I don't think it would be difficult to do. I will look into it! For now, Streisand can execute on any standard Debian 7 se
59.
▲
by
jlund
12y ago
I am happy to answer questions about this, if anyone has any. Or if anyone finds any bugs or has other feedback, that would also be great.
60.
▲
Show HN: Streisand – Silence censorship, automate the effect
(github.com)
234 points
by
jlund
12y ago
|
52 comments
More ›