Hacker Newsnew | past | comments | ask | show | jobs | submit | cmars's commentslogin

I made a little utility for tunneling with the Tor daemon. Check out https://github.com/cmars/onionpipe.

onionpipe forwards ports on the local host to remote Onion addresses as Tor hidden services and vice-versa.


I've been researching altcoins, and RaiBlocks sounds interesting.

xrb_3wq3d975sq1oef7y35mzakrywke18hab85g548wkshu61pec4fxkixbwhr48

Thanks!



In a forward-secure manner?


> Tor onion services solve the setup-your-own-server issues, it's just not super easy yet.

Lately I've been trying to make this easier. I developed ormesh (https://github.com/cmars/ormesh) in an attempt to simplify setting up hidden services for private use.

I think both Tor and IPFS are both awesome and useful decentralization projects, they just have different use cases & characteristics. AIUI IPFS lacks fine-grained access controls. Last time I looked, it seemed like I either had to run all my own infrastructure of IPFS nodes with pre-shared private keys, or open everything to the public and encrypt on top of that... I prefer the Tor hidden service model, where I can decide on a per-service basis how I want to share it, revoke client access if necessary, and have my traffic securely routed on existing infrastructure.

Edit: fixed link


Saw this on /r/golang (I was the one asking why the full Tor browser). I have considered similar [0]. A simple service (or portable exe) that has Tor statically linked and lets you reach/manage a machine from anywhere (think webmin-like web console on onion service) would have real value. Of course it can be authenticated and have the option to open direct connection (webrtc?) if you need fast media playing or direct download.

0 - https://github.com/cretz/software-ideas/issues/54


I feel the same way about depending on, and routing my traffic through third-party services.

I've recently developed a utility[0] to help simplify setting up hidden services w/client auth for this purpose, you might find interesting.

[0] https://github.com/cmars/ormesh


There was some controversy [1] [2] about Nokia decrypting SSL connections for their accelerated browser. Not familiar with their platform, or whether you could remove them, but Nokia proxy certificates are certainly being trusted by default.

If you're this paranoid, build one of those laser cut Arduino GSM phones instead[3]. You could add your own discreet baseband kill switch.

[1] https://gaurangkp.wordpress.com/2013/01/09/nokia-https-mitm/

[2] https://freedom-to-tinker.com/blog/sjs/how-the-nokia-browser...

[3] http://web.media.mit.edu/~mellis/cellphone/


Lately I have been feeling we as builders had this responsibility to build the Internet that the world needed, and we failed. We were distracted, we got rich, we ignored or misread the needs of our fellow humans.

The walled gardens that we now find so insidious and creepy are due to our own failure to empower the users. We made HTTP, SMTP, XMPP protocols. Large companies brought these to the masses, in ways the masses can understand and interact with in their limited capacity... for a price.

Can we reclaim humanity's birthright? Can we build a vision of the world we wish to live in, that is accessible to and understandable by many? Or is our entire collective fate to become a monetized click stream of suckers?

This article names Google, but to me that is beside the point. Google is a large system set in motion by shareholders and market forces that has equilibrium. It consumes click streams and subscriptions, and excretes money, like others of its kind. Can such an organism ever serve the best interests of humanity all the time?

If you find yourself hating Google, better to look within yourself. Do you have the courage to walk away from these kinds of services and build an alternative, however humble it might be, that empowers and liberates your fellow humans?

I am still working on this in myself. My email is still gmail, I would miss some personalities in my G+ circles, but I am uncomfortable, and I find current trends unsettling.

(edited for grammar)


It's just a click. For it to matter so much whether I am clicking this link or that link with the right intent, that all this supposed meaning and morality hangs in the balance, that it could make all this difference, it all seems so absurd. Almost makes me want to disable ABP, Allow Scripts Globally (dangerous), shut my eyes, and just start clicking. None of it really matters.

Eh, I think I'm done with the Internet for today. Might run afoul the click police.


> It's just a click [...] that it could make all this difference, it all seems so absurd

It makes more of a difference to an advertiser than your vote makes in the presidential elections. Do you vote?

Also, keep in mind that the largest part of the money you just "donated" goes to Google and not the web publisher.


Same here:

  Linux (redacted) 3.2.0-41-virtual #66-Ubuntu SMP Thu Apr 25 03:47:17 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux

  [  413.309308] BUG: unable to handle kernel paging request at 0000001781eef4e8
  [  413.310359] IP: [<ffffffff8108d605>] atomic_dec_and_mutex_lock+0x15/0xa0
  [  413.311025] PGD 1c4ec067 PUD 0 
  [  413.311680] Oops: 0000 [#6] SMP 
  [  413.312007] CPU 0
Edit: disregard the timestamp above, VM has not synced with NTP for some time.


Frankly, I have to apologize I've never bothered with testing on ubuntu. That niche (workstations and small servers) is different beast for somebody else to bite.


So, the question is, are we safe this time? Or do we just need a better exploit code to be written for us? :)


just need better exploit code


citation needed


One strong drink is enough for me, so I just tip 100% at the local place where I regularly camp -- whether I'm camping or picking up a drink. If your coffee shop is near a university, bring your regular barista something nice, some food, etc. during finals. He or she is probably pulling doubles. This is coming up soon...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: