VPN, privacy & Firefox (+ other Gecko browsers)* rev. 0.3.13

[chan] Crypto-Anarchist Federation
Nov 13 10:51

+----------------------------------------------------------------------------------+ | VPN, privacy & Firefox (+ other Gecko browsers)* rev. 0.3.13 | +----------------------------------------------------------------------------------+ ========== VPN section ========== + You can try free OpenVPN configs or Softether: + OpenVPN: - OpenVPN - you can edit configs (.ovpn) with notepad to change encryption (line 88 - standard is not so good: AES-128-CBC - try AES-256-CBC instead) - OpenVPN - you can edit configs (.ovpn) with notepad to add option "block-outside-dns" (for example in line 104) to avoid DNS leaks - OpenVPN - if you add option "block-outside-dns" you can avoid "DNS leaks" & you don't need (Simple) DNSCrypt (my testing suggest that when you using OpenVPN without "block-outside-dns" option together with Simple DNSCrypt you are affected by DNS leaks) (Simple DNSCrypt not working for me, anyway this needs further testing...) - OpenVPN - you can edit configs (.ovpn) with notepad to add option "--remote-cert-tls server" (for example in line 21) to avoid "Man-in-the-Middle" attack https://openvpn.net/index.php/open-source/documentation/howto.html#secnotes [OpenVPN 2.1 and above] - https://www.vpnbook.com/ (few free OpenVPN configs) - http://www.vpngate.net/en/ (a lot of free OpenVPN configs) + OpenVPN manuals: - https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage - https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage - https://openvpn.net/index.php/open-source/documentation/howto.html - https://openvpn.net/index.php/open-source/documentation/security-overview.html + Softether: - http://www.vpngate.net/en/ - I recommend to try DNSCrypt to avoid DNS leaks (check your DNS leaks - links are below) - Changed the default algorithm for SSL from RC4-MD5 to AES128-SHA - http://www.softether.org/5-download/history - http://www.softether.org/1-features/3._Security_and_Reliability + Softether disadvantages: - logging policy: 2 weeks [default] - when you will be disconnected then your IP will be exposed (there is no 'kill switch' feature) - DNS leaks... + Security of popular algorithms: - https://en.wikipedia.org/wiki/RC4#Security - https://en.wikipedia.org/wiki/MD5#Security ========== Browser section ========== + Secure your privacy in Firefox: - by using addons like in IceCat [https://directory.fsf.org/wiki/IceCat] I mean: Adblock Plus (ABP), Disable WebRTC, Fat-Free Fox, No Resource URI Leak, NoScript, Privacy Badger, uBlock Origin (uBO), uMatrix etc. Additionally you can add: CanvasBlocker, Disconnect, FoxyProxy, Https Everywhere, Privacy Settings, Random Agent Spoofer. Take a look @ these sites: - https://web.archive.org/web/20170404173124/http://b.agilob.net/better-security-privacy-and-anonymity-in-firefox - http://configfox.sourceforge.net/ - https://www.bestvpn.com/make-firefox-secure-using-aboutconfig/ - https://www.bestvpn.com/privacy-news/control-firefox-privacy-settings-with-an-add-on/ - https://vikingvpn.com/cybersecurity-wiki/browser-security/guide-hardening-mozilla-firefox-for-privacy-and-security - https://www.howtogeek.com/102032/how-to-optimize-mozilla-firefox-for-maximum-privacy/ - http://www.ghacks.net/2015/07/01/control-privacy-settings-in-firefox-easily/ + If you would like to use Google Chrome anyway you can replace it with Chromium or Iron: - https://en.wikipedia.org/wiki/Chromium_(web_browser) - https://en.wikipedia.org/wiki/SRWare_Iron + Use Tor or Tor Browser (based on Firefox): - "We will never be able to de-anonymize all Tor users all the time. • With manual analysis we can de-anonymize a very small fraction of Tor users" - https://edwardsnowden.com/docs/doc/tor-stinks-presentation.pdf‎ - https://commons.wikimedia.org/wiki/File:Tor_Stinks.pdf - https://en.wikipedia.org/wiki/Tor_(anonymity_network)#Tor_Browser - https://www.torproject.org/docs/tor-manual.html.en - https://www.torproject.org/docs/faq.html.en - https://blog.torproject.org/improving-tors-anonymity-changing-guard-parameters + SSH/SOCKS/proxy: - Privoxy - https://en.wikipedia.org/wiki/Privoxy - https://lifehacker.com/5763170/how-to-secure-and-encrypt-your-web-browsing-on-public-networks-with-hamachi-and-privoxy - https://lifehacker.com/237227/geek-to-live--encrypt-your-web-browsing-session-with-an-ssh-socks-proxy - https://outflux.net/blog/archives/2006/12/07/paranoid-browsing-with-squid/ - https://embraceubuntu.com/2006/12/08/ssh-tunnel-socks-proxy-forwarding-secure-browsing/ - https://pl.terminal28.com/instalacja-i-konfiguracja-squid3-tor-privoxy-anonimowosc-w-sieci [translate with your favourite translator] - https://www.reaper-x.com/2011/10/17/how-to-install-squid-proxy-on-windows/ - https://www.unixmen.com/install-configure-squid-proxy-ubuntu-debian/ - https://www.cyberciti.biz/faq/debian-ubuntu-linux-install-onionrouter-software/ - Pirate Tor Browser - http://www.softpedia.com/get/Internet/Browsers/PirateBrowser.shtml or http://www.majorgeeks.com/files/details/piratebrowser.html + Change your UserAgent frequently (get UA addon for your browser). Example of UA sites: - Random Agent Spoofer addon for firefox: https://addons.mozilla.org/en-US/firefox/addon/random-agent-spoofer/ List of UA sites: - http://www.browser-info.net/useragents - http://mybrowseraddon.com/custom-useragent-string.html - https://developers.whatismybrowser.com/useragents/explore/ - https://udger.com/resources/ua-list - https://techblog.willshouse.com/2012/01/03/most-common-user-agents/ - http://www.useragentstring.com/pages/useragentstring.php + Fingerprint (fingerprinting algorithms): - https://en.wikipedia.org/wiki/Fingerprint_(computing) - https://en.wikipedia.org/wiki/Canvas_fingerprinting - https://en.wikipedia.org/wiki/Device_fingerprint - https://browserleaks.com/canvas + Check your browser privacy/security: - https://browserleaks.com/ - http://browserspy.dk/ - https://panopticlick.eff.org/ - https://www.howsmyssl.com/ + Other sites worth mentioning: - riseup.net/en/better-web-browsing - privacytools.io - https://en.wikipedia.org/wiki/Category:Internet_privacy - https://en.wikipedia.org/wiki/Category:Crypto-anarchism ========== OS section ========== + Check Tails Linux: - https://en.wikipedia.org/wiki/Tails_(operating_system) - https://www.wired.com/2014/04/tails/ + Check Whonix Linux: - https://en.wikipedia.org/wiki/Whonix - https://www.whonix.org/ + Secure you DNS with DNSCrypt: - For Linux follow this: http://www.webupd8.org/2014/08/encrypt-dns-traffic-in-ubuntu-with.html - For Windows - you need: "dnscrypt-winclient" or "Simple DNSCrypt". URLs: - https://simplednscrypt.org/ - https://github.com/jedisct1/dnscrypt-proxy/wiki - https://github.com/Noxwizard/dnscrypt-winclient (Simple DNSCrypt not working for me (I'm still using "block-outside-dns" option in OpenVPN config file). (Anyway this needs further testing...) + Check your DNS leaks: - https://ipleak.net/ - https://www.dnsleaktest.com/ - https://whoer.net/ ========== P2P section ========== + Use peerblock - https://en.wikipedia.org/wiki/PeerBlock + Use ipfilter.dat - for example: ed2k://|file|ipfilter_v0153.dat|19871409|93474AE3F1D3A0A7C4EEC7E52A146721|/ __________________________________________________________ * Other Gecko browsers - this means it may also work with: Airfox, Beonex Communicator, Camino, Comodo IceDragon, Conkeror, Classilla, Firefox for Android, Flock, Galeon, Ghostzilla, HP Secure Web Browser, IceCat (GNU IceWeasel), K-Meleon, Kazehakase, Kirix Strata, Lotus Symphony, Lunascape, MicroB, Minimo, Netscape 6, Nightingale, Oxygen, Pale Moon, Portable FireFox, SeaMonkey, Swiftfox, Swiftweasel, Sylera (for mobile), TenFourFox, Timberwolf (AmigaOS 4), Tor Browser, Waterfox, xB Browser https://en.wikipedia.org/wiki/Gecko_(software) Any suggestions are welcomed. Source: https://beamstat.com/chan/privacy https://beamstat.com/chan/Crypto-Anarchist%20Federation (Bitmessage channel)

[chan] Crypto-Anarchist Federation
BM-2cWdaAUTrGZ21RzCpsReCk8n86ghu2oY3v

Subject Last Count
NSAtan: From my diary [redacted] Jan 22 07:03 1
FINALLY FOUND A REAL HACKER Jan 21 18:20 1
What is secure? Jan 20 14:39 2
Anonymous VCS Jan 18 17:42 1
OMEGA release 41 is available for download Jan 18 17:12 1
forbidden information & darknet directory assistance Jan 18 04:34 1
Public announcement Jan 17 05:19 5
[chan] 411 BM-2cW53MzWqtod8TA6vybdUeqd2LhTuXCX3L Jan 17 01:05 1
An Inside Job: Remote Power Analysis Attacks on FPGAs Jan 16 14:05 1
Guy Carr: Globalists are Satanists Jan 14 22:28 1
Crypto-Anarchists should sign the petition allowing Julian Assange to be pardonned by US Government. Jan 12 08:26 68
WARNING : Problem with Matrix Invite from Komona comrades from 34C3 Jan 11 19:19 1
New functionality request for BitMessage after the trolling of nazi feds of yesterday. Jan 11 18:34 12
Help Fight Government Tyranny Jan 11 13:22 1
join the antifa Jan 11 09:12 6
Andrew Escher Aurenheimer (Weev) exposed Jan 11 03:25 1
TinyFPGA Computer Project Board Jan 9 01:10 1
c. Jan 9 00:08 6
Introducing Twister, the 100% P2P & fully decentralized Twitter clone, similar technologicaly and architecturaly to BitMessage, for being fully decentralized. Jan 8 04:45 2
Request for private exchange with Mr. J Jan 7 19:16 3
looking for website Jan 7 15:22 1
I am still looking for Timo from Komona #34C3 Jan 7 06:40 2
Introducing the Crypto-Anarchist tool GitTorrent, a true 100% P2P & decentralized tool to securely host source code of other Crypto-Anarchist projects. Jan 7 01:22 5
Fingerprinting Jan 7 00:45 1
#Meltdown and timing covert channels. Jan 6 12:43 1
looking for code repository - alt.binaries on news.atman.pl :119 Jan 6 08:30 5
Cryptofon Jan 6 07:49 5
ohai Jan 5 21:35 1
Microprocessor Hardware backdoors updates. Jan 5 17:27 7
Variable and machine generated secret ciphers Jan 4 13:55 1
Updated: STATBOT v0.0 : pings other STATBOTS to measure bitmessage transit times Jan 4 08:48 1
Genghis says: github mangles statbot source code Jan 4 06:04 1
For the new comrades joining this Crypto-Anarchist Federation chan. Jan 4 00:51 12
BitMessage Channels List (Some new folks asked) Jan 4 00:47 3
Crypto-Anarchist guy was always right... Jan 3 14:59 1
Snowden Files at ZeroNet :-) Jan 3 12:31 1
Crypto-Anarchist protection tool : Professional / Military grade double faraday cage for mobile phone / smartphone. Jan 3 12:16 1
Cool FPGA tools & boards (Many models, trademarks, and cool stuff, like FPGA based Raspberry Pi clone) hacktivist & vendor I meet at #34C3 Jan 3 11:30 1
Need advice: intel T2330 dual-core CPU compromised? Jan 3 09:41 9
looking for code repository Jan 3 09:36 2
"Security Message" for the "Crypto-Anarchist / Anarchist" Community on #BitMessage. Jan 3 00:27 1
Looking for Timo I meet at 34C3 ! Jan 2 11:46 1
Happy New Year, chan!!!! Jan 1 17:43 12
OMEGA release 40 is available for download Jan 1 17:33 1
what's going on in this chan Dec 31 14:30 11
Crypto-Anarchist Federation Dec 30 23:05 1
Genocidal Jewish Privilege on Full Display Dec 30 05:56 1
On Richard Spencer's Degenerative Jewish Philosophies Dec 30 05:33 1
Ethereum Occult Symbol #2 Dec 26 14:58 9
NSA invented Bitcoin in 1996 -- 22 years before CIA released it Dec 26 08:46 1
Ethereum Occult Symbol #3 Dec 26 08:40 1
Ethereum Occult Symbol #1 Dec 26 07:44 1