Show HN: Automatic VPN Generator – Protect Yourself at Sochi and Starbucks
tinfoilsecurity.com
tinfoilsecurity.com
1. Go ahead and apply all of the software updates. The RAX Ubuntu images are behind on a lot of security updates.
apt-get -q upgrade
apt-get -q dist-upgrade
reboot (at the end)
2. While you're at it, enable automatic security-related upgrades. It's likely that the user of your service is less technical and not Linux-saavy. Let's keep their cloud server from being owned.3. Force public key auth (disable password auth) on their OpenSSH server and (preferably) disable root logins entirely. Create a user account for them if needed, with sudo access.
4. Set up IPtables as default-deny with holes punched for OpenVPN and OpenSSH.
5. Configure OpenSSH to listen on port 443 in addition to 22. Some hotspots block port 22. Almost nobody blocks port 443/tcp. This is super-handy if you're ever working from some place with a restrictive or filtering firewall. SOCKS over SSH is awesome, especially when you're dealing with censorship or malevolence at the DNS level. I used this technique when I was in the Army and our Army housing had horrible DNS servers that censored a lot of legitimate sites.
6. I would prefer you not ask for people's cloud provider API keys. This has huge potential for abuse. Instead, give them a script that they can run on any Mac or Linux box that takes the root password and IP and provisions their server for them.
I suppose I should make a PR for you; maybe later this weekend
Great points otherwise, would love to see a PR. :) thanks for the feedback!
Please upgrade your script to generate a 4096-bit DH modulus. EDIT: A 2048-bit safe prime provides over 100 bits of security and is much faster to generate.
I'm not sure why OpenSSL hasn't upgraded their default modulus size, but to have the same strength as a 150-bit symmetric cipher key, against the best attack techniques 2004 had to offer, you'd need about a 4575-bit DH modulus.[1] AES-128 is about as hard to break as a 3200-bit DH modulus given the best techniques of 2001.[2]
EDIT: Times to generate different sized safe primes on my MBP maxing out one core:
512 bits = 0.5 sec
1024 bits = 0.8 sec
2048 bits = 2 min
3072 bits = more than 30 minutes
4096 bits = more than 60 minutes
[1] https://tools.ietf.org/html/rfc3766 (see table in section 5)
That would be awesome.
Promoting the use of VPNs and secure browsing habits is awesome, and I applaud them for open sourcing the script. But asking people to trust them to do the work negates much of the benefit they're trying to provide.
I get that you can make the argument that we're training people to stick their API keys in random textboxes on the internet, but we thought getting more people on a VPN was worth the risk.
"We stay paranoid so you don't have to be"
ssh -D <port> user@host
Then configure your browser (I use a plugin called FoxyProxy) to use localhost:<port> as SOCKS5 proxy.
This is also very cool: https://github.com/apenwarr/sshuttle
Edit: I should add that I do not think your DNS requests will go over the proxy. You might be able to configure your browser to do that. Caveat emptor.
chromium-browser --proxy-server="socks5://localhost:<port>"
FoxyProxy is good too; but... yet-another-third-party.In Firefox, visit "about:config" and ensure that "network.proxy.socks_remote_dns" is set to "True".
Chrome apparently sends DNS queries via the proxy by default but in some cases (prefetching is mentioned specifically) it may not [0].
[0]: https://sites.google.com/a/chromium.org/dev/developers/desig...
But yes, if you allow plugins that have the ability to initiate arbitrary connections, there's no way to guarantee they aren't making un-proxied connections, unless you either use firewall rules to block outgoing un-proxied connections, or you transparently proxy everything (VPN). Same as with running arbitrary non-browser apps that might open socket connections.
I use it to access machines on my home network when I'm abroad.
http://www.sarfata.org/posts/setting-up-an-amazon-vpn-server...
I'm still trying to find a VPN solution that can stream 1080p video across the Pacific Ocean, but I still haven't been able to get something working with enough bandwidth.
You may also want to specify "cipher AES-256-CBC" in both client and server config to upgrade from the default AES-128 it uses.
[1]: https://openvpn.net/index.php/open-source/documentation/misc...
Do we need more detail? :)
NBC: All Visitors to Sochi Olympics Immediately Hacked
The strange part is that the server I am using should not be sending email or doing much really except hosting some git repos and a basic website.
The site talks about deleting or pausing servers, then going back to the TinFoil page to start over in the future. However, it looks like DigitalOcean charges a flat $5 per month for the lowest tier. Is there any harm in leaving it running 24/7 and connecting when I'm in public? The most I'd be charged is $5/month, right?
If you don't mind paying the $5, by all means leave it up 24/7. :)
E.g. I want a 10 chain VPN proxy, here is my API keys for N servives, please distribute the VPN across these.
Obviously this is a slightly different use case than just protecting against passive monitoring, but I think it'd be cool.
>"Sidestep is an open-source application for Mac OS X that sits quietly in the background, protecting your security and privacy as you browse the web."
>[...]
>"When Sidestep detects you connecting to an unprotected wireless network, it automatically encrypts all of your Internet traffic and reroutes it through a secure connection to a server of your choosing, which acts as your Internet proxy. And it does all this in the background so that you don’t even notice it."
OpenVPN works on a lower level and just tells the operating system to use it as a gateway (as configured here) and every software will magically start routing traffic over it. This is generally what you want for security, but can be annoying for bandwidth or latency sensitive applications.
ssh -D port hostIts been a long time i did not not see as much bullshit. In linux, its as simple as going into the vpn tab of your connections, entering your username, password and crt file, and you are done.