Understanding finger and ssh will not be required to use thimbl, only to set up thimbl service for your users, which we imagine will be the same people who set up the email and web for there domain: the sysops. Wether the sysops microblog or not is irrelevant ;)
BTW, if you want to be notified when there is more to see, follow us on twitter @thimbl (or me @dmytri) (or identi.ca or friendfeed) or join our facebook page http://facebook.com/telekommunisten
Thanks Hacker News! Nice to see this pop up here, even if I wouldn't have posted it here just yet ;)
But if we wrote a Thimbl user information update server and asked you to run that on your own server, you would do that and consider our service as secure as sshd? Really? Our position is that you give as a standard remote login interface, that is ssh, how you implement that for your own finger users is up to you (see my other comment)
Hi everyone, thanks for the interest, Thimbl is not ready for public release, we are still working on it, so you'll have to patient. Regading why we use SSH: Because it is already available on your servers and is a standard, thus there is no barrier to getting started. Don't want to share "your" ssh password with some random website? No problem, how you implement access to your finger .plan files is up to you, create a special server with ssh service just for your .plan files, don't want to give your users shell accounts? creat a shell-less ssh service using something like conch or zope, etc whatever! Still not happy? Clone thimbl.net and run your own web interface! The point of using established standards is that everyone can do it there way. Thanks for the comments. With thimbl and thibl user can use any thimbl.net clone, and it make no difference.
Well, not much that can be done about caching proxies. Regarding DNS, have you been able to look at whether the IP's from failed requests show up on the new IP shortly after? I.E perhaps browser-pinning from open sessions?
Thanks, I'll look into this more. In the case of Mammatus response, the TTL would already be expired, so the only problem would be if it pinned for longer and didn't request again on failure.
Hi paraschopra. What does it do when the request using the cached DNS fails? In conversations with security experts researching DNS re-binding attacks, I've heard that pinning is dropped after one failed request, as techniques like sending multiple A records for a domain depend on this. Also see my comments to forkqueue.
Hi mrb, this is just the first release. Mammatus will return 2 A records if the endpoint domain does, so that will be built in. Of course anycast is a great option if the organisation has the option of getting an ASN, running BGP, etc. If that is not an option, Mammatus is a reasonable alternative.
Hi forkqueue, DNS pinning is indeed an issue, the scope of which this experiment will help identify. However, this would only affect those with an existing record cached for an unavailable node, no new requests would be directed that node. Futher, a Mammatus cloud can also be used as a back-end service for another front-end service which can evade the cache by prepending a random string or timestamp to the subdomain, i.e. 123.mammatus.thimbl.net. Mammatus ignores subdomains of it's subdomain, so this works. Also, information from research into DNS rebinding attacks shows that browser based pinning drops it's cache when it gets a failed requests, so a re-request would also work after failing once. Mammatus is not meant to replace all other HA techiniques. Certainly for organizations with the appropriate budget, there are potentially more robust options for front-end systems. For many situations, this is a good technique, considering how inexpensive it is. Also, this same issue exists for systems like dynamic DNS, which remain quite popular in many use-cases.
This is a pretty old text, but comments are very welcome. I'm currently working on the Telekommunist Manifesto to be published by the Institute of Netwoked Cultures in time for the Chaos Communication Congress in Berlin this December. The Manifesto will contain an updated version of some of this material, so comments and feedback are very welcome.
Material costs, like all prices must include rent, interest and wages. CC removes rent only on the IP, not on the location the store is in, for example, which still must be included in the final consumer price. Manufacturing books and selling them is commercial activity even when undertaken by an anarchist book shop. The anarchist book shop, presumably works collectively and thus has no external shareholders, and therefore can only have income, not profit. The point of copyfarleft is to prevent value derive from free terms from being captured by non-producing capital owners.
Actually, what sane person reads the sentance "The ability to control productive assets at a distance, the ability to ‘own’ something being put to productive use by another person that makes possible the subjugation of individuals and communities" without seeing how well this applies to the USSR, China, etc. Property is still just as much property when it is owned by the State, the King or The Corporation. It is important to understand the distinction between property and possesion. Proudhon: "I prove that those who do not possess to-day are proprietors by the same title as those who do possess; but, instead of inferring therefrom that property should be shared by all, I demand, in the name of general security, its entire abolition."
Hi, thanks for the comments. For example take the book 54 by Wu Ming, released under a NC license, because it is NC this prevents both Random House and the local Anarchist bookshop from havin free terms, Copyfarleft allows the bookshop to have free terms, but not Random House. That way the bookshop could independenlt manufacture and sell copyfarleft material without any violation, but Random House would need to negotiate a licence with the authors, exactly as they did for 54.
Which is exactly like a real world Dead Drop, and in the same way that a dead letterbox can be changed when the ring fears discovery, so can the deadSwap gateway. I'm not sure what you aare suggesting, if you could suggest a decentralized way a spy ring might exchange a drop, please let me know.
That you need to know fewer people is significant, and even more so is that you not meet in person that is why the "Dead Drop", "Dead Letter Box", etc is such a common tactic in espionage. deadSwap is a file sharing system/ urban game based on the concept. When done correctly it is very effective and very difficult to sting, thus it has been a standard in spycraft for decades.
being a super spy is not easy, however with training this sort of infiltration should be easily avoidable by any deadSwap cell. For one, the cell would already have been infiltrated if the "cyber-enforcement division" know the sms gateway number, if the agents are good (and never allow a rabit to see them), the most they could sting is one rabit, who would have deniablility as he is only just now getting the drop.
Yes, just like real spy rings, if you get infiltrated you are dead. That is rather the point of the game, to teach you how to be clandestine. Better learn now so you're not fumbling the drop when it counts.