Anonymous Servers - Xerobank, privacy rip off ??

This is Interesting: Free IT Magazines  
Home > Archive > Anonymous Servers > July 2007 > Xerobank, privacy rip off ??





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Xerobank, privacy rip off ??
macarro

2007-06-23, 7:14 am

I have come across a privacy service called Xerobank.com after spending
a while reading it I suspect that they are offering Tor services at $35
month!!

Their privacy policy says "the servers are located in different
countries so we can't give the logs to the authorities".

Anyone could confirm this? They are quite good at marketing in the
webpage so it is not that obvious that they use Tor, but I looked into
it because a PC magazine in the UK names them as a Tor ACCESS provider.

It is also highly suspecious that they have the free Torpark logo on
their page.


--

Customized News: http://news.spotback.com
Borked Pseudo Mailed

2007-06-23, 1:13 pm

The latest offering in the field of expensive "One-Stop" privacy
services. Supposedly surfing at high speed access.

Brought to you by Steve Topletz of Torpark notoriety.

The offering appears very close to MP. Wouldn't be surprised if
Xerobank stole some key MP employees.

One is entrusting one's privacy testicles to a single entity.

Their privacy notice appears contradictory. On the one hand they claim
"no logging."

To quote heir section on Technical Logs:

"Technical Logs
XeroBank does not collect IP addresses, but may collect data that is
not Personally Identifying Information when accessing XeroBank services
and web sites. These technical logs are not personally identifiable,
and XeroBank makes no attempt to link them with the individuals that
actually use the service or web site. The log files are collected for
internal system analysis and benchmarking purposes only and are being
deleted after a maximum of 90 days. XeroBank may only store summarized
access statistics not containing any IP addresses or other personal
information. XeroBank employs Google Analytics in its web site in order
to collect demographic data about visitors. XeroBank has filtered all
Google Analytics data to replace visitor IP addresses with '0.0.0.0'."

Yea, right...








Anonymous

2007-06-23, 1:13 pm

macarro wrote:

> I have come across a privacy service called Xerobank.com after spending
> a while reading it I suspect that they are offering Tor services at $35
> month!!


Scam.

This is nothing but Torpark (preconfigured version of firefox/privoxy/etc)
packaged in a shrink wrapped box and sold alongside a tunnel. And the
tunnel is nothing but a default configuration of OpenSSH. That's how
difficult it is to set up a "privacy tunnel", you install the ssh daemon
and open a hole in your firewall if necessary.

The business was faltering as torrify.com, and it will probably falter as
xerobank.com. Even Tor's developers don't look favorably on Torpark. It
introduces a whole bunch of new problems, and the author doesn't seem to
want to be bothered addressing them.

You can get better privacy and the best anonymity in the world using
JanusVM. It's the exact same basic setup, 100% free, and you're not
allowing someone else to handle all your Tor traffic and effectively
become your sole entry node.

> Their privacy policy says "the servers are located in different
> countries so we can't give the logs to the authorities".


Same FUD, different FUDster. ;-)

If you read certain forums or hang out in the right IRC channels you
already know that "Arrakistor" A.K.A Steve Topletz has a bit of an
overactive imagination and likes to make unsupported claims. His "leaves
no traces on your PC", or "doesn't use swap files" nonsense has been
disproved over and over, by experts and laypersons alike for example. It's
a pretty easy thing to check, so Steve either didn't bother checking
before he made those claims, or he's dumber than a toadstool.

The "high speed access to the Tor network" snake oil is particularly
bogus. It doesn't matter how fast you get there, the Tor network is what
it is. In a typical configuration you're getting there at your computer's
internal bus speeds, and it's still dog slow at times. So how is a "high
speed SSH tunnel" suppose to speed things up?

Answer: It wont.

> Anyone could confirm this? They are quite good at marketing in the
> webpage so it is not that obvious that they use Tor, but I looked into
> it because a PC magazine in the UK names them as a Tor ACCESS provider.
>
> It is also highly suspecious that they have the free Torpark logo on
> their page.


It's his product, why shouldn't he use the logo? I think it's suspicious
that they don't make the facts more clear. They seem to want to hide what
their service really is for some reason.

Hmmmmmmmmmmmmmmmm..........

Anyway, as for the "making money off Tor" angle, it's already been brought
to the attention of Tor's developers and the Tor community at large. They
don't see it as something a respectable person would do, but on principal
they're not going to do anything about it because it's not technically a
breach of any licensing agreement to make money off Tor. One of Tor's
developers has considered a private, pay-for Tor network in fact.

It's wrong to stand on the shoulders of others and play to the fears of
paranoid minds with FUD and lies just to make a buck or two, but so far
there's nothing unlawful going on that anyone knows about. It's just shady
beyond anything who you'd want to trust with your privacy might do.

Anonymous

2007-06-23, 7:13 pm

Anonymous wrote:

> macarro wrote:
>
>
> Scam.


Scam might be a little harsh. There's a lot of FUD and hype attached to
TorPark/Torrify/Xeroban, but underneath it all I really believe Steve
thinks he's doing a good thing.

What bothers me the most about the whole TorPark/cDc/Hactivismo thing is
the fact that they're all deluding themselves about how noble and effective
they are with respect to human rights. I lived in Asia for 11 years, and
made it into mainland China 7 times for a total of about 14 months living
on Chinese soil. You have to understand the culture to understand what a
sad joke the whole thing is.

China is almost identical to Japan when it comes to "face", or respect and
honor. Trafficking in subversive material is a crime, but not one that's
going to get you shot no matter what the media tells you. I know, I was
there in the middle of it with friends on both sides of the wall. If
you get caught doing a crime anywhere in that part of the world your
punishment is defined almost entirely by how you conduct yourself after
being caught. Deny your crimes and you're royally screwed. Accept and
atone, and you're given the lightest possible penalty.

Just using Tor in China to cover up your activities will get you in deep
ca-ca. Deeper ca-ca than doing the crime in the first place will. That
society sees it as a personal insult to their intelligence when you try
and con job them, so you either come clean about what you're doing or
suffer big time. And there's is no "innocent until proved" there. If
you're suspected, you're pretty much guilty.

Tor is causing more problems for more people in China than it's solving,
you can be sure of that. And the saddest part of the whole deal is that
they're luring innocent people to their folly because they're blind to the
truth of things by the same western ideals they think they're promoting.

admin@torrify.com

2007-06-24, 7:13 pm

Greetings,

Macarro, I wrote Torpark, and I am an admin at XeroBank (formerly
Torrify), and XeroBank now owns the former Torpark. That is why the
logo is on the page.

Perhaps I can address some of these claims directly, as they seem to
reach conclusions without even the most cursory observation of facts
or experience. I am amazed by what a little knowledge but a lot of
confusion can lead people to believe. Let's clear that up.

Regarding Tor usage in China, it is not an issue at all. If you are
already a known dissident, there is little harm in accessing the Tor
network. I gave a thorough exposition on this at the Torrify forum, as
to why China continues to allow access to the Tor network. If you
aren't already a known dissident, it can alert authorities to the fact
that you are. I was discussing covert data channels with another
hacktivismo member, in this regard. Let's get back to the issue at
hand though:

We are not offering onion routing services, yet. However, we have
secretly developed and deployed an onion-routing network. It is in
testing right now, and is not yet available for public consumption.
And by the way it is FAST! I was bouncing 1800Kbps through it while it
was just warming up to the nameservers. While I think this solution
for anonymity is superior, the throughput consumption is enormous. For
every 1MB you transfer in/out, it creates 6MB of traffic. The network
services we are offering, broken down with technical specificaitions,
are 1) SSH tunnel for http/https/smtp traffic, providing 200Kbps to
700Kbps from our servers. This is a multi-hop network. Right now this
is priced at $10/month. 2) VPN TLS connection, providing 1500Kbps to
4000Kbps from our servers. This is a multi-hop network. Right now this
is priced at $35/month. 3) VPN TLS connection, providing a bandwidth
pool of 40,000Kbps, which can be shared by up to 30 user connections
which the owner of the account can assign. Right now this is priced at
$500/month, and can be made available preconfigured on hardware
routers so they are plug and play.

Most of the confusion seems to be that people think because we offer
high speed access _to_ the tor network, that somehow we are claiming
to make the tor network itself fast, or that we are using resources of
the tor network for commercial gain. Neither of which is true. Some of
our network providers already run many of the fastest tor nodes on the
public network, in the same datacenters as ours, in addition to us
running our own gateway entry nodes. This virtually eliminates the
latency of entry nodes and puts you right into the tor network. So if
you are trying to access a hidden service (thus using the Tor
network), you get there pretty quick. At least, you're dropping the
number of latency vectors by 33%. I think we also have JAP gateway
servers as well, I'll have to check and see if those are available
yet.

>The business was faltering as torrify.com, and it will probably falter as
>xerobank.com. Even Tor's developers don't look favorably on Torpark. It
>introduces a whole bunch of new problems, and the author doesn't seem to
>want to be bothered addressing them.


I'm not sure where you get your "information", but we never even
offered services as Torrify. You may be surprised to know that Torpark/
xB Browser is THE most popular online anonymity browser in the world.
Tor's developers had issue with Torpark because it wasn't written
cross platform in a language they could read, nor was it released
under GPL/3BSD as they wanted it to be. Torpark introduces no new
problems, and solves many of the prior problems that Tor itself had
with implementation, such as the DNS leak problem that requires the
use of Privoxy to solve. Torpark became more popular among users than
Tor itself did, so the reaction of competitors and detractors isn't
hard to understand. No objections yet have had any merit or gained any
traction, and I challenge you in public to dispute it by listing any
of these inherent "problems" you claim to have knowledge of.

>You can get better privacy and the best anonymity in the world using
>JanusVM. It's the exact same basic setup, 100% free, and you're not
>allowing someone else to handle all your Tor traffic and effectively
>become your sole entry node.


I can't tell that you have any idea what you are talking about
regarding networks and anonymity. JanusVM has its own set of problems,
and is based upon a design idea I mentioned to someone in the Tor
project about a year ago. But we have designed a superior solution
that will be released on August 3rd, called xB Machine. And like all
our software, it is free, turn-key, and easy to use.

Regarding leaving traces, this is an inherent flaw in Windows, and not
a function of Torpark/xB Browser. The specific problem lies in Firefox
paging, but suffice to say, it isn't Torpark that is leaving data
behind. And what data does it leave behind? Well if you have memory
that gets sent to the swap, you could have that memory written to disk
and stay persistent after you shutdown the program, assuming it
doesn't get overwritten by another problem (like RAM). While the
solution seems to be to reduce your swapsize to 0, and turn on swap
wiping at shutdown, that is too over-reaching and just shifts the
problem to RAM. That is just shifting the vector from non-volatile
memory to semi-volatile memory, which is the illusion of a solution.
While it would be easy enough to do, assuming the user had the rights
to do it, that just isn't a real solution for the problem in the
design of Windows. Another issue is that of registry keys. Torpark
itself isn't creating registry keys, but firefox might. While we could
go back and erase any registry keys created, easily enough, that
doesn't tackle the issue. What it does is tell a forensics person that
someone ran firefox. I don't personally find that very compelling, but
Iet's give it some thought... If you have someone who already has
administrative access to your system, but you're complaining about
innocuous registry keys, you're rearranging deckchairs on the titanic.
At that point, you've got much bigger problems, and why you weren't
using disk encryption in he first place is the issue.

>Anyway, as for the "making money off Tor" angle, it's already been brought
>to the attention of Tor's developers and the Tor community at large. They
>don't see it as something a respectable person would do, but on principal
>they're not going to do anything about it because it's not technically a
>breach of any licensing agreement to make money off Tor. One of Tor's
>developers has considered a private, pay-for Tor network in fact.


I agree, why would anyone sell something that others are giving away
at their
own expense? This is why XeroBank has never used the Tor network, and
xB Browser
is free and will always remain so.

Regards,
Steve Topletz
XeroBank Administrator

traveller 66

2007-06-24, 7:13 pm

On Sun, 24 Jun 2007 14:42:36 -0700, admin@torrify.com wrote:

> Greetings,
>
> Macarro, I wrote Torpark, and I am an admin at XeroBank (formerly
> Torrify), and XeroBank now owns the former Torpark. That is why the
> logo is on the page.


FUD is a specialty here, good luck in your business. I hope someone doesn't
troll you or set up posts from you without your headers on topics to try
and discredit you with them. That's what happens to people in here that say
anything but cotse. Only cotse trols do business in usenet like that.
joe

2007-06-24, 7:13 pm

traveller 66 wrote:
> On Sun, 24 Jun 2007 14:42:36 -0700, admin@torrify.com wrote:
>
>
> FUD is a specialty here, good luck in your business. I hope someone doesn't
> troll you or set up posts from you without your headers on topics to try
> and discredit you with them. That's what happens to people in here that say
> anything but cotse. Only cotse trols do business in usenet like that.


It will live or die on it's own merit.

I see my plea did no good.
Nomen Nescio

2007-06-24, 7:13 pm

traveller 66 wrote:

> On Sun, 24 Jun 2007 14:42:36 -0700, admin@torrify.com wrote:
>
>
> FUD is a specialty here, good luck in your business. I hope someone

doesn't
> troll you or set up posts from you without your headers on topics to try
> and discredit you with them. That's what happens to people in here

that say
> anything but cotse. Only cotse trols do business in usenet like that.
>


Allow me to translate Ademspeak for you, what he meant to say was:

"If you don't lie to people in here you'll get along fine, if you do
then you will be shredded for those lies."

If you do choose the Adem route of lying in your claims and end up
shredded for it, the current fave to blame it on is Cotse. Just so you
know and can be prepared. But if you don't lie in your claims of what
the service provides, you'll have no issues here, welcome to alt.privacy.

I, for one, welcome a mix choice for a paid service. While still having
the problem of a single entity owning all machines, it is a far better
setup than a single SSH server tunnel. Freedom.Net once tried to offer
a similar service, you may want to look for where it went wrong for them
and avoid those same pitfalls. I believe that they quite overestimated
the existing market, as well as the legal issues they'd face.

Anonymous

2007-06-25, 1:13 am

traveller 66 wrote:

> FUD is a specialty here, good luck in your business. I hope someone doesn't
> troll you or set up posts from you without your headers on topics to try


Unfortunately for you Google isn't the only Usenet archive on the planet.

Suck on this you filthy pedophile. It's your admission, complete with the
headers you're whining about. Another major *spank* for your filthy
pedophile XXX this week. Anyone using a server with decent retention can
look it up by message ID now. Hope you enjoy having your nose rubbed in it,
and have a nice day! <laugh>

---cut---
Path: s02-b27.iad01!nx02.iad01.newshosting.com!newshosting.com!post01.iad01!not-for-mail
Newsgroups: alt.privacy
Subject: Re: Any Phone Safe?
From: "EggplantŠ" <vegetables@theguarden.com>
References: <b61949089c833bede77f7815a32964d7@dizum.com> <Xns98D83ADFDB7DCEggplant@63.218.45.252> <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net> <1af100c765b949c399bfc6d598ce0b0e@dizum.com> <Xns98DF50B8F10BAEggplant@63.218.45.254> <29162e230034491ac10bfc386
356a94d@deuxpi.ca>
Organization: 60's Burnout
Message-ID: <Xns98DF8560483E1Eggplant@63.218.45.252>
User-Agent: Xnews/5.03.24
X-No-Archive: yes
Date: 22 Feb 2007 21:57:02 GMT
Lines: 36
X-Complaints-To: abuse@newshosting.com

Anonyma <anon-bounces@deuxpi.ca> wrote in
news:29162e230034491ac10bfc386356a94d@de
uxpi.ca:A vortex formed within
the smokey haze of my alledged mind and became this:

> Eggplant=C2=A9 wrote:
>
>
> <CLIP>
>
>
> ROTFLMAO!!!!!
>
> Forget to change socks there, asslicker?
>
> So it turns out the "traveler" puppet is also a pedoXXXX pervert called
> Eggfart. That explains a lot. You were always "both" just a couple of
> XXXXtarded asslickers. It's good to know Privacy.LIE and its twin
> sister scam services have such a distinguished customer base.
>
> Owned by perverted racists..... patronized by racist perverts.=20
>
> LOL! Outstanding. Thank you. LOL!!
>
>

Boy are you a moron. I'd use remailers for everything and stay anonymous
if I were going to be 2 people. Yeah, I've forgotten to change nics on my
Xnews. But I don't use remailers. You're way off base as usual.
---cut---

Ari

2007-06-25, 1:13 am

On Sun, 24 Jun 2007 14:42:36 -0700, admin@torrify.com wrote:

> Tor's developers had issue with Torpark because it wasn't written
> cross platform in a language they could read, nor was it released
> under GPL/3BSD as they wanted it to be.


What did the ONI have to say?
admin@torrify.com

2007-06-25, 1:13 am

On Jun 24, 9:12 pm, Ari <arisilverst...@yahoo.com> wrote:
> On Sun, 24 Jun 2007 14:42:36 -0700, a...@torrify.com wrote:
>
> What did the ONI have to say?


ONI? Office of Naval Intel?

Anonymous

2007-06-25, 1:13 am

In article <e03fdb208e01a5f2729aa4b6eb1c143a@ecn.org>
Anonymous <cripto@ecn.org> wrote:
>
> traveller 66 wrote:
>
>
> Unfortunately for you Google isn't the only Usenet archive on the planet.
>
> Suck on this you filthy pedophile. It's your admission, complete with the
> headers you're whining about. Another major *spank* for your filthy
> pedophile XXX this week. Anyone using a server with decent retention can
> look it up by message ID now. Hope you enjoy having your nose rubbed in it,
> and have a nice day! <laugh>


By Gum you're right! allnews.readfreenews.net still had the whole thread
hanging around. Wowzers.

In order:

From: Nomen Nescio <nobody@dizum.com>
Newsgroups: alt.privacy
Subject: Any Phone Safe?
References:
X-No-Archive: Yes
Message-ID: <b61949089c833bede77f7815a32964d7@dizum.com>
Date: Tue, 13 Feb 2007 01:30:08 +0100 (CET)
Mail-To-News-Contact: abuse@dizum.com
Organization: mail2news@dizum.com

Other than having crypto phones on each end what's the safest, most
anonymous phone you can own nowadays? Is cell safer than landline? Why or
why not. Anyone who believes that the government only listens to
terrorists I think is really taking a big risk especially if they are on
Bush's black list (I am sure he has one).

-------------------------

Newsgroups: alt.privacy
Subject: Re: Any Phone Safe?
From: "EggplantŠ" <vegetables@theguarden.com>
References: <b61949089c833bede77f7815a32964d7@dizum.com>
Organization: 60's Burnout
Message-ID: <Xns98D83ADFDB7DCEggplant@63.218.45.252>
User-Agent: Xnews/5.03.24
X-No-Archive: yes
Date: 15 Feb 2007 13:46:37 GMT
Lines: 17
X-Complaints-To: abuse@newshosting.com

Nomen Nescio <nobody@dizum.com> wrote in
news:b61949089c833bede77f7815a32964d7@di
zum.com:A vortex formed within the
smokey haze of my alledged mind and became this:

> Other than having crypto phones on each end what's the safest, most
> anonymous phone you can own nowadays? Is cell safer than landline? Why or
> why not. Anyone who believes that the government only listens to
> terrorists I think is really taking a big risk especially if they are on
> Bush's black list (I am sure he has one).
>
>


The problem with cell phones is the "implied consent" laws. You are
knowingly using a portable transmitter/reciever. Anything done on a cell
phone can be used in court without any privacy protection laws that would
apply to landlines. No warrant necessary because it was sent openly over
the airwaves.

--------------------------------

From: traveler 66 <noreply@nym.alias.net>
Subject: Re: Any Phone Safe?
Newsgroups: alt.privacy
User-Agent: 40tude_Dialog/2.0.14.1
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Reply-To: noreply@nym.alias.net
Organization: Anonymous
References: <b61949089c833bede77f7815a32964d7@dizum.com>
<Xns98D83ADFDB7DCEggplant@63.218.45.252>
Date: Thu, 15 Feb 2007 23:12:39 -0800
Message-ID: <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
Lines: 21
X-Complaints-To: admin01@privacy.li

On 15 Feb 2007 13:46:37 GMT, EggplantŠ wrote:

> Nomen Nescio <nobody@dizum.com> wrote in
> news:b61949089c833bede77f7815a32964d7@di
zum.com:A vortex formed within the
> smokey haze of my alledged mind and became this:
>
>
> The problem with cell phones is the "implied consent" laws. You are
> knowingly using a portable transmitter/reciever. Anything done on a cell
> phone can be used in court without any privacy protection laws that would
> apply to landlines. No warrant necessary because it was sent openly over
> the airwaves.


Why don't you post your address here, I'll look up the law in your area for
you.

---------------------------------------

From: Nomen Nescio <nobody@dizum.com>
Subject: Re: Any Phone Safe?
Newsgroups: alt.privacy
References: <b61949089c833bede77f7815a32964d7@dizum.com>
<Xns98D83ADFDB7DCEggplant@63.218.45.252>
<gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
Message-ID: <1af100c765b949c399bfc6d598ce0b0e@dizum.com>
Date: Fri, 16 Feb 2007 14:00:04 +0100 (CET)
Mail-To-News-Contact: abuse@dizum.com
Organization: mail2news@dizum.com

traveler 66 wrote:

> On 15 Feb 2007 13:46:37 GMT, Eggplant=C2=A9 wrote:
>=20
>=20
> Why don't you post your address here, I'll look up the law in your
> area for you.


Do you mean "look up" as in the way you ignore and deny the laws in all
the cheap hosting privacy SHIT HOLES where you rent server space just
so you can swindle people with your off-shore lies?

Slimy asslickers like you offering legal research assistance is BEYOND
ironic. How many times have you tried to tell us local laws and MLATS
don't matter now? A couple dozen?=20

How's it feel to have your bullshit come back to haunt you? Hmmmmm?

LOL!

-------------------------------------

Newsgroups: alt.privacy
Subject: Re: Any Phone Safe?
From: "EggplantŠ" <vegetables@theguarden.com>
References: <b61949089c833bede77f7815a32964d7@dizum.com>
<Xns98D83ADFDB7DCEggplant@63.218.45.252>
<gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
<1af100c765b949c399bfc6d598ce0b0e@dizum.com>
Organization: 60's Burnout
Message-ID: <Xns98DF50B8F10BAEggplant@63.218.45.254>
User-Agent: Xnews/5.03.24
X-No-Archive: yes
Date: 22 Feb 2007 16:46:13 GMT
Lines: 49
X-Complaints-To: abuse@newshosting.com

Nomen Nescio <nobody@dizum.com> wrote in
news:1af100c765b949c399bfc6d598ce0b0e@di
zum.com:A vortex formed within
the smokey haze of my alledged mind and became this:

> traveler 66 wrote:
>
20[vbcol=seagreen]
>
> Do you mean "look up" as in the way you ignore and deny the laws in all
> the cheap hosting privacy SHIT HOLES where you rent server space just
> so you can swindle people with your off-shore lies?
>
> Slimy asslickers like you offering legal research assistance is BEYOND
> ironic. How many times have you tried to tell us local laws and MLATS
> don't matter now? A couple dozen?=20
>
> How's it feel to have your bullshit come back to haunt you? Hmmmmm?
>
> LOL!
>

WTF are you talking about (in your further attempts to confuse issues).

I don't have a server, nor am I connected to anyone who does beyond being
a very satified customer with prili. Nothing has come back to haunt me at
all. Who ever said the laws don't matter? Having to put words in peoples
mouths to try to look wise again I see. When do you offer anything to
help anyone? You're just a troll.

------------------------------------

From: Anonyma <anon-bounces@deuxpi.ca>
X-Anonymous: yes
X-Anon-Help: <http://www.deuxpi.ca/>
<mailto:deuxpi-admin@deuxpi.ca>
Subject: Re: Any Phone Safe?
Newsgroups: alt.privacy
References: <b61949089c833bede77f7815a32964d7@dizum.com>
<Xns98D83ADFDB7DCEggplant@63.218.45.252>
<gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
<1af100c765b949c399bfc6d598ce0b0e@dizum.com>
<Xns98DF50B8F10BAEggplant@63.218.45.254>
Message-ID: <29162e230034491ac10bfc386356a94d@deuxpi.ca>
Date: Thu, 22 Feb 2007 16:23:00 -0500 (EST)
Mail-To-News-Contact: abuse@dizum.com
Organization: mail2news@dizum.com

Eggplant=C2=A9 wrote:

> Nomen Nescio <nobody@dizum.com> wrote in=20
> news:1af100c765b949c399bfc6d598ce0b0e@di
zum.com:A vortex formed
> within the smokey haze of my alledged mind and became this:
>=20

<CLIP>
[vbcol=seagreen]
> WTF are you talking about (in your further attempts to confuse
> issues).
>=20
> I don't have a server, nor am I connected to anyone who does beyond


ROTFLMAO!!!!!

Forget to change socks there, asslicker?

So it turns out the "traveler" puppet is also a pedoXXXX pervert called
Eggfart. That explains a lot. You were always "both" just a couple of
XXXXtarded asslickers. It's good to know Privacy.LIE and its twin
sister scam services have such a distinguished customer base.

Owned by perverted racists..... patronized by racist perverts.=20

LOL! Outstanding. Thank you. LOL!!

-------------------------------------

Newsgroups: alt.privacy
Subject: Re: Any Phone Safe?
From: "EggplantŠ" <vegetables@theguarden.com>
References: <b61949089c833bede77f7815a32964d7@dizum.com>
<Xns98D83ADFDB7DCEggplant@63.218.45.252>
<gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
<1af100c765b949c399bfc6d598ce0b0e@dizum.com>
<Xns98DF50B8F10BAEggplant@63.218.45.254>
<29162e230034491ac10bfc386356a94d@deuxpi.ca>
Organization: 60's Burnout
Message-ID: <Xns98DF8560483E1Eggplant@63.218.45.252>
User-Agent: Xnews/5.03.24
X-No-Archive: yes
Date: 22 Feb 2007 21:57:02 GMT
Lines: 36
X-Complaints-To: abuse@newshosting.com

Anonyma <anon-bounces@deuxpi.ca> wrote in
news:29162e230034491ac10bfc386356a94d@de
uxpi.ca:A vortex formed within
the smokey haze of my alledged mind and became this:

> Eggplant=C2=A9 wrote:
>
>
> <CLIP>
>
>
> ROTFLMAO!!!!!
>
> Forget to change socks there, asslicker?
>
> So it turns out the "traveler" puppet is also a pedoXXXX pervert called
> Eggfart. That explains a lot. You were always "both" just a couple of
> XXXXtarded asslickers. It's good to know Privacy.LIE and its twin
> sister scam services have such a distinguished customer base.
>
> Owned by perverted racists..... patronized by racist perverts.=20
>
> LOL! Outstanding. Thank you. LOL!!
>
>

Boy are you a moron. I'd use remailers for everything and stay anonymous
if I were going to be 2 people. Yeah, I've forgotten to change nics on my
Xnews. But I don't use remailers. You're way off base as usual.

-------------------------------------

admin@torrify.com

2007-06-25, 1:13 am

On Jun 24, 6:19 pm, traveller 66 <nore...@nym.alias.net> wrote:
> On Sun, 24 Jun 2007 14:42:36 -0700, a...@torrify.com wrote:
>
>
> FUD is a specialty here, good luck in your business. I hope someone doesn't
> troll you or set up posts from you without your headers on topics to try
> and discredit you with them. That's what happens to people in here that say
> anything but cotse. Only cotse trols do business in usenet like that.


No worries. That is what key signing is for. If someone claims to be
me and makes some silly statement, ask them to sign their message
using my key. I'll probably sign all my posts once I find a good
reader that can do it.

traveller 66

2007-06-25, 1:13 am

On Mon, 25 Jun 2007 05:12:09 +0200 (CEST), Anonymous wrote:

> In article <e03fdb208e01a5f2729aa4b6eb1c143a@ecn.org>
> Anonymous <cripto@ecn.org> wrote:
>
> By Gum you're right! allnews.readfreenews.net still had the whole thread
> hanging around. Wowzers.
>
> In order:
>
> From: Nomen Nescio <nobody@dizum.com>
> Newsgroups: alt.privacy
> Subject: Any Phone Safe?
> References:
> X-No-Archive: Yes
> Message-ID: <b61949089c833bede77f7815a32964d7@dizum.com>
> Date: Tue, 13 Feb 2007 01:30:08 +0100 (CET)
> Mail-To-News-Contact: abuse@dizum.com
> Organization: mail2news@dizum.com
> Xref: authen.puce.readfreenews.net alt.privacy:217848
>
> Other than having crypto phones on each end what's the safest, most
> anonymous phone you can own nowadays? Is cell safer than landline? Why or
> why not. Anyone who believes that the government only listens to
> terrorists I think is really taking a big risk especially if they are on
> Bush's black list (I am sure he has one).
>
> -------------------------
>
> Newsgroups: alt.privacy
> Subject: Re: Any Phone Safe?
> From: "EggplantŠ" <vegetables@theguarden.com>
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> Organization: 60's Burnout
> Message-ID: <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> User-Agent: Xnews/5.03.24
> X-No-Archive: yes
> Date: 15 Feb 2007 13:46:37 GMT
> Lines: 17
> X-Complaints-To: abuse@newshosting.com
> Xref: authen.puce.readfreenews.net alt.privacy:217882
>
> Nomen Nescio <nobody@dizum.com> wrote in
> news:b61949089c833bede77f7815a32964d7@di
zum.com:A vortex formed within the
> smokey haze of my alledged mind and became this:
>
>
> The problem with cell phones is the "implied consent" laws. You are
> knowingly using a portable transmitter/reciever. Anything done on a cell
> phone can be used in court without any privacy protection laws that would
> apply to landlines. No warrant necessary because it was sent openly over
> the airwaves.
>
> --------------------------------
>
> From: traveler 66 <noreply@nym.alias.net>
> Subject: Re: Any Phone Safe?
> Newsgroups: alt.privacy
> User-Agent: 40tude_Dialog/2.0.14.1
> MIME-Version: 1.0
> Content-Type: text/plain; charset="iso-8859-1"
> Content-Transfer-Encoding: 8bit
> Reply-To: noreply@nym.alias.net
> Organization: Anonymous
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> Date: Thu, 15 Feb 2007 23:12:39 -0800
> Message-ID: <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
> Lines: 21
> X-Complaints-To: admin01@privacy.li
> Xref: authen.puce.readfreenews.net alt.privacy:217907
>
> On 15 Feb 2007 13:46:37 GMT, EggplantŠ wrote:
>
>
> Why don't you post your address here, I'll look up the law in your area for
> you.
>
> ---------------------------------------
>
> From: Nomen Nescio <nobody@dizum.com>
> Subject: Re: Any Phone Safe?
> Newsgroups: alt.privacy
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
> Message-ID: <1af100c765b949c399bfc6d598ce0b0e@dizum.com>
> Date: Fri, 16 Feb 2007 14:00:04 +0100 (CET)
> Mail-To-News-Contact: abuse@dizum.com
> Organization: mail2news@dizum.com
> Xref: authen.puce.readfreenews.net alt.privacy:217912
>
> traveler 66 wrote:
>
>
> Do you mean "look up" as in the way you ignore and deny the laws in all
> the cheap hosting privacy SHIT HOLES where you rent server space just
> so you can swindle people with your off-shore lies?
>
> Slimy asslickers like you offering legal research assistance is BEYOND
> ironic. How many times have you tried to tell us local laws and MLATS
> don't matter now? A couple dozen?=20
>
> How's it feel to have your bullshit come back to haunt you? Hmmmmm?
>
> LOL!
>
> -------------------------------------
>
> Newsgroups: alt.privacy
> Subject: Re: Any Phone Safe?
> From: "EggplantŠ" <vegetables@theguarden.com>
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
> <1af100c765b949c399bfc6d598ce0b0e@dizum.com>
> Organization: 60's Burnout
> Message-ID: <Xns98DF50B8F10BAEggplant@63.218.45.254>
> User-Agent: Xnews/5.03.24
> X-No-Archive: yes
> Date: 22 Feb 2007 16:46:13 GMT
> Lines: 49
> X-Complaints-To: abuse@newshosting.com
> Xref: authen.puce.readfreenews.net alt.privacy:218035
>
> Nomen Nescio <nobody@dizum.com> wrote in
> news:1af100c765b949c399bfc6d598ce0b0e@di
zum.com:A vortex formed within
> the smokey haze of my alledged mind and became this:
>
> 20
> WTF are you talking about (in your further attempts to confuse issues).
>
> I don't have a server, nor am I connected to anyone who does beyond being
> a very satified customer with prili. Nothing has come back to haunt me at
> all. Who ever said the laws don't matter? Having to put words in peoples
> mouths to try to look wise again I see. When do you offer anything to
> help anyone? You're just a troll.
>
> ------------------------------------
>
> From: Anonyma <anon-bounces@deuxpi.ca>
> X-Anonymous: yes
> X-Anon-Help: <http://www.deuxpi.ca/>
> <mailto:deuxpi-admin@deuxpi.ca>
> Subject: Re: Any Phone Safe?
> Newsgroups: alt.privacy
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
> <1af100c765b949c399bfc6d598ce0b0e@dizum.com>
> <Xns98DF50B8F10BAEggplant@63.218.45.254>
> Message-ID: <29162e230034491ac10bfc386356a94d@deuxpi.ca>
> Date: Thu, 22 Feb 2007 16:23:00 -0500 (EST)
> Mail-To-News-Contact: abuse@dizum.com
> Organization: mail2news@dizum.com
> Xref: authen.puce.readfreenews.net alt.privacy:218044
>
> Eggplant=C2=A9 wrote:
>
>
> <CLIP>
>
>
> ROTFLMAO!!!!!
>
> Forget to change socks there, asslicker?
>
> So it turns out the "traveler" puppet is also a pedoXXXX pervert called
> Eggfart. That explains a lot. You were always "both" just a couple of
> XXXXtarded asslickers. It's good to know Privacy.LIE and its twin
> sister scam services have such a distinguished customer base.
>
> Owned by perverted racists..... patronized by racist perverts.=20
>
> LOL! Outstanding. Thank you. LOL!!
>
> -------------------------------------
>
> Newsgroups: alt.privacy
> Subject: Re: Any Phone Safe?
> From: "EggplantŠ" <vegetables@theguarden.com>
> References: <b61949089c833bede77f7815a32964d7@dizum.com>
> <Xns98D83ADFDB7DCEggplant@63.218.45.252>
> <gzxeevjdr3jk.1udn2x095zaia$.dlg@40tude.net>
> <1af100c765b949c399bfc6d598ce0b0e@dizum.com>
> <Xns98DF50B8F10BAEggplant@63.218.45.254>
> <29162e230034491ac10bfc386356a94d@deuxpi.ca>
> Organization: 60's Burnout
> Message-ID: <Xns98DF8560483E1Eggplant@63.218.45.252>
> User-Agent: Xnews/5.03.24
> X-No-Archive: yes
> Date: 22 Feb 2007 21:57:02 GMT
> Lines: 36
> X-Complaints-To: abuse@newshosting.com
> Xref: authen.puce.readfreenews.net alt.privacy:218045
>
> Anonyma <anon-bounces@deuxpi.ca> wrote in
> news:29162e230034491ac10bfc386356a94d@de
uxpi.ca:A vortex formed within
> the smokey haze of my alledged mind and became this:
>
> Boy are you a moron. I'd use remailers for everything and stay anonymous
> if I were going to be 2 people. Yeah, I've forgotten to change nics on my
> Xnews. But I don't use remailers. You're way off base as usual.
>
> -------------------------------------


A troll that can't read headers, or a troll who wants to set up and accuse
people of what they themselves are. You're the one that's pathetic fool.

Flush
Ari

2007-06-25, 1:13 am

Reply-To: arisilverstein@yahoo.com
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net HkT5b4/IcW7hPzu/Iyua+QbK5goIlyZb2wc5Ze3onWo+KY3V0W
User-Agent: 40tude_Dialog/2.0.15.1
Bytes: 1561
Xref: number1.nntp.dca.giganews.com alt.privacy:182879 alt.privacy.anon-server:447547

On Mon, 25 Jun 2007 04:28:10 -0000, admin@torrify.com wrote:

> On Jun 24, 9:12 pm, Ari <arisilverst...@yahoo.com> wrote:
>
> ONI? Office of Naval Intel?


Yessir. Going back to early 90s, DARPA handoff. They are keen about
keeping up with their "baby".
Cyberiade.it Anonymous Remailer

2007-06-25, 7:13 am

traveller 66 A.K.A. Eggplant wrote:

> A troll that


<discard!>

Sorry pedofuk, you're owned. You pissed and moaned about someone proving
you confessed to being a pedofuk "with headers" until someone took the
time to do just that. And now that it's been referenced on two different
servers and archived at Google for all times, you're just plain old up
shit creek without your canoe.

Sucks to be you. *laugh*

Anonymous

2007-06-25, 7:13 am

Anonymous wrote:

>
> By Gum you're right! allnews.readfreenews.net still had the whole thread
> hanging around. Wowzers.


<snip repost>

You guys are too good at this shit. My list of links is rapidly turning
into an FAQ. Actually, that's not a bad idea. ;)

** The Truth About Privacy.LIE **

Privacy.LIE sock puppet "traveller 66" exposes himself as a pedophile.

http://groups.google.com/group/alt....85119af1d32a5ae

http://groups.google.com/group/alt....ae?dmode=source

http://groups.google.com/group/alt....7741086f2ff3eb4 (reposted admission)
http://groups.google.com/group/alt....f706a505f078bec (threaded admission)

Privacy.LIE outs one of their customers. Sort of.

http://groups.google.com/group/alt....0b?dmode=source

Privacy.LIE fails to ID yet another Tor node, about a week later.

http://groups.google.com/group/alt....58?dmode=source

http://groups.google.com/group/alt....06?dmode=source

http://groups.google.com/group/alt....db?dmode=source

Privacy.LIE's "security" is exposed.

http://groups.google.com/group/alt....70b6341770f8a78

http://groups.google.com/group/alt....46?dmode=source

Privacy.LIE "fixes" their security issues.

http://groups.google.com/group/alt....6cd101c25c5830b

The world's most recognized security expert dissects Privacy.LIE,

http://www.schneier.com/blog/archiv...oghouse_pr.html

Privacy.LIE engages in nymhopping to defend themselves.

http://www.homelandstupidity.us/200...-to-be-trusted/

Historical Privacy.LIE theft.

http://www.appleby.net/privacy.html

Privacy.LIE theft today.

http://forums.truecrypt.org/viewtopic.php?t=5893
http://www.wilderssecurity.com/showthread.php?p=981542

Goldy

2007-06-25, 7:13 am

I am one of the two people that put together JanusVM.

> regarding networks and anonymity. JanusVM has its own set of problems,


What problems?
I would love to hear what those are. I'm always eager to make it
better.

> and is based upon a design idea I mentioned to someone in the Tor
> project about a year ago.


We did this to try and win the VMware Ultimate Virtual Appliance
Challenge, which we didn't.
Well, I had a few of my own personal reasons as well. ;-)

JanusVM came to be because there were too many applications that
didn't support SOCKS (or Tor), and most of the third-party apps that
"wrap" your app into a SOCKS connection didn't work well in Windows,
if at all.

So we took the simple approach; just tunnel it all into a Linux VM and
handle it there.
And anyone at any time can rip through our VM and see what it's made
of; %100 open source.

Regardless, a transparent proxy approach for Tor has so far proved
itself to be worthy, and that's why we are the ONLY free product
mentioned in the Tor roadmap.
http://tor.eff.org/svn/trunk/doc/de...oadmap-2007.pdf

There has also been a few LiveCD's that have come out recently, which
look quite promising. We are working on our own Live CD, but it'll be
awhile before it's done.

Anyhow, I look forward to seeing your xBMachine on August 3rd......see
you in Vegas. ;-)

traveller 66

2007-06-25, 1:13 pm

Date: Mon, 25 Jun 2007 09:06:21 -0800
Message-ID: <2jo2jw1tw8lq$.fe1we806hr5n$.dlg@40tude.net>
Lines: 21
X-Complaints-To: admin01@privacy.li
Bytes: 1848
Xref: number1.nntp.dca.giganews.com alt.privacy:182903 alt.privacy.anon-server:447560

On Mon, 25 Jun 2007 04:35:20 -0000, admin@torrify.com wrote:

> On Jun 24, 6:19 pm, traveller 66 <nore...@nym.alias.net> wrote:
>
> No worries. That is what key signing is for. If someone claims to be
> me and makes some silly statement, ask them to sign their message
> using my key. I'll probably sign all my posts once I find a good
> reader that can do it.


That's a must do thing for in here.
John Smith

2007-06-25, 1:13 pm

On Mon, 25 Jun 2007 09:06:21 -0800, in article
<2jo2jw1tw8lq$.fe1we806hr5n$.dlg@40tude.net>, traveller 66
<noreply@nym.alias.net> wrote:

>
>That's a must do thing for in here.


*sigh*

Yet, you are too stupid to do so yourself and have been busted a
number of times now using the wrong sock puppet as a
result................

Your stupidity really is priceless.

Now, dance "puppety puppet", dance.

<chuckle>
Cyberiade.it Anonymous Remailer

2007-06-25, 7:13 pm

traveller 66 wrote:

> On Mon, 25 Jun 2007 04:35:20 -0000, admin@torrify.com wrote:
>
>
> That's a must do thing for in here.


** The Truth About Privacy.LIE **

Privacy.LIE sock puppet "traveller 66" exposes himself as a pedophile.

http://groups.google.com/group/alt....85119af1d32a5ae

http://groups.google.com/group/alt....ae?dmode=source

http://groups.google.com/group/alt....7741086f2ff3eb4 (reposted admission)

http://groups.google.com/group/alt....f706a505f078bec (threaded admission)

Privacy.LIE sock puppet traveller/Eggplant confesses to pedophilia.

http://groups.google.com/group/alt....1d4c408a0409dc5

http://groups.google.com/group/alt....02efcc71c44c767

Privacy.LIE sock puppet traveller/Eggplant pretends to argue with himself.

http://groups.google.com/group/alt....1216dc836c9b7f6

Privacy.LIE outs one of their customers. Sort of.

http://groups.google.com/group/alt....0b?dmode=source

Privacy.LIE fails to ID yet another Tor node, about a week later.

http://groups.google.com/group/alt....58?dmode=source

http://groups.google.com/group/alt....06?dmode=source

http://groups.google.com/group/alt....db?dmode=source

Privacy.LIE's "security" is exposed.

http://groups.google.com/group/alt....70b6341770f8a78

http://groups.google.com/group/alt....46?dmode=source

Privacy.LIE "fixes" their security issues.

http://groups.google.com/group/alt....6cd101c25c5830b

The world's most recognized security expert dissects Privacy.LIE,

http://www.schneier.com/blog/archiv...oghouse_pr.html

Privacy.LIE engages in nymhopping to defend themselves.

http://www.homelandstupidity.us/200...-to-be-trusted/

Historical Privacy.LIE theft.

http://www.appleby.net/privacy.html

Privacy.LIE theft today.

http://forums.truecrypt.org/viewtopic.php?t=5893

http://www.wilderssecurity.com/showthread.php?p=981542

traveller 66

2007-06-25, 7:13 pm

On Mon, 25 Jun 2007 17:45:31 GMT, John Smith wrote:

> On Mon, 25 Jun 2007 09:06:21 -0800, in article
> <2jo2jw1tw8lq$.fe1we806hr5n$.dlg@40tude.net>, traveller 66
> <noreply@nym.alias.net> wrote:
>
>
> *sigh*
>
> Yet, you are too stupid to do so yourself and have been busted a
> number of times now using the wrong sock puppet as a
> result................
>
> Your stupidity really is priceless.
>
> Now, dance "puppety puppet", dance.
>
> <chuckle>


Puppets and FUD I leave to you.
Anonymous

2007-06-25, 7:13 pm

traveller 66 wrote:

> On Mon, 25 Jun 2007 04:35:20 -0000, admin@torrify.com wrote:
>
>
> That's a must do thing for in here.


Which is why you've relied on your failed XNA strategy to cover your
filthy pedophile XXX instead of PGP signing everything, huh?

ROTFLMAO!














Anonymous

2007-06-25, 7:13 pm

traveller 66 wrote:

...nobody cares what a pedophile has to say

Privacy.LIE sock puppet "traveller 66" exposes himself as a pedophile.

http://groups.google.com/group/alt....85119af1d32a5ae

http://groups.google.com/group/alt....ae?dmode=source

http://groups.google.com/group/alt....7741086f2ff3eb4 (reposted admission)

http://groups.google.com/group/alt....f706a505f078bec (threaded admission)

Privacy.LIE sock puppet traveller/Eggplant confesses to pedophilia.

http://groups.google.com/group/alt....1d4c408a0409dc5

http://groups.google.com/group/alt....02efcc71c44c767

Goldy

2007-06-26, 7:13 pm

SIDE NOTE:
Both of you, SHUT THE HELL UP! I AM SICK OF HEARING ABOUT YOUR
SERVICE AND THEIR SERVICE AND ALL THE DAMN PUPPETS! Someone asked a
valid question about a new service, so give a valid answer or shut the
hell up if you don't know anything about it. Damn. Take your XXXXing
argument into a private offline channel or something, please. NOBODY
CARES ABOUT PUPPETS OR LIES ANYMORE!!!
----------------------------------------------------------------------------------------

As for XeroBank, I believe they are going to be releasing there
xB_Machine at Defcon in Las Vegas on August 3rd. I will be happy to
give you an update once I see it for myself.

I did however, get a chance to play with the XB Browser. It is the
same as Torpark. It also has "XeroBankPlus.exe" which is
PUTTY(freeware).

So to recap, they are re-using free software to support Tor. If what
you're paying for is the private network they are setting up, then
that seems fair considering bandwidth cost money. If you're paying
for freeware that you can download off the Internet at anytime, then I
wouldn't trust them, but that doesn't seem to be the case....so far.
I'm really curious to see this once it's up and running, and I'll be
happy to give my honest opinion once I can see it for myself.

Until then, I'll stick with my software that I put together (JanusVM)
which is freeware.

admin@torrify.com

2007-06-27, 1:14 am

Kyle,

Yeah, the XeroBankPlus.exe file is putty indeed, actually I think it
is porta-plink. We just named it that so people would know what the
process was when looking at it in the process manager. And of course,
all the xB software is free and open source, as it always was and will
be.

Regarding the xB VM: You shall know the VM, and the VM shall set you
free. And by problems I mean shortcomings, but maybe that is because I
have a different idea of what to construct for the client. You can tag
me offlist if you like and we can discuss.

I'll be giving a small talk on it at defcon. Did you hear about Mike
Perry's talk? I thought it might be of particular interest to you.

Steve

Anonymous

2007-06-27, 7:13 pm

admin wrote:

> Kyle,
>
> Yeah, the XeroBankPlus.exe file is putty indeed, actually I think it
> is porta-plink. We just named it that so people would know what the


So, you're taking other people's work and renaming it, so you can build a
business around providing access to an open network that you're charging
people to use? Then lobbing stones at projects JanusVM which provide
essentially the same functionality as your own project?

And none of that bothers you?

It's no wonder Tor's developers don't much like you. I'm sort of holding
my nose myself and I don't develop that sort of software.

admin@torrify.com

2007-06-29, 7:13 am

http://support.xerobank.com/wiki/doku.php?id=faq

We don't charge anything for the software, we give full credit for all
work, are fully within all license parameters, and don't charge for
access to an open network, only our private high-speed network.
However, your not being a developer elucidates about why you don't
understand licensing. And JanusVM is an excellent project idea, glad
that someone is developing it, as it is small enough to be usable as
network filter but not so big that it is a hassle to download. There
are definitely things I would change about it, but it isn't my
project. But xB Machine is, and it will be around 200MB when we finish
the first version.

Steve

Anonymous

2007-06-29, 7:13 pm

admin wrote:

It might help to quote some of what you're replying to.

> http://support.xerobank.com/wiki/doku.php?id=faq
>
> We don't charge anything for the software, we give full credit for all
> work,


You do not. PuTTY is just one example.

> are fully within all license parameters, and don't charge for
> access to an open network,


You most certainly do charge for access to a free and open network, and
provide access to that free and open network using free and open software
that you've repackaged.

> only our private high-speed network.


Your "high speed private network" has no value what so ever without access
to some outside resource. What you're really selling is anonymous access
to the Internet, and you're providing that by accessing the Tor network.
Period. That's the truth no matter how you try and doublespeak the
"private network" angle.

> However, your not being a developer elucidates about why you don't
> understand licensing.


You need to read for comprehension Steve. I've been developing software
since before you were born. I understand software licensing better than
you ever will. Nobody said you were breaching any licensing agreement in
any case, they said you were breaching normal human ethics and morality by
making money off the hard work of others.

> And JanusVM is an excellent project idea, glad
> that someone is developing it, as it is small enough to be usable as
> network filter but not so big that it is a hassle to download. There
> are definitely things I would change about it, but it isn't my
> project. But xB Machine is, and it will be around 200MB when we finish
> the first version.


So what are these "problems" you hinted at and then shied away from
explaining when that software's developer showed up?

traveller 66

2007-06-29, 7:13 pm

On Fri, 29 Jun 2007 06:39:21 -0000, admin@torrify.com wrote:

> http://support.xerobank.com/wiki/doku.php?id=faq
>
> We don't charge anything for the software, we give full credit for all
> work, are fully within all license parameters, and don't charge for
> access to an open network, only our private high-speed network.
> However, your not being a developer elucidates about why you don't
> understand licensing. And JanusVM is an excellent project idea, glad
> that someone is developing it, as it is small enough to be usable as
> network filter but not so big that it is a hassle to download. There
> are definitely things I would change about it, but it isn't my
> project. But xB Machine is, and it will be around 200MB when we finish
> the first version.
>
> Steve


Just wait until the cyber troll starts posting you up here with FUD, by the
way, can you let me know about the signatures with newsreaders, etc.
Thanks.
George Orwell

2007-06-29, 7:13 pm

Anonymous wrote:

> admin wrote:
>
> It might help to quote some of what you're replying to.
>
>
> You do not. PuTTY is just one example.


I don't understand how this person can claim to be giving full credit to
other software authors when it's not even fully disclosed that "xB" is
essentially TorPark (Portable Firefox + Tor) until asked about it. Or when
just a couple messages ago in this thread he told us he wasn't even clear
about what programs his "xB" package really uses himself, and admits that
information is hidden from users...

Message-ID: <1182905593.892299.81940@n60g2000hse.googlegroups.com>

"Yeah, the XeroBankPlus.exe file is putty indeed, actually I think it
is porta-plink. We just named it that so people would know what the
process was when looking at it in the process manager. And of course,
all the xB software is free and open source, as it always was and will
be."

Anonymous

2007-06-29, 7:13 pm

Anonymous wrote:

> admin wrote:
>
> It might help to quote some of what you're replying to.
>
>
> You do not. PuTTY is just one example.
>
>
> You most certainly do charge for access to a free and open network, and
> provide access to that free and open network using free and open software
> that you've repackaged.
>
>
> Your "high speed private network" has no value what so ever without access
> to some outside resource. What you're really selling is anonymous access
> to the Internet, and you're providing that by accessing the Tor network.
> Period. That's the truth no matter how you try and doublespeak the
> "private network" angle.


If anyone has any doubts about this at all I have a private email exchange
with Steve where he tried to convince me that he could make the Tor
network work so much faster because all his alleged "secret" servers were
located in the same data centers as "Tor backbone servers". When I pointed
out there's no such thing as "Tor backbone servers" he tried to pass off
directory servers as some sort of high speed Tor nodes, flip flopped to
just "fast nodes", and then called me a 17 year old kid living in France.

I admit I was talking down a bit to see how he would respond, but I fail
to see why he thinks being French is some sort of insult....??

I'm also waiting to see if he makes the same mistakes another well known
anonymity service just made. ;-)









Anonymous Sender

2007-06-29, 7:13 pm

traveller 66 wrote:

> Just wait until the cyber troll starts posting you up here with FUD,


You mean "FUD" as in this crushing collection of documented Privacy.LIE
theft, lies, scams, racism, and moral debauchery? The informative fact
sheet with even more links being added all the time because you're just
too damned stupid to keep from making yourself look like a total XXXXXXX
every time we bait you into another pissing contest?

Is THIS the "FUD" you're referring to, pedophile....


** The Truth About Privacy.LIE **

Privacy.LIE sock puppet "traveller 66" exposes himself as a pedophile.

http://groups.google.com/group/alt....85119af1d32a5ae

http://groups.google.com/group/alt....ae?dmode=source

http://groups.google.com/group/alt....7741086f2ff3eb4 (reposted admission)

http://groups.google.com/group/alt....f706a505f078bec (threaded admission)

Privacy.LIE sock puppet traveller/Eggplant confesses to pedophilia.

http://groups.google.com/group/alt....1d4c408a0409dc5

http://groups.google.com/group/alt....02efcc71c44c767

Privacy.LIE sock puppet traveller/Eggplant pretends to argue with himself.

http://groups.google.com/group/alt....1216dc836c9b7f6

Privacy.LIE outs one of their customers. Sort of.

http://groups.google.com/group/alt....0b?dmode=source

Privacy.LIE fails to ID yet another Tor node, about a week later.

http://groups.google.com/group/alt....58?dmode=source

http://groups.google.com/group/alt....06?dmode=source

http://groups.google.com/group/alt....db?dmode=source

Privacy.LIE's "security" is exposed.

http://groups.google.com/group/alt....70b6341770f8a78

http://groups.google.com/group/alt....46?dmode=source

Privacy.LIE "fixes" their security issues.

http://groups.google.com/group/alt....6cd101c25c5830b

The world's most recognized security expert dissects Privacy.LIE,

http://www.schneier.com/blog/archiv...oghouse_pr.html

Privacy.LIE engages in nymhopping to defend themselves.

http://www.homelandstupidity.us/200...-to-be-trusted/

Historical Privacy.LIE theft.

http://www.appleby.net/privacy.html

Privacy.LIE theft today.

http://forums.truecrypt.org/viewtopic.php?t=5893

http://www.wilderssecurity.com/showthread.php?p=981542

More informative Privacy.LIE links

http://www.maildropnet.com/scams.htm

http://www.appleby.net/netscam/currentscam.html

http://www.ptshamrock.com/shame.htm

http://www.privacyworld.com/scams.htm

http://www.gatago.com/alt/privacy/5568908.html

http://archive.mail-list.com/privacyworld/msg00212.html

http://www.newsbackup.com/about1061381.html

http://www.hyipdiscussion.com/due-d...nteresting.html

http://www.velocityreviews.com/foru...privacylie.html

http://www.privacy-consultants.com/ and then...
http://www.appleby.net/netscam/FPCscam.html

Dr. §¤¤§

2007-06-30, 1:14 am

"Anonymous" <mix@awxcnx.de> wrote in message
news:06b985c967b3adb715617b43aba2f003@aw
xcnx.de...
> If anyone has any doubts about this at all I have a private email exchange
> with Steve where he tried to convince me that he could make the Tor
> network work so much faster because all his alleged "secret" servers were
> located in the same data centers as "Tor backbone servers". When I pointed
> out there's no such thing as "Tor backbone servers" he tried to pass off
> directory servers as some sort of high speed Tor nodes, flip flopped to
> just "fast nodes", and then called me a 17 year old kid living in France.
>
> I admit I was talking down a bit to see how he would respond, but I fail
> to see why he thinks being French is some sort of insult....??
>
> I'm also waiting to see if he makes the same mistakes another well known
> anonymity service just made. ;-)


It'd be nice if he operated like Christian does with OmniMix... he asks for
input, and actually makes substantive changes based upon that input. I think
Christian is building a great program, as well as the trust that will make
the program widely adopted.

I can understand that sometimes it's hard to be nice to a person who's
talking down to you, but if you're running a business, keeping your cool and
holding your tongue (as it were) while allowing people to vent goes a long
way toward smoothing over any rough spots.

So, his quip about you being an adolescent French citizen probably was a big
mistake.

There's a time to be nice, and there's a time to crack someone upside the
head... knowing which is which is very important.


George Orwell

2007-06-30, 1:14 am

traveller 66 wrote:

> On Fri, 29 Jun 2007 06:39:21 -0000, admin@torrify.com wrote:
>
>
> Just wait until the cyber troll starts posting you up here with FUD, by the
> way, can you let me know about the signatures with newsreaders, etc.
> Thanks.


Looking for some new raw material to carve pedoXXXX sock puppets from
now that you've destroyed the old ones with your stupidity are you?

http://groups.google.com/group/alt....7741086f2ff3eb4

"Yeah, I've forgotten to change nics on my Xnews."

ROTFL!









Anonymous

2007-06-30, 1:12 pm

> It'd be nice if he operated like Christian does with OmniMix... he asks for
> input, and actually makes substantive changes based upon that input. I think
> Christian is building a great program, as well as the trust that will make
> the program widely adopted.


Unlikely. No source code, no trust.


Dr. §¤¤§

2007-06-30, 1:12 pm

"Anonymous" <cripto@ecn.org> wrote in message
news:4ce8b84e31d1af2a99c97e3528deae9b@ec
n.org...
>
> Unlikely. No source code, no trust.


Yabbut, there are other ways to determine if a program is acting the way
it's supposed to (how many people can actually parse through the source code
and determine what it does, anyway?)... you can run a local proxy and funnel
all connections through that to watch all connections and log where
everything's connecting to, you can set up your router to report all the
connections to your machine, etc. And, you can strip system permissions from
it so it can't really damage your system if it happens to obtain a nasty.

So far, I've not noticed anything untoward happening with OmniMix.

Although it would be nice if it were open source... the coding I've done, I
kept closed source until I got the code perfected (mainly because I was a
bit embarrassed about the state of the code), but opened it up once it was
working the way I wanted and the code was cleaned up.

Christian understands that to gain trust, he's got to open-source it. Give
it time. Until then, rely upon the fact that he's dealt squarely with us,
he's taking suggestions and bug reports, and he's actively working to
perfect the program... all without an attitude. That's a big factor in my
book.

Plus, once it's open-source, there could be a lot more people working on it
to extend it in ways Christian probably hasn't even dreamed of (anonymous
VOIP, anyone?).

Myself, I don't worry so much about being locked-down anonymous... I've
already been 'outed' (my picture, email address, work address, home address,
telephone number, etc. published to usenet) by a kook years ago... it just
served to amuse me and earn that kook some awards. My contact information
has since changed, so I'm not 'jumping at the chance' to have it published
again, though.

But, I'm willing to run OmniMix... it works well, is easy to use and does
exactly what I need it to do... namely: allow me to poke kooks with pointy
sticks while remaining anonymous.

It's a hobby, don'tcha know.


Borked Pseudo Mailed

2007-06-30, 1:12 pm

Dr. §¤¤§ wrote:

> "Anonymous" <cripto@ecn.org> wrote in message
> news:4ce8b84e31d1af2a99c97e3528deae9b@ec
n.org...
>
> Yabbut, there are other ways to determine if a program is acting the way
> it's supposed to (how many people can actually parse through the source code
> and determine what it does, anyway?)... you can run a local proxy and


One person reviewing source is infinitely better than zero people reviewing
source. It has absolutely nothing at all to do with "how many" or the
tired old red herring about each individual reviewing their own copy.

Peer review DOES work. The last three serious bugs in GnuPG were found by
third parties, just to offer one in a list of so many real life examples
I'm surprised there's anyone left with the lack of self respect it takes
to argue against OSS being anything but an advantage.

There's no penalty to releasing source code. It doesn't weaken security in
any way, it only enhances it.

There's only two reasons an author of this type of software would refuse
to release source. They're either hiding something, be it intentionally
evil or otherwise, or they're not confident enough in their own coding
skills to display them for public scrutiny.

Christian is obviously the latter, he's plainly stated so. And from the
evidence presented here he's possibly also one of the the former.

> funnel all connections through that to watch all connections and log
> where everything's connecting to, you can set up your router to report
> all the connections to your machine, etc. And, you can strip system
> permissions from it so it can't really damage your system if it happens
> to obtain a nasty.


Why would you assume the only bad things a program might do will be
observable on the wire? That would be the most useless way for an actual
attacker to code in a "back door" for a couple of reasons. It would be
easy to spot for one, and it would require the attacker to monitor those
connections. Activity that's also easy to spot. It's also one of the most
unlikely accidental problems a programmer might code into a piece of
software. It's pretty hard to "mistakenly" code TCP connections to
arbitrary destinations. In fact I'd say it's next to impossible without
completely breaking the software.

A far more likely scenario is something that nobody would be able to see
by observation like an error in the steps used to encrypt a message or
some sort of subtle "pattern" being injected into the messages themselves
which compromises anonymity. Or even a conceptual flaw like improperly
using other software in ways that diminish their effectiveness.

> It's a hobby, don'tcha know.


I'm tempted to scream "SHUT UP EELBASH!" here. ;)

As has been pointed out, this "hobby" has a serious impact on some people
and in some corners of the world. Your "hobby" is another (wo)man's life
or death situation.

Dr. §¤¤§

2007-06-30, 1:12 pm

"Borked Pseudo Mailed" <nobody@pseudo.borked.net> wrote in message
news:b567c8549784a2cfa86b3c6502a6b93e@ps
eudo.borked.net...
> Peer review DOES work. The last three serious bugs in GnuPG were found by
> third parties, just to offer one in a list of so many real life examples
> I'm surprised there's anyone left with the lack of self respect it takes
> to argue against OSS being anything but an advantage.


Oh, I'm not arguing against OSS being anything but an advantage... I'm just
saying that we should let Christian get his code cleaned up and
presentable... I know I'd hate for anyone to see my initial spaghetti code
before it's cleaned up.

He seems sincere in his desire to help... I guess it's just my basic
weakness to trust people who seem sincere, but I can't seem to become so
jaded that I don't trust *anybody*.


> Christian is obviously the latter, he's plainly stated so. And from the
> evidence presented here he's possibly also one of the the former.


?? You'll have to show that to me, I haven't seen it.


> A far more likely scenario is something that nobody would be able to see
> by observation like an error in the steps used to encrypt a message or
> some sort of subtle "pattern" being injected into the messages themselves
> which compromises anonymity. Or even a conceptual flaw like improperly
> using other software in ways that diminish their effectiveness.


Ah, yes. I see your point. It'd be kind of hard to modify the headers or the
body without anyone picking up on it, I'd think, but I could definitely
envision some sort of fiddling with the encryption to make it easier to
decrypt en-route.


>
> I'm tempted to scream "SHUT UP EELBASH!" here. ;)


Heh. No, the kook / pointy stick thing is the hobby. My alter-ego allows me
more fun than I could ever have in real life. I know, I know... I have no
life. Meh, what can one do, right?


> As has been pointed out, this "hobby" has a serious impact on some people
> and in some corners of the world. Your "hobby" is another (wo)man's life
> or death situation.


Yeah, I understand that... fortunately for me, I live in a (relatively) free
country.


traveller 66

2007-06-30, 1:12 pm

On Sat, 30 Jun 2007 03:59:22 +0200 (CEST), George Orwell wrote:

> traveller 66 wrote:
>
>
> Looking for some new raw material to carve pedoXXXX sock puppets from
> now that you've destroyed the old ones with your stupidity are you?
>
> http://groups.google.com/group/alt....7741086f2ff3eb4
>
> "Yeah, I've forgotten to change nics on my Xnews."
>
> ROTFL!


No you have, and you really do need professional help.
Dr. §¤¤§

2007-06-30, 7:13 pm

"traveller 66" <noreply@nym.alias.net> wrote in message
news:1hs01bo9ce6s3.1qcnlzr1lq1tx$.dlg@40tude.net...
> No you have, and you really do need professional help.


Weak. You sound whipped... are you?


Anonymous

2007-06-30, 7:13 pm

Dr. §¤¤§ wrote:

> "Borked Pseudo Mailed" <nobody@pseudo.borked.net> wrote in message
> news:b567c8549784a2cfa86b3c6502a6b93e@ps
eudo.borked.net...
>
> Oh, I'm not arguing against OSS being anything but an advantage... I'm just
> saying that we should let Christian get his code cleaned up and
> presentable... I know I'd hate for anyone to see my initial spaghetti code
> before it's cleaned up.


His code should be cleaned up and presentable before he ever releases the
software. Sloppy code means buggy programs, and we've already seen real
life examples of that from OM. Glaring examples like the misplaced hash
header (?) bug of late.

If it's not ready for peer review it certainly isn't ready for production.
That's even worse than simply not releasing source because you don't care
to, or honestly believe it's some sort of risk. If you're releasing
software compiled from code you know is so substandard you don't want
anyone else to see it you're doing something very wrong.

> He seems sincere in his desire to help... I guess it's just my basic
> weakness to trust people who seem sincere, but I can't seem to become so
> jaded that I don't trust *anybody*.


I agree, he seems sincere. So does Steve Topletz, but both of them are
still missing the mark by miles in some pretty major ways.

>
> ?? You'll have to show that to me, I haven't seen it.


His own confessions regarding his coding practices are known, even if the
endless repeating of the "as soon as I get it cleaned up" excuse weren't
enough. It doesn't take that long to clean up working code. If it does,
the code is broken by the very definition of the term.

>
> Ah, yes. I see your point. It'd be kind of hard to modify the headers or the
> body without anyone picking up on it, I'd think, but I could definitely
> envision some sort of fiddling with the encryption to make it easier to
> decrypt en-route.


Or break the encryption entirely. Or misrepresent what chains are used to
redirect everything to an evil node or nodes, and then "remix" to another
legit node to give an appearance of propriety. Or manage headers in such a
way that certain sequences are known or predictable according to some
unique feature of a particular installation. Or.... I can think of
probably a hundred ways to partially or fully compromise the remailer
network without making it as easy to spot as "phoning home".

>
> Heh. No, the kook / pointy stick thing is the hobby. My alter-ego allows me
> more fun than I could ever have in real life. I know, I know... I have no
> life. Meh, what can one do, right?


Ahhhh... gotcha. ;)

>
> Yeah, I understand that... fortunately for me, I live in a (relatively)
> free country.


Is there really any such place left on this planet? That isn't a small
tropical island nobody really cares about because it so remote it's
useless? ;)

Anonymous

2007-06-30, 7:13 pm

travellerpuppet #66 A.K.A. Georg "Slimeball" Adem wrote:

> need professional help.


Yes you do...

http://groups.google.com/group/alt....1d4c408a0409dc5

"No babies in my posts. Young and adolescent girls showing off for the
camera knowing exactly what they're doing are not babies."

http://groups.google.com/group/alt....02efcc71c44c767

"most know my prefered age for pics to view are budding 12 - 14 year olds."

You're a sick, putrid excuse for human life. The lowest form of shit.
The professional help you deserve is a slow death at the hands of a highly
skilled marksman. Knees first, then go to work on the shoulders
and elbows. Maybe an ear. Then when you've started confessing your sins
and begging for that telling shot to the head, you should be left to bleed
out in agony.

Anonymous

2007-06-30, 7:13 pm

traveller 66 wrote:

...nothing of any value

** The Truth About Privacy.LIE **

Privacy.LIE sock puppet "traveller 66" exposes himself as a pedophile.

http://groups.google.com/group/alt....85119af1d32a5ae

http://groups.google.com/group/alt....ae?dmode=source

http://groups.google.com/group/alt....7741086f2ff3eb4 (reposted admission)

http://groups.google.com/group/alt....f706a505f078bec (threaded admission)

Privacy.LIE sock puppet traveller/Eggplant confesses to pedophilia.

http://groups.google.com/group/alt....1d4c408a0409dc5

http://groups.google.com/group/alt....02efcc71c44c767

Privacy.LIE sock puppet traveller/Eggplant pretends to argue with himself.

http://groups.google.com/group/alt....1216dc836c9b7f6

Privacy.LIE outs one of their customers. Sort of.

http://groups.google.com/group/alt....0b?dmode=source

Privacy.LIE fails to ID yet another Tor node, about a week later.

http://groups.google.com/group/alt....58?dmode=source

http://groups.google.com/group/alt....06?dmode=source

http://groups.google.com/group/alt....db?dmode=source

Privacy.LIE's "security" is exposed.

http://groups.google.com/group/alt....70b6341770f8a78

http://groups.google.com/group/alt....46?dmode=source

Privacy.LIE "fixes" their security issues.

http://groups.google.com/group/alt....6cd101c25c5830b

The world's most recognized security expert dissects Privacy.LIE,

http://www.schneier.com/blog/archiv...oghouse_pr.html

Privacy.LIE engages in nymhopping to defend themselves.

http://www.homelandstupidity.us/200...-to-be-trusted/

Historical Privacy.LIE theft.

http://www.appleby.net/privacy.html

Privacy.LIE theft today.

http://forums.truecrypt.org/viewtopic.php?t=5893

http://www.wilderssecurity.com/showthread.php?p=981542

More informative Privacy.LIE links

http://www.maildropnet.com/scams.htm

http://www.appleby.net/netscam/currentscam.html

http://www.ptshamrock.com/shame.htm

http://www.privacyworld.com/scams.htm

http://www.gatago.com/alt/privacy/5568908.html

http://archive.mail-list.com/privacyworld/msg00212.html

http://www.newsbackup.com/about1061381.html

http://www.hyipdiscussion.com/due-d...nteresting.html

http://www.velocityreviews.com/foru...privacylie.html

http://www.privacy-consultants.com/ and then...
http://www.appleby.net/netscam/FPCscam.html

Anonymous Sender

2007-06-30, 7:13 pm

Anonymous wrote:

> travellerpuppet #66 A.K.A. Georg "Slimeball" Adem wrote:
>
>
> Yes you do...
>
> http://groups.google.com/group/alt....1d4c408a0409dc5
>
> "No babies in my posts. Young and adolescent girls showing off for the
> camera knowing exactly what they're doing are not babies."
>
> http://groups.google.com/group/alt....02efcc71c44c767
>
> "most know my prefered age for pics to view are budding 12 - 14 year olds."
>
> You're a sick, putrid excuse for human life. The lowest form of shit.
> The professional help you deserve is a slow death at the hands of a highly
> skilled marksman. Knees first, then go to work on the shoulders
> and elbows. Maybe an ear. Then when you've started confessing your sins
> and begging for that telling shot to the head, you should be left to bleed
> out in agony.


I like Charlie Daniels' solution...

"Just take them rascals out in the swamp,
putt'm on their knees and tie'm to a stump,
and let the rattlers and the bugs and alligators do the rest."

Why waste expensive bullets? ;-)











Anonymous Sender

2007-06-30, 7:13 pm

rover wrote:

> -----BEGIN PGP MESSAGE-----


Look everyone, I cracked PGP! ;-)

<cut>
On Sat, 30 Jun 2007, "Dr. §¤¤§" <§¤¤§@dodgeit.com> wrote:
>"Anonymous" <cripto@ecn.org> wrote in message
> news:4ce8b84e31d1af2a99c97e3528deae9b@ec
n.org...
>
>Yabbut, there are other ways to determine if a program is acting the way
>it's supposed to (how many people can actually parse through the source code
>and determine what it does, anyway?)...


I can. It used to be part of my job.

<SNIP>
>
>But, I'm willing to run OmniMix... it works well, is easy to use and does
>exactly what I need it to do... namely: allow me to poke kooks with pointy
>sticks while remaining anonymous.
>
>It's a hobby, don'tcha know.


Trolling is a hobby?
</cut>


Anonymous

2007-06-30, 7:13 pm

rover wrote:

<snip ASCII armored message>

Maybe you should try clearsigning instead?

Anonymous Sender

2007-06-30, 7:13 pm

Dr. §¤¤§ wrote:

> "traveller 66" <noreply@nym.alias.net> wrote in message
> news:1hs01bo9ce6s3.1qcnlzr1lq1tx$.dlg@40tude.net...
>
> Weak. You sound whipped... are you?


Bet he says no. ;)

Dr. §¤¤§

2007-07-01, 1:14 am

"Anonymous Sender" <anonymous@remailer.metacolo.com> wrote in message
news:f44ddaba4848f136a8862f0910ec6760@re
mailer.metacolo.com...

> Trolling is a hobby?


Well, I was thinking of turning it into a livelihood... if you payerz me 5
Quatloos, I won't torll you.

:-)


George Orwell

2007-07-01, 1:13 pm

>His code should be cleaned up and presentable before he ever releases the
>software. Sloppy code means buggy programs, and we've already seen real
>life examples of that from OM. Glaring examples like the misplaced hash
>header (?) bug of late.
>
>If it's not ready for peer review it certainly isn't ready for production.
>That's even worse than simply not releasing source because you don't care
>to, or honestly believe it's some sort of risk. If you're releasing
>software compiled from code you know is so substandard you don't want
>anyone else to see it you're doing something very wrong.


If Mixmaster had followed the same strategy of logging everything it
does, we wouldn't have this discussion. OmniMix hands over raw data
to Mixmaster, which processes them and returns the result. With each
step (client -> OmniMix -> Mixmaster -> OmniMix -> SMTP server)
checking the few lines of transmitted data at both ends and finding
out any irregularity would be a solvable task even for an elementary
pupil. No need to interpret thousands of lines of source code.

Bear in mind, it took more than half a year for the community to
stumble on the '##' problem, though OmniMix offered all the data
necessary to figure it out and each header literally yelled out
'X-Invalid: ##'. But nobody cared. Nobody went to the trouble of
reading so much as the logs presented. Whom then do you expect to
read the Delphi sources and find the crucial bug or back door you
expect? And I've no idea which TCP/IP protocol manipulation one can
have in mind that isn't overcome at least at the second remailer.

That's why in my opinion your words are nothing but hypocritical
blather and pomposity.

>Or break the encryption entirely. Or misrepresent what chains are used to
>redirect everything to an evil node or nodes, and then "remix" to another
>legit node to give an appearance of propriety. Or manage headers in such a
>way that certain sequences are known or predictable according to some
>unique feature of a particular installation. Or.... I can think of
>probably a hundred ways to partially or fully compromise the remailer
>network without making it as easy to spot as "phoning home".


That's exactly what only Mixmaster itself would be capable of. But
for years now nobody cares about where the Disastry files actually
came from and everyone relies on the source code presented belonging
to the application executed by all QuickSilver and OmniMix users day
in, day out. That's where I see the real threat. Add some file
logging facility of its in- and output, rebuild it and you end up with
a system transparent for review from the client software over to the
entry remailer. And by review I don't mean review just by the
fictious software expert you hope to do the job of rummaging through
the code, but review by every user herself without taking up a great
deal of time. That's the security I'd like to have.

Rango

Anonymous

2007-07-01, 1:13 pm

George Orwell wrote:

>
> If Mixmaster had followed the same strategy of logging everything it
> does, we wouldn't have this discussion. OmniMix hands over raw data
> to Mixmaster, which processes them and returns the result. With each
> step (client -> OmniMix -> Mixmaster -> OmniMix -> SMTP server)
> checking the few lines of transmitted data at both ends and finding
> out any irregularity would be a solvable task even for an elementary
> pupil. No need to interpret thousands of lines of source code.


Utter nonsense. there's uncountable subtle and not so subtle things OM
could do to partition and out users that you'd never be able to spot.
Remember that OM determineds what chains are built. Also remember that
BY DESIGN OM builds very weak chains.

> Bear in mind, it took more than half a year for the community to
> stumble on the '##' problem, though OmniMix offered all the data
> necessary to figure it out and each header literally yelled out
> 'X-Invalid: ##'. But nobody cared. Nobody went to the trouble of


In your mind nobody cared. In reality some of us knew about X-Invalid but
kept the information to ourselves. Some of us know about other things OM
and other clients do too, but wont tell because that information is an
advantage when dealing with trolls like you. And now that the cat is out
of the bag anyon co go back through messages retrospectively and pick out
certain OM messages, discover patterns, etc. So EVERYBODY should care.

> reading so much as the logs presented. Whom then do you expect to
> read the Delphi sources and find the crucial bug or back door you
> expect? And I've no idea which TCP/IP protocol manipulation one can
> have in mind that isn't overcome at least at the second remailer.
>
> That's why in my opinion your words are nothing but hypocritical
> blather and pomposity.


Your opinion on the issue is meaningless because you're not bright
enough to understand a mail client that uses mixmaster to encrypt
messages can defeat mixmaster. Take this stupidity for example:

>
> That's exactly what only Mixmaster itself would be capable of. But


Idiot. One more time for our slower readers: OMNIMIX IS IN TOTAL CONTROL
OF WHICH CHAINS ARE BUILT. <sheesh!> We just HAD this discussion and even
Christian agreed that sending every copy of every message to a single
remailer was a problem.

And how do you know for a fact OM actually uses mixmaster to encrypt?

You don't.


> for years now nobody cares about where the Disastry files actually
> came from and everyone relies on the source code presented belonging
> to the application executed by all QuickSilver and OmniMix users day
> in, day out. That's where I see the real threat. Add some file


You really are an idiot. Not only has mixmaster progressed beyond the
Disastry days, the source code is compiled into an executable that's easy
to verify. When you're done making a fool of yourself you may want to stop
by the Sourceforge download page. f you're wide awake and at your best you
MIGHT just figure out that those .sig downloads have something to do with
file integrity.

> logging facility of its in- and output, rebuild it and you end up with
> a system transparent for review from the client software over to the
> entry remailer. And by review I don't mean review just by the
> fictious software expert you hope to do the job of rummaging through
> the code, but review by every user herself without taking up a great
> deal of time. That's the security I'd like to have.


You're beyond dumb. You have absolutely no clue what you're talking about.

>
> Rango

<