<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xinophobia &#187; Firewall</title>
	<atom:link href="http://www.xinophobia.com/category/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xinophobia.com</link>
	<description>You ARE paranoid and they ARE out to get you.</description>
	<lastBuildDate>Sat, 01 Aug 2009 23:25:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pretty Great Firewall</title>
		<link>http://www.xinophobia.com/2008/07/pretty-great-firewall/</link>
		<comments>http://www.xinophobia.com/2008/07/pretty-great-firewall/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 05:49:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.xinophobia.com/?p=88</guid>
		<description><![CDATA[The strategy here is going to change a little bit. My original assumption about the Internet access control mechanisms was that the rules would be fairly static. This has proven to not be the case. Given the upcoming Olympic Games, I believe that access is going to be much less restrictive than usual and that [...]]]></description>
			<content:encoded><![CDATA[<p>The strategy here is going to change a little bit. My original assumption about the Internet access control mechanisms was that the rules would be fairly static. This has proven to not be the case. Given the upcoming Olympic Games, I believe that access is going to be much less restrictive than usual and that changes will be made very quickly.</p>
<p>As of 7/12/08:</p>
<p>Domains not reachable:</p>
<p>- facebook.com (was reachable on 6/29/08)<br />
- icanhascheezburger.com (was previously able to load site without pictures but now totally unreachable)<br />
- uncyclopedia.com<br />
- torproject.org<br />
- dit-inc.us</p>
<p>Domains reachable:</p>
<p>- cnn.com<br />
- bbc.co.uk<br />
- xkcd.com<br />
- wikipedia.org</p>
<p>The combination of Privoxy+Tor is again successful in accessing the blocked sites.<br />
I chose to use this method because of its usability: free, well-integrated into popular browsers, and easy to setup.</p>
<p>However, there are several importants caveats to using tor:</p>
<p>- The network as it exists will not support connections requiring a lot of bandwidth (i.e. bittorrent, massive file transfers, etc.). It will work but it will be extremely slow. I need to stress that such usage will also have a negative impact on other tor users.<br />
- The software is experimental and should not be relied upon for strong anonymity.<br />
- The most reliable source for software and updates (torproject.org) is not reachable without a working copy of Tor.<br />
- Very few entry nodes are reachable. This raises some serious questions about the immediate security and long-term viability of Tor.</p>
<p>In my 80 hours or so logged into a functional circuit, I have seen only three distinct entry nodes. From a security standpoint, it is easy to believe that these entry nodes are planted or otherwise compromised to allow monitoring. Even if the entries are legitimate, it wouldn&#8217;t be hard to shutdown the network entirely. I leave this as an exercise to the reader.</p>
<p>There is an interesting paper on timing attacks for any onion router network:<br />
Low-Resource Routing Attacks Against Anonymous Systems by Kevin Bauer, Damon McCoy, Dirk Grunwald, Tadayoshi Kohno, Douglas Sicker<br />
<a href="http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf" target="_blank"> http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf</a></p>
<p>There are many alternatives to Tor which I will decline to list here. One that I am investigating is FreeGate: <a href="http://dit-inc.us" target="_blank">dit-inc.us</a>.</p>
<p>I encourage readers to have a plan of action in case Internet access is restricted in their area. What tools do you have immediately available to facilitate a breakout? If you don&#8217;t usually encrypt communications (i.e. pgp or some variant), will you want/need to? How many of your contacts will you be able to reach via other means (secure or not)?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xinophobia.com/2008/07/pretty-great-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Great Firewall or Greatest Firewall?</title>
		<link>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/</link>
		<comments>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 02:57:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Reports]]></category>

		<guid isPermaLink="false">http://www.xinophobia.com/?p=18</guid>
		<description><![CDATA[(quick update, full post to follow&#8230;)
Sites that are accessible:
- Gmail over 128bit SSL
- International Google
- myspace.com (not confirmed entirely accessible)
- facebook.com (ssl login okay)
Domains not accessible:
- wordpress.com
- livejournal.com
- meetup.com
- bbc.co.uk
Tools used:
- Vidalia (Tor) and privoxy
- open proxies from proxy.org
Success on all blocked sites with the above combination.
It took a LONG time to grab the list [...]]]></description>
			<content:encoded><![CDATA[<p>(quick update, full post to follow&#8230;)</p>
<p>Sites that are accessible:</p>
<p>- Gmail over 128bit SSL</p>
<p>- International Google</p>
<p>- myspace.com (not confirmed entirely accessible)</p>
<p>- facebook.com (ssl login okay)</p>
<p>Domains not accessible:</p>
<p>- wordpress.com</p>
<p>- livejournal.com</p>
<p>- meetup.com</p>
<p>- bbc.co.uk</p>
<p>Tools used:</p>
<p>- Vidalia (Tor) and privoxy</p>
<p>- open proxies from proxy.org</p>
<p>Success on all blocked sites with the above combination.</p>
<p>It took a LONG time to grab the list of relays in the Tor network. Given how few entry points there were, I suspect that most of the entry points are blocked. Tor has to find at least one open entry, pull an updated list of relays and then try to build a connection. I would not rely upon this method in the long term. Sad, but true.</p>
<p>Note on open proxies: use as much caution as you would any unfamiliar website. Many open proxies are heavily polluted with ads, pop-ups and worse. Proxies based out of your country may be your best bet.</p>
<p>(The next update may take a while. I only slept 3 hours before my flight and am experiencing just a touch more jetlag than expected. Crashing in 3&#8230;2&#8230;1&#8230;)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>On the other side of the world&#8230;</title>
		<link>http://www.xinophobia.com/2008/06/on-the-other-side-of-the-world/</link>
		<comments>http://www.xinophobia.com/2008/06/on-the-other-side-of-the-world/#comments</comments>
		<pubDate>Sat, 28 Jun 2008 18:32:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.xinophobia.com/?p=4</guid>
		<description><![CDATA[On the other side of the world&#8230;
&#8230;there is a Great Firewall looming over the webscape. Like any good defensive wall it  keeps out invaders. Yet, the oft unnoticed aspect of walls is perhaps just as important. It keeps people in. Whether the wall is cyber or physical, it sends a not-so-subtle message that &#8220;We [...]]]></description>
			<content:encoded><![CDATA[<p>On the other side of the world&#8230;</p>
<p>&#8230;there is a Great Firewall looming over the webscape. Like any good defensive wall it  keeps out invaders. Yet, the oft unnoticed aspect of walls is perhaps just as important. It keeps people in. Whether the wall is cyber or physical, it sends a not-so-subtle message that &#8220;We are all you should be interested in. There is nothing out there that a right-thinking person would want to see.&#8221;</p>
<p>Let me point out that this is true to some degree everywhere. Some methods are explicit. Others are far more insidious &#8211; a subtle manipulation of reality. But this is a topic for another time.</p>
<p>Like the typical wrong-thinking person, I have become accustomed to my free access to the Internet. Being unwilling to give it up, I have prepared for a small scale inspection of this Wall with just a touch of breaching as required.</p>
<p>First would be a survey of what is actually allowed and prohibited. The easy way is to hit the hotspots: wikipedia, major news sites, blog hosting sites, etc.</p>
<p>Next step is to examine what tools remain accessible. Are open proxies still available? How about the Tor network? One can quickly get a feel for if/what kind of crackdown has been made. The availability of some kind of open access, even sporadic, would have a huge impact on the success of breakout attempts. Open access means a chance to download new tools, refresh lists of proxies, exchange information and in short, buy oneself a little more time.</p>
<p>Finally, I will examine what methods are required to reach the blocked content. Personally, I suspect that one method will work for everything but there are inherent risks in being a one-trick pony. The sentries, though lumbering, are always moving. Sitting still is one of the best ways to find yourself locked down. Without outside assistance, it could be very difficult to break free again.</p>
<p>Reports on the above are forthcoming over the next week. Silence on the wire would suggest a much stronger adversary than I had anticipated.</p>
<p>To leave you with a bit of concrete information, I present the following tips on finding power outlets at airports.</p>
<p>1) Endeavor to fly through good airports and on good airlines. The Southwest terminal in Austin-Bergstrom has laptop bars setup with stools and a raised counter with two outlets per person. Good for your cell phone, too! The Continental terminal at Newark International actually has most outlets covered up with metal plates. Which leads me to number two.</p>
<p>2) Look around you for electronic devices. TVs, speakers, lighted signs, etc. all require power. If they&#8217;re going to wire those signs, it wouldn&#8217;t be too much of a stretch to place an outlet on the floor or wall. Electric cart parking/recharging areas by definition have power. Construction vehicles used indoors are usually electric. Discovering where they charge is akin to finding the lair of a dragon.</p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/adj-tix-machine.jpg"><img class="aligncenter size-full wp-image-7" title="adj-tix-machine" src="http://www.xinophobia.com/wp-content/uploads/2008/06/adj-tix-machine.jpg" alt="Next to the self-serve ticket machine" width="352" height="300" /></a></p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/cart-charging.jpg"><img class="aligncenter size-full wp-image-9" title="cart-charging" src="http://www.xinophobia.com/wp-content/uploads/2008/06/cart-charging.jpg" alt="Cart charging area" width="346" height="300" /></a></p>
<p>3) Wander into an empty part of the terminal and look for others with electronics. These people may have done the work for you.</p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/you-know-he-has-power.jpg"><img class="aligncenter size-full wp-image-6" title="you-know-he-has-power" src="http://www.xinophobia.com/wp-content/uploads/2008/06/you-know-he-has-power.jpg" alt="You know he has power" width="400" height="300" /></a></p>
<p>4) Check near pillars and other structural supports.. An unadorned pillar may have surveillance or NBC detection equipment inside. Water fountains also require beaucoup electricity.</p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/pillar.jpg"><img class="aligncenter size-full wp-image-12" title="pillar" src="http://www.xinophobia.com/wp-content/uploads/2008/06/pillar.jpg" alt="Pillar" width="400" height="295" /></a></p>
<p>5) If your desperate, check behind the ticket counters at unused gates. Just be aware that security may not be happy to find you back there.</p>
<p>6) Another last-ditch power source can be found in restrooms. Some models of automatic sinks plug into the wall. Of course, this depends on the type of sink and layout of the bathroom. This is option is wet, conspicuous and difficult to explain.</p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/under-sink.jpg"><img class="aligncenter size-full wp-image-11" title="under-sink" src="http://www.xinophobia.com/wp-content/uploads/2008/06/under-sink.jpg" alt="Under the sink - it\'s gross down there" width="400" height="300" /></a></p>
<p>7) Use your imagination! Observe your environment carefully and take nothing for granted. Even if you have to stand in the middle of the floor and strike a pose while you text.</p>
<p><a href="http://www.xinophobia.com/wp-content/uploads/2008/06/middle-of-the-floor.jpg"><img class="aligncenter size-full wp-image-10" title="middle-of-the-floor" src="http://www.xinophobia.com/wp-content/uploads/2008/06/middle-of-the-floor.jpg" alt="In the middle of the floor" width="358" height="300" /><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xinophobia.com/2008/06/on-the-other-side-of-the-world/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
