17:00:18 #startmeeting anti-censorship weekly checkin 2019-06-27 17:00:18 Meeting started Thu Jun 27 17:00:18 2019 UTC. The chair is phw. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:18 Useful Commands: #action #agreed #help #info #idea #link #topic. 17:00:30 our pad is available here: https://pad.riseup.net/p/tor-censorship-2019-keep 17:00:48 * cohosh is here but partially distracted by another meeting 17:01:09 our only announcement is that right after this meeting, we will continue with our race meeting 17:01:18 :-) 17:01:37 for those of you who don't know: race is a new project that will help us push forward our PT spec and obfs5 17:02:08 next up is our discussion section. the first item is bridgedb. 17:02:35 i'm bringing this up mostly to have an update on what is going on and try to understand plan and priorities for it. 17:02:37 so, bridgedb was rather broken over the last few months and many valid requests for bridgedb resulted in an empty response 17:03:00 i spent a lot of time looking at logs and at the moment it looks like there is no problem... anymore? 17:03:10 https://trac.torproject.org/projects/tor/ticket/30441#comment:17 17:04:05 people got a response from the site with no Bridge lines to use or they got some with unavailable bridges in? 17:04:06 it looks like all valid bridgedb requests currently result in 1-3 bridges 17:04:44 ahf: both, actually, but the problem is primarily the former 17:04:57 ok 17:05:07 so, there are two problems, really: bridgedb giving you an empty response, and bridgedb giving you broken obfs4 bridges 17:05:18 phw: should we ask peopl from front-desk to try it again and let us know? 17:05:20 we should have made progress on both problems 17:05:41 gaba: i think that's a good idea 17:05:58 if y'all wanna give it a try at some point, that would be helpful 17:06:15 try to request bridges over different channels and let me know if bridgedb doesn't give you bridges 17:06:48 late last week i was using some bridges from bridgedb where i thought i couldn't reach them, but i got functioning ones to test #28930 and it turned out it was some network issue on my desktop 17:07:01 no blanks and no non-functioning ones 17:07:33 anyway, even if bridgedb is working again, it's frustrating because i don't fully understand what caused the issues over the last months. 17:08:12 i also had to blacklist ~50 obfs4 bridges whose obfs4 port was unreachable 17:08:42 ouch >.< that's a lot 17:08:51 :/ 17:09:14 i'll try to work with gman to have the bridgeauth reject them, so hopefully the operators see a scary warning in their logs and reach out 17:09:41 do we need to work with community to find a way to get more people setting up bridges? 17:10:05 gaba: yes. i reached out to tor-relays@ the other day. one person responded to me directly, saying that the instructions were very useful. 17:10:13 nice 17:10:20 the next step is to work on a broader outreach campaign 17:10:37 nice 17:10:38 one remaining question is if we only want obfs4 bridges, or if we also want vanilla bridges 17:11:07 the problem is: if you set up an obfs4 bridge, it's *only* distributed as obfs4, and no longer as vanilla. that means that if we want a vanilla bridge, it must not run obfs4. 17:11:50 maybe a blogpost about bridges again and links on how to set them up so we can share that and ask people at Tor to add slides about bridge creations when they give talks about Tor. 17:11:57 hm, that sounds like something we should fix in core tor? 17:12:03 at the moment, i think we have slightly more vanilla bridges than obfs4 bridges 17:12:25 ahf: just to be clear, that's by design, and done by bridgedb 17:12:51 ah, okay, so the bridge auth is aware that the bridge can do both obfs4 and vanilla? 17:13:01 imagine your bridge runs vanilla and obfs4, and you hand out the vanilla line to someone in china. the gfw will recognise vanilla tor and block your entire bridge, including the obfs4 port, which could have worked in china. 17:13:12 basically, vanilla tor is a liability to obfs4 ;) 17:13:15 yeah 17:13:49 the bridge auth is aware, yes, but bridgedb is the one deciding what lines to hand out to users 17:14:02 cool 17:14:17 gaba: yes, sounds good. 17:14:51 speaking of obfs4: i have a quick question for catalyst and ahf 17:15:03 yep? 17:15:08 several bridge ops configured a private ip address for their obfs4 bridge 17:15:29 the PT spec explicitly allows this but says that some kind of redirection must be in place for this to work 17:16:18 this may be a tor issue. i don't think any private ip addresses should end up in a descriptor, right? 17:16:21 yeah, common for relay operators too (to bind tor on port 80/443 without running as root i believe) 17:16:46 no, if we don't have an option right now for specifying a "hidden IP" (not going in the descriptor) and the public IP then we should fix that 17:17:17 ok, i can create a ticket for that 17:17:36 in torrc see the flags for ORPort: NoListen, NoAdvertise 17:18:17 yes, please do, sounds like a good thing to fix (if it's a good thing that relay operators listen on the 1-1024 port range) 17:18:24 gotcha, thanks! 17:18:54 ok, i think that concludes are discussion about bridgedb and about setting up new obfs4 bridges. anything else? 17:19:39 the next item is the snowflake webextension that arlolra has been working on 17:19:58 as i understand it, there's now a usable prototype that's already in the mozilla addons store! 17:20:04 \o/ 17:20:11 awesome \o/ 17:20:11 \o/ 17:20:12 and arlolra also submitted it to the chrome store where it's pending review 17:20:17 that's a huge milestone :) 17:20:32 also thanks to antonela for all the ui feedback! 17:20:43 happy to help! 17:21:22 :) 17:21:42 at this point we could use more testers, so please add it to your browser and file tickets if something's wrong 17:21:43 arlolra: feel free to assign webextension tickets to yourself if you have plans to work on them 17:21:57 i sorta jumped in there on the toggle ebcause we were getting some pressure 17:22:04 but i want to avoid stepping on your toes with stuff 17:22:09 i wonder if we have a meta ticket that keeps track of all the webextension improvement tickets 17:22:20 there's a snowflake-webextension keyword 17:22:28 ah, thanks cohosh 17:22:41 cohosh: no, no, I broke it out into separate tasks so you can start helping 17:23:04 and, sadly, I don't think we can declare victory until #30998 is fixed 17:23:05 arlolra: cool ^_^ it was fun to get caught up to speed on webextension development again 17:23:24 ah yeah, do you know who owns/maintains the websocket code? 17:23:32 probably dcf 17:23:48 we can close #30931, right? 17:24:08 gaba: sure 17:25:24 anything else to add wrt our discussion section? 17:25:52 * phw interprets *crickets* as "no" 17:26:21 there's a paper in the 'interesting links' section that we should skim: https://www.ndss-symposium.org/ndss-paper/enemy-at-the-gateways-censorship-resilient-proxy-distribution-using-game-theory/ 17:26:26 published at this year's ndss 17:26:54 ok, let's check out each other's 'heeds help with' section 17:27:29 like i said, it would be great if you could request bridges from bridgedb and let me know if you didn't get any 17:27:35 * cohosh has lots of code to review 17:28:12 ok 17:28:15 i think #21315 will be fast 17:28:21 cohosh: i can review #21315 again 17:28:23 and phw reviewed a previous version 17:28:26 phw: ty! 17:28:34 cohosh: I can review #30934 17:28:40 arlolra: awesome, thanks! 17:28:47 the others can wait a bit 17:28:57 #28942 is the pion integration 17:29:14 i'm still waiting to hear back on some PRs from them though 17:29:23 so that can wait a bit 17:29:38 and so can the sequencing stuff 17:30:43 dcf had a look at one of these two, right? 17:31:33 yeah at the sequencing work 17:31:49 i can move forward with that since this round was implementing suggested fixes 17:32:14 great! 17:32:41 is anybody reviewing #30998? 17:32:48 #30998 17:32:50 then there's #30998 left. we need dcf for this, right? 17:33:53 probably yes 17:34:19 ok, i think we're good for today, then. any last words? 17:34:44 cohosh: I need a firefox account from you 17:35:07 ah i can make one after this meeting 17:35:26 thanks 17:35:55 we are not having meetings for the next two weeks? 4july and then traveling to tor meeting? 17:36:36 fwiw, I think we have access to the default bridge 17:36:37 https://trac.torproject.org/projects/tor/wiki/org/teams/AntiCensorshipTeam/SnowflakeBridgeSurvivalGuide#Bridgesurvivalguide 17:36:50 oh, that's right gaba. next week is july 4, then we have tor-dev 17:36:59 but yes, having a dcf would be preferable 17:37:08 do you think that's too long? 17:37:52 arlolra: ah we can add the patch now and wait to upstream it you mean? 17:38:11 oh, also, this is our last meeting for this month and i'll compile our monthly report over the next few days 17:38:28 it would be great if everyone could add their highlights of the month to a pad 17:38:31 * phw creates a pad 17:39:03 cohosh: yes, if needs be 17:39:18 https://pad.riseup.net/p/h4FrASe8pVEaAfmUs_IG 17:40:23 anything else, gaba_ 17:40:26 ? 17:41:05 nop 17:41:10 ok, thanks everyone! 17:41:13 #endmeeting