@昏鸦
@昏鸦
关注的小组(1)
动态 帖子 0 评论 7 短评 0 收到的赞 7 送出的赞 0
  1. 昏鸦   在小组 2047 回复文章

    2047助你快速匿名建网站

    最主要实现的部分没有写出来...
    我盲目猜测一下是用 tor 建立匿名站点 (最方便安全的方法) 或者类似 ssh -L 之类的办法把端口暴露给贵司工程人员,然后转发一下。看起来蛮省心的。不知道什么时候能支持 I2P ?

  2. 昏鸦   在小组 2047 回复文章

    在中国设立一个公司,专营网络论坛,主打匿名和绝不删帖,论坛源代码公开,商业前景如何?

    楼主可以了解一下 4chan。
    这样一个论坛大概是可以做出来的,但是赚钱就不要想了。
    用户看到的内容可以通过浏览器筛选过滤。过滤规则基于用户贴的标签,以及众多用户对标签进行的投票票数。当然这种方式可能存在刷票数的问题,没法完全防住。我想到的解决方法是自己选择信任的标签员。
    发言当然是全匿名。你甚至不需要用户注册登陆系统,让用户自行 gpg 签名即可标识特定身份。
    开放源代码不是很赞同,虽然我是自由软件爱好者。理由和 @thphd 一样,如果技术不够你会被日成筛子。
    此外,如果真有这样的论坛,我希望论坛上所有数据任何人都可以轻松同步获取。这样一个站长被端掉了还可以有其他站长续上。
    最后,我以为,适当的发言门槛是有必要的,不管是以何种方式呈现。

  3. 昏鸦   在小组 2047 回复文章

    谈谈阿里强奸案背后的商业逻辑

    有一处不懂,还望解答。为什么说“性交易合法化是威胁党国统治的”?

  4. 昏鸦   在小组 2047 回复文章

    缅北中国革命党人简析

    来源请求

    感谢整理,不过上述内容应标注出处为宜,可供后来的读者参考。

    对于缅北中国革命党人的存在近段时间我也有关注,但目前仅收集到来自缅北中国革命党人单方面的信息,因此内容有可能存在某些局限性。贴主有在其他贴利用可能关联的新闻推证,但我认为目前仍对这些内容持谨慎态度为宜。

  5. 昏鸦   在小组 2047 回复文章

    00后小红帽“净网志愿者协会”与两广网警联合办案,通过社工手段找到“编程随想”真实身份

    一些天真可怜的小朋友。

    贴主,这标题还是改一下比较好。乍看吓一跳,以为是新闻稿。点进来一看通篇嘲讽,概括得很不好啊。

  6. 昏鸦   在小组 2047 回复文章

    (转载)I2P-Bote:基于I2P的随机高延迟匿名电子邮件

    i2p-bote 项目已经死了,这里是 I2P 开发者 zzz 描述的细节:
    http://zzz.i2p/topics/2853

    RIP Bote

    Everybody should assume Bote is dead abandonware. You can stop asking about it.

    The previous maintainer, str4d, is totally unresponsive to our queries.

    There's numerous reports that it doesn't work any more. There's 50+ unresolved tickets, most open for several years. It doesn't support secure signature types introduced in I2P over 6 years ago.

    It's a large, complex code base with dozens of dependencies. Nobody on the I2P team wants to work on it. The team did attempt to assign people to work on it, but due to disinterest, bad match of skills, low priority, and loose project management, almost nothing happened.

    Some have asked for us to bundle (un-pluginize) it, that's impossible due to the bote license restrictions, and doesn't address the maintenance issue.

    str4d moved it from monotone to github 3 years ago under the (widely held) theory that monotone prevents new developers from joining, and that with that barrier removed, contributors would flock to the project. That hasn't happened. There's zero new contributors, and a total of 4 (ignored) PRs in 3 years.

    Back in 2006, jrandom stopped working on the core I2P router to work on Syndie, a secure and anonymous messaging platform. At the time he stated that messaging was the core use case for I2P. That without a solid messaging product we would not succeed. Syndie was always problematic, and when jrandom stopped working on it (and then vanished), it wasn't going to become big. Even though I spent quite some time working on it afterwards.

    Bote was started by HungryHobo around the same time. The protocol is documented, but I don't know if it was ever reviewed by anybody for security, or choice of crypto algorithms. It is well documented and at a high level seems to be well-designed. A few years later, HH had health problems if I recall, and vanished. str4d eventually picked it up and did an enormous amount of work on it. But like every single thing he used to support, it's now abandoned, and he won't talk to any of us any more, on any topic, for any reason.

    Both syndie and bote were started before the sharp rise of social media platforms, and they both seem antiquated today. I don't know what a modern, secure, distributed, anonymous messaging platform would look like if we started from scratch today. Without these applications, we're left with two primary, decades-old platforms - email and IRC.

    We have had big success with mattermost (a slack-like platform) internally. It's quite usable over I2P even though most of the team does it over clearnet, can't be bothered with dogfooding. There are outstanding anonymity and efficiency/performance issues with mattermost that have not been resolved nor reported upstream.

    We have also talked about bundling a javascript IRC client into the console but initial investigations show that it could be quite difficult. We added comments to i2psnark a couple years back, not widely used. Zab added IRC-like functions to MuWire.

    The last time the team talked about it, we agreed that messaging is still a key to i2p's success. We don't know exactly what that would look like, but it's not bote. From our experience with modern social media platforms, and with mattermost, it's clear that attachments, especially images, is a requirement, as is low-latency. Bote and syndie were very high latency, by design. Image attachments is a fantastic feature but image sharing on open platforms is problematic in anonymous networks for the usual reasons.

    There has also been a proposal within the team to completely rethink / redesign susimail, and combine it with bote. That's problematic for a number of reasons - not our core expertise, 10 times harder than just maintaining bote (which nobody wants to do), the bote license issues... and nobody has a clear vision of what it would even look like. If it were me I'd rewrite the low-level parts of bote from scratch (cleanroom from the docs) and stick it in susimail. But others have strong opinions that susimail is a complete dumpster fire of a UI and that's what should be thrown out. Either way it's a horrible shotgun wedding. And a total fantasy given our current resources. I don't understand the "I don't want to maintain X but I'd be happy to rewrite it from scratch" mentality but it is common. With even minimal control over how we allocate our resources, it shouldn't happen. But we'll see.

    So I don't know what the answer is, but it's clear that it's not bote. You all can stop holding out for it.

    Last edited: Thu, 05 Mar 2020, 02:50pm by zzz

  7. 昏鸦   在小组 2047 回复文章

    怎么能在墙国做一个完全匿名的身份?

    我个人不认为线下匿名身份是一个好的选择。
    我的看法是,在线下刻意保持这种匿名状态本身就是一种很刺眼的标识。要做到没有疏漏是很困难的。
    当然,帖主有提到 :

    后面就是让设备上的身份不能跟现实身份有交集

    可能也是有这方面考虑。
    我个人的建议是线下身份尽可能保持普通化,保持大众化,混入十几亿茫茫人海。
    你有我的身份证号;你有我的面部特征数据;你有我的指纹样本;你有我的亲属关系图;你有我的银行卡交易记录……你有我的一切数据,但你拼凑不出真实的我。我在网络空间中是另一个身份。

    线下匿名交易二手电子设备

    我的个人观点是这并没有必要。如果做到线下身份毫不起眼,你买到的设备并不会比匿名交易得到的设备存在更多问题。如果害怕设备带有特殊标识,虚拟机一直是我们的好伙伴: )

    刷机,软件安装全用u盘

    我的个人建议是使用社区维护且软件包可以做到从源码编译出相同结果的 GNU/Linux 发行版本。安装系统时务必校验镜像文件,之后通过国内镜像站更新系统并无不妥,因为大部分主流发行版本的包管理器带有校验功能。如果害怕下载记录被镜像站记录则可以走代理。若您有数据洁癖,侧重于匿名性的操作系统中,运行于虚拟机的有 Whonix,可以烧写到U盘的有 Tails 。
    电子货币方面我个人看法与站长一致,推荐 Monero (XMR) 。其中一条虽然不愿意承认但是事实的理由是,Monero 的货币价值有一部分由黑产背书,不会有价值方面的太大问题。除了提供良好的交易匿名保护,PoW 所使用的 RandomX 我个人认为是目前最佳算法了。
    另外一提,在技术上做到自己所认为的万无一失并不足够。突破口通常会是我们自己。
    说起来我是不是跑题了……