03.xhtml 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152
  1. <?xml version="1.0" encoding="utf-8"?>
  2. <!--
  3. h t t :: / / t /
  4. h t t :: // // t //
  5. h ttttt ttttt ppppp sssss // // y y sssss ttttt //
  6. hhhh t t p p s // // y y s t //
  7. h hh t t ppppp sssss // // yyyyy sssss t //
  8. h h t t p s :: / / y .. s t .. /
  9. h h t t p sssss :: / / yyyyy .. sssss t .. /
  10. <https://y.st./>
  11. Copyright © 2015 Alex Yst <mailto:copyright@y.st>
  12. This program is free software: you can redistribute it and/or modify
  13. it under the terms of the GNU General Public License as published by
  14. the Free Software Foundation, either version 3 of the License, or
  15. (at your option) any later version.
  16. This program is distributed in the hope that it will be useful,
  17. but WITHOUT ANY WARRANTY; without even the implied warranty of
  18. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  19. GNU General Public License for more details.
  20. You should have received a copy of the GNU General Public License
  21. along with this program. If not, see <https://www.gnu.org./licenses/>.
  22. -->
  23. <!DOCTYPE html>
  24. <html xmlns="http://www.w3.org/1999/xhtml">
  25. <head>
  26. <base href="https://y.st./en/weblog/2015/11-November/03.xhtml" />
  27. <title>A flawed trust model &lt;https://y.st./en/weblog/2015/11-November/03.xhtml&gt;</title>
  28. <link rel="icon" type="image/png" href="/link/CC_BY-SA_4.0/y.st./icon.png" />
  29. <link rel="stylesheet" type="text/css" href="/link/basic.css" />
  30. <link rel="stylesheet" type="text/css" href="/link/site-specific.css" />
  31. <script type="text/javascript" src="/script/javascript.js" />
  32. <meta name="viewport" content="width=device-width" />
  33. </head>
  34. <body>
  35. <nav>
  36. <p>
  37. <a href="/en/">Home</a> |
  38. <a href="/en/a/about.xhtml">About</a> |
  39. <a href="/en/a/contact.xhtml">Contact</a> |
  40. <a href="/a/canary.txt">Canary</a> |
  41. <a href="/en/URI_research/"><abbr title="Uniform Resource Identifier">URI</abbr> research</a> |
  42. <a href="/en/opinion/">Opinions</a> |
  43. <a href="/en/coursework/">Coursework</a> |
  44. <a href="/en/law/">Law</a> |
  45. <a href="/en/a/links.xhtml">Links</a> |
  46. <a href="/en/weblog/2015/11-November/03.xhtml.asc">{this page}.asc</a>
  47. </p>
  48. <hr/>
  49. <p>
  50. Weblog index:
  51. <a href="/en/weblog/"><abbr title="American Standard Code for Information Interchange">ASCII</abbr> calendars</a> |
  52. <a href="/en/weblog/index_ol_ascending.xhtml">Ascending list</a> |
  53. <a href="/en/weblog/index_ol_descending.xhtml">Descending list</a>
  54. </p>
  55. <hr/>
  56. <p>
  57. Jump to entry:
  58. <a href="/en/weblog/2015/03-March/07.xhtml">&lt;&lt;First</a>
  59. <a rel="prev" href="/en/weblog/2015/11-November/02.xhtml">&lt;Previous</a>
  60. <a rel="next" href="/en/weblog/2015/11-November/04.xhtml">Next&gt;</a>
  61. <a href="/en/weblog/latest.xhtml">Latest&gt;&gt;</a>
  62. </p>
  63. <hr/>
  64. </nav>
  65. <header>
  66. <h1>A flawed trust model</h1>
  67. <p>Day 00241: Tuesday, 2015 November 03</p>
  68. </header>
  69. <p>
  70. I tried setting up a hidden service on my mobile, but I could not figure out how to make it work.
  71. Orbot has an option to set up a hidden service.
  72. It says that it will automatically generate an onion address when doing so, after which, it will tell you what address it came up with.
  73. I figured that after it had set that up, I could find the file containing the onion key, then replace it with the onion key that my hidden service here uses.
  74. No dice.
  75. Orbot silently failed and did not generate an onion address.
  76. Next, I tried using the option that allows you to add configuration lines to the torrc file.
  77. Again, no dice.
  78. Like before, no error messages were output, but the <code>HiddenServiceDir</code> and <code>HiddenServicePort</code> lines seemed to have been ignored.
  79. I could not find any information on how to make it work on the Web, though <a href="https://wowana.me/">wowaname</a> said that it did not matter anyway; Orbot keeps the onion key in its monolithic Android application data file, so the key cannot be swapped out for the preferred one without special knowledge.
  80. I was hoping to be able to move the onion half of this website to my mobile so I wouldn&apos;t have to leave my laptop on at all times any more, but it looks like that is not going to work.
  81. </p>
  82. <p>
  83. I have not finished reading all the email from my overly-full inbox, but I did finish cleaning it out.
  84. I&apos;ve moved everything that still needs processing into a subdirectory so that I can actually see incoming mail.
  85. Most of the yet-to-be-processed mail is political.
  86. Everything else has been deleted, answered, and/or otherwise acted upon.
  87. </p>
  88. <p>
  89. It seems that Marc With A C has released a <a href="https://marcwithac.bandcamp.com/album/the-carpet-crawlers-from-nerdy-shows-call-of-cthulhu">new album</a>, albeit a small one.
  90. Josh Woodward seems to have cleaned up his website quite a bit, too.
  91. His website looked professional on the outside before, but if you navigated around a bit, it seemed to have multiple layers.
  92. It felt as if a newer version of the website had been partially built on top of an older version of the website, which very well could have been the case.
  93. Now, however, the website seems uniform and consistent.
  94. </p>
  95. <p>
  96. I found an issue with my bifurcated website setup.
  97. Due to the centralized security model used with <abbr title="Transport Layer Security">TLS</abbr>, the certificates used by the two websites are considered somehow less trustworthy than neglecting to use any encryption at all.
  98. You can usually tell your Web browser to bypass the flawed trust model on a per-website basis, but that doesn&apos;t fully solve the problem when using cross-site <abbr title="Cascading Style Sheets">CSS</abbr> like I am using to make the links to the onion half of the website visible when the page is viewed over <abbr title="The Onion Router">Tor</abbr>.
  99. The <abbr title="Cascading Style Sheets">CSS</abbr> file from the site you are viewing loads properly, but the <abbr title="Cascading Style Sheets">CSS</abbr> file from the other website is blocked unless both websites have been viewed separately and their certificates accepted by the viewer.
  100. On the clearnet website, this results in the links to the onion website remaining invisible even if the Web browser has been configured to use <abbr title="The Onion Router">Tor</abbr>.
  101. On the onion website, this results in the website being mostly unstyled.
  102. This could be fixed by paying exorbitant fees to a &quot;certificate authority&quot;, but I refuse to do that as long as they continue to be expensive as they are.
  103. For a basic certificate with wildcard subdomain support, it would cost about $80 <abbr title="United States Dollars">USD</abbr> per year, and that would just be for the clearnet certificate.
  104. It&apos;s more difficult to get &quot;certificate authorities&quot; to issue certificates for onion domains, and from what I hear, they charge even higher rates to do so.
  105. Assuming <a href="https://letsencrypt.org/">Let&apos;s Encrypt</a> will issue certificates for onion-based websites, they may be the solution, though right now, their services are still in a limited beta.
  106. </p>
  107. <p>
  108. I&apos;ve decided not to purchase any domains for the time being.
  109. I was going to wait until the renewal date of <code>//y.st.</code> in order to synchronize the renewal dates so that I would only have one renewal date to remember.
  110. However, I think it would be a better idea to just use my <code>//ystyst.mp.</code> domain for beginning my potentially-collaborative projects.
  111. It&apos;s a dumb domain for sure, but I&apos;d rather not purchase another domain that I&apos;m not even completely sure that I will get much use out of.
  112. The unfortunate side effect of this decision is that I&apos;ll have revealed the name of the group, Thorn, before making the domain purchase.
  113. The chance is slim, but someone may scoop up the domain I eventually plan to buy myself.
  114. </p>
  115. <p>
  116. I&apos;ve finally uploaded this website&apos;s code to <a href="https://notabug.org/y.st.">NotABug.org</a>.
  117. Due to the privacy issues that caused this website&apos;s bifurcation, I had to make the repository private.
  118. If not logged in, the repository&apos;s webpage even returns a 404 error.
  119. This means that while this repository functions as a backup copy in case I lose the website due to hard drive failure again, I can only retrieve the backup if I have not lost my KeePassX database.
  120. Keeping the KeePass database&apos;s local backup up to date is a lot easier than keeping the local backup of the website up to date though.
  121. The website is much larger, so I back it up to an external hard drive.
  122. Setting up the hard drive is inconvenient, so I don&apos;t do it every day.
  123. On the other hand, I usually back my KeePassX database up to my mobile every day that I&apos;ve made a change to it, in addition to backing it up on the external hard drive when I back up the website and my personal files.
  124. For that reason, I usually have an up-to-date local backup of the KeePassX database but not an up-to-date backup of the website.
  125. A Git-based remote backup is easy to update daily though.
  126. I&apos;ve also removed the outdated copy of the website from Github.
  127. </p>
  128. <p>
  129. My <a href="/a/canary.txt">canary</a> still sings the tune of freedom and transparency.
  130. </p>
  131. <hr/>
  132. <p>
  133. Copyright © 2015 Alex Yst;
  134. You may modify and/or redistribute this document under the terms of the <a rel="license" href="/license/gpl-3.0-standalone.xhtml"><abbr title="GNU&apos;s Not Unix">GNU</abbr> <abbr title="General Public License version Three or later">GPLv3+</abbr></a>.
  135. If for some reason you would prefer to modify and/or distribute this document under other free copyleft terms, please ask me via email.
  136. My address is in the source comments near the top of this document.
  137. This license also applies to embedded content such as images.
  138. For more information on that, see <a href="/en/a/licensing.xhtml">licensing</a>.
  139. </p>
  140. <p>
  141. <abbr title="World Wide Web Consortium">W3C</abbr> standards are important.
  142. This document conforms to the <a href="https://validator.w3.org./nu/?doc=https%3A%2F%2Fy.st.%2Fen%2Fweblog%2F2015%2F11-November%2F03.xhtml"><abbr title="Extensible Hypertext Markup Language">XHTML</abbr> 5.1</a> specification and uses style sheets that conform to the <a href="http://jigsaw.w3.org./css-validator/validator?uri=https%3A%2F%2Fy.st.%2Fen%2Fweblog%2F2015%2F11-November%2F03.xhtml"><abbr title="Cascading Style Sheets">CSS</abbr>3</a> specification.
  143. </p>
  144. </body>
  145. </html>