c34cd093a59cdb37c2870ccd7c2e839c362d8360
Peter Palfrader Move website to wml

Peter Palfrader authored 19 years ago

en/volunteer.wml   1) ## translation metadata
Peter Palfrader In CVS the magic keyword is...

Peter Palfrader authored 19 years ago

en/volunteer.wml   2) # Revision: $Revision$
Andrew Lewman renamed contribute to volun...

Andrew Lewman authored 19 years ago

volunteer.html     3) 
Peter Palfrader Move website to wml

Peter Palfrader authored 19 years ago

en/volunteer.wml   4) #include "head.wmi" TITLE="Volunteer"
Andrew Lewman renamed contribute to volun...

Andrew Lewman authored 19 years ago

volunteer.html     5) 
volunteer.html     6) <div class="main-column">
volunteer.html     7) 
volunteer.html     8) <!-- PUT CONTENT AFTER THIS TAG -->
Roger Dingledine make the frontpage appear l...

Roger Dingledine authored 17 years ago

en/volunteer.wml   9) <h2>Three things everyone can do now:</h2>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html    10) <ol>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  11) <li>Please consider <a href="<page docs/tor-doc-server>">running
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    12) a server</a> to help the Tor network grow.</li>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  13) <li>Tell your friends! Get them to run servers. Get them to run hidden
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    14) services. Get them to tell their friends.</li>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  15) <li>We are looking for funding and sponsors. If you like Tor's goals, please
Roger Dingledine a short paragraph of explan...

Roger Dingledine authored 19 years ago

en/volunteer.wml  16)   <a href="<page donate>">take a moment to donate to support further
en/volunteer.wml  17)   Tor development</a>. Also, if you know any
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  18)   companies, NGOs, agencies, or other organizations that want communications
Roger Dingledine cut out much of the front p...

Roger Dingledine authored 19 years ago

en/volunteer.wml  19)   security, let them know about us.</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html    20) </ol>
volunteer.html    21) 
Roger Dingledine put anchors into the volunt...

Roger Dingledine authored 18 years ago

en/volunteer.wml  22) <a id="Usability"></a>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  23) <h2><a class="anchor" href="#Usability">Supporting Applications</a></h2>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    24) <ol>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  25) <li>We need good ways to intercept DNS requests so they don't "leak" their
en/volunteer.wml  26) request to a local observer while we're trying to be anonymous. (This
en/volunteer.wml  27) happens because the application does the DNS resolve before going to
en/volunteer.wml  28) the SOCKS proxy.)</li>
en/volunteer.wml  29) <ul>
en/volunteer.wml  30) <li>We need to <a
en/volunteer.wml  31) href="http://wiki.noreply.org/noreply/TheOnionRouter/TSocksPatches">apply
en/volunteer.wml  32) all our tsocks patches</a> and maintain a new fork. We'll host it if
en/volunteer.wml  33) you want.</li>
en/volunteer.wml  34) <li>We should patch Dug Song's "dsocks" program to use Tor's
en/volunteer.wml  35) <i>mapaddress</i> commands from the controller interface, so we
en/volunteer.wml  36) don't waste a whole round-trip inside Tor doing the resolve before
en/volunteer.wml  37) connecting.</li>
en/volunteer.wml  38) <li>We need to make our <i>torify</i> script detect which of tsocks or
en/volunteer.wml  39) dsocks is installed, and call them appropriately. This probably means
en/volunteer.wml  40) unifying their interfaces, and might involve sharing code between them
en/volunteer.wml  41) or discarding one entirely.</li>
en/volunteer.wml  42) </ul>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    43) <li>People running servers tell us they want to have one BandwidthRate
volunteer.html    44) during some part of the day, and a different BandwidthRate at other parts
volunteer.html    45) of the day. Rather than coding this inside Tor, we should have a little
Peter Palfrader Update links

Peter Palfrader authored 18 years ago

en/volunteer.wml  46) script that speaks via the <a href="<page gui/index>">Tor Controller Interface</a>,
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    47) and does a setconf to change the bandwidth rate. Perhaps it would run out
volunteer.html    48) of cron, or perhaps it would sleep until appropriate times and then do
volunteer.html    49) its tweak (that's probably more portable). Can somebody write one for us
Roger Dingledine and link some sandbox stuff...

Roger Dingledine authored 18 years ago

en/volunteer.wml  50) and we'll put it into <a href="<svnsandbox>contrib/">contrib/</a>?
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  51) This is a good entry for the <a href="<page gui/index>">Tor GUI
Nick Mathewson Remove some completed or in...

Nick Mathewson authored 18 years ago

en/volunteer.wml  52) competition</a>.
en/volunteer.wml  53)   <!-- We have a good script to adjust stuff now, right? -NM -->
en/volunteer.wml  54) </li>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  55) <li>Tor can <a
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    56) href="http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#ChooseEntryExit">exit
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  57) the Tor network from a particular exit node</a>, but we should be able
en/volunteer.wml  58) to specify just a country and have something automatically pick. The
en/volunteer.wml  59) best bet is to fetch Blossom's directory also, and run a local Blossom
en/volunteer.wml  60) client that fetches this directory securely (via Tor and checking its
en/volunteer.wml  61) signature), intercepts <tt>.country.blossom</tt> hostnames, and does
en/volunteer.wml  62) the right thing.</li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    63) <li>Speaking of geolocation data, somebody should draw a map of the Earth
volunteer.html    64) with a pin-point for each Tor server. Bonus points if it updates as the
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  65) network grows and changes. Unfortunately, the easy ways to do this involve
en/volunteer.wml  66) sending all the data to Google and having them draw the map for you. How
en/volunteer.wml  67) much does this impact privacy, and do we have any other good options?</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html    68) </ol>
volunteer.html    69) 
Roger Dingledine put anchors into the volunt...

Roger Dingledine authored 18 years ago

en/volunteer.wml  70) <a id="Documentation"></a>
en/volunteer.wml  71) <h2><a class="anchor" href="#Documentation">Documentation</a></h2>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html    72) <ol>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  73) <li>We hear that Tor users can fall victim to anonymity-breaking attacks
en/volunteer.wml  74) from javascript, java, activex, flash, etc, if they don't disable
en/volunteer.wml  75) them. Are there plugins out there (like NoScript for Firefox) that make
en/volunteer.wml  76) it easier for users to manage this risk? What is the risk exactly?</li>
en/volunteer.wml  77) <li>Is there a full suite of plugins that will replace all of Privoxy's
en/volunteer.wml  78) functionality for Firefox 1.5+? We hear Tor is much faster when you take
en/volunteer.wml  79) Privoxy out of the loop.</li>
en/volunteer.wml  80) <li>Please help Matt Edman with the documentation and how-tos for his
Nick Mathewson Remove some completed or in...

Nick Mathewson authored 18 years ago

en/volunteer.wml  81) Tor controller,
en/volunteer.wml  82) <a href="http://vidalia-project.net/">Vidalia</a>.</li>
Roger Dingledine more cleanup, get the link...

Roger Dingledine authored 18 years ago

en/volunteer.wml  83) <li>Evaluate and document
en/volunteer.wml  84) <a href="http://wiki.noreply.org/wiki/TheOnionRouter/TorifyHOWTO">our
en/volunteer.wml  85) list of programs</a> that can be configured to use Tor.</li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    86) <li>We need better documentation for dynamically intercepting
Roger Dingledine remove some done things fro...

Roger Dingledine authored 18 years ago

en/volunteer.wml  87) connections and sending them through Tor. tsocks (Linux), dsocks (BSD),
Nick Mathewson Remove some completed or in...

Nick Mathewson authored 18 years ago

en/volunteer.wml  88) and freecap (Windows) seem to be good candidates, as would better
en/volunteer.wml  89) use of our new TransPort feature.</li>
Roger Dingledine more cleanup, get the link...

Roger Dingledine authored 18 years ago

en/volunteer.wml  90) <li>We have a huge list of <a href="http://wiki.noreply.org/noreply/TheOnionRouter/SupportPrograms">potentially useful
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html    91) programs that interface to Tor</a>. Which ones are useful in which
volunteer.html    92) situations? Please help us test them out and document your results.</li>
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml  93) <li>Help translate the web page and documentation into other
en/volunteer.wml  94) languages. See the <a href="<page translation>">translation
en/volunteer.wml  95) guidelines</a> if you want to help out. We also need people to help
en/volunteer.wml  96) maintain the existing Italian, French, and Swedish translations -
en/volunteer.wml  97) see the <a href="<page translation-status>">translation status
en/volunteer.wml  98) overview</a>.</li>
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml  99) <li>Can somebody walk us through whether we want to go the
en/volunteer.wml 100) <a href="http://www.cacert.org/">cacert</a> route for our
en/volunteer.wml 101) SSL <a href="<page documentation>#Developers">SVN repository?</a></li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   102) </ol>
volunteer.html   103) 
Roger Dingledine put anchors into the volunt...

Roger Dingledine authored 18 years ago

en/volunteer.wml 104) <a id="Coding"></a>
en/volunteer.wml 105) <h2><a class="anchor" href="#Coding">Coding and Design</a></h2>
Roger Dingledine link to the wiki gsoc blurb...

Roger Dingledine authored 17 years ago

en/volunteer.wml 106) <p>Want to spend your <a href="http://code.google.com/soc/">Google Summer
en/volunteer.wml 107) of Code</a> working on Tor? Great.
en/volunteer.wml 108) <a href="http://wiki.noreply.org/noreply/TheOnionRouter/SummerOfCode">Read
en/volunteer.wml 109) more about Tor and GSoC</a>, and see if any of the below ideas catch
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 110) your eye.</p>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   111) <ol>
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 112) <li>Tor servers don't work well on Windows XP. On
Roger Dingledine link to the wiki gsoc blurb...

Roger Dingledine authored 17 years ago

en/volunteer.wml 113) Windows, Tor uses the standard <tt>select()</tt> system
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 114) call, which uses space in the non-page pool. This means
en/volunteer.wml 115) that a medium sized Tor server will empty the non-page pool, <a
en/volunteer.wml 116) href="http://wiki.noreply.org/noreply/TheOnionRouter/WindowsBufferProblems">causing
Roger Dingledine link to the wiki gsoc blurb...

Roger Dingledine authored 17 years ago

en/volunteer.wml 117) havoc and system crashes</a>. We should probably be using overlapped IO
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 118) instead. One solution would be to teach libevent how to use overlapped IO
en/volunteer.wml 119) rather than select() on Windows, and then adapt Tor to the new libevent
en/volunteer.wml 120) interface.</li>
en/volunteer.wml 121) <li>Because Tor servers need to store-and-forward each cell they handle,
en/volunteer.wml 122) high-bandwidth Tor servers end up using dozens of megabytes of memory
en/volunteer.wml 123) just for buffers. We need better heuristics for when to shrink/expand
en/volunteer.wml 124) buffers. Maybe this should be modelled after the Linux kernel buffer
Roger Dingledine a few more design/coding it...

Roger Dingledine authored 17 years ago

en/volunteer.wml 125) design, where we have many smaller buffers that link to each other,
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 126) rather than monolithic buffers?</li>
en/volunteer.wml 127) <li>We need an official central site to answer "Is this IP address a Tor
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 128) exit server?" questions. This should provide several interfaces, including
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 129) a web interface and a DNSBL-style interface. It can provide the most
en/volunteer.wml 130) up-to-date answers by keeping a local mirror of the Tor directory
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 131) information. The tricky point is that being an exit server is not a
en/volunteer.wml 132) boolean: so the question is actually "Is this IP address a Tor exit
en/volunteer.wml 133) server that can exit to my IP address:port?" The DNSBL interface
en/volunteer.wml 134) will probably receive hundreds of queries a minute, so some smart
en/volunteer.wml 135) algorithms are in order. Bonus points if it does active testing through
Roger Dingledine link to the torbl-design draft

Roger Dingledine authored 17 years ago

en/volunteer.wml 136) each exit node to find out what IP address it's really exiting from.
en/volunteer.wml 137) <a href="<svnsandbox>doc/contrib/torbl-design.txt">Read more here</a>.</li>
Roger Dingledine a few more design/coding it...

Roger Dingledine authored 17 years ago

en/volunteer.wml 138) <li>It would be great to have a LiveCD that includes the latest
en/volunteer.wml 139) versions of Tor, Polipo or Privoxy, Firefox, Gaim+OTR, etc. There are
en/volunteer.wml 140) two challenges here: first is documenting the system and choices well
en/volunteer.wml 141) enough that security people can form an opinion on whether it should be
en/volunteer.wml 142) secure, and the second is figuring out how to make it easily maintainable,
en/volunteer.wml 143) so it doesn't become quickly obsolete like AnonymOS. Bonus points if
en/volunteer.wml 144) the CD image fits on one of those small-form-factor CDs.</li>
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 145) <li>Related to the LiveCD image, we should work on an intuitively secure
en/volunteer.wml 146) and well-documented USB image for Tor and supporting applications. A
en/volunteer.wml 147) lot of the hard part here is deciding what configurations are secure,
en/volunteer.wml 148) documentating these decisions, and making something that is easy to
en/volunteer.wml 149) maintain going forward.</li>
Roger Dingledine link to the wiki gsoc blurb...

Roger Dingledine authored 17 years ago

en/volunteer.wml 150) <li>Our preferred graphical front-end for Tor, named
en/volunteer.wml 151) <a href="http://vidalia-project.net/">Vidalia</a>, needs all sorts
en/volunteer.wml 152) of development work.</li>
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 153) <li>We need to actually start building our <a href="<page
en/volunteer.wml 154) documentation>#DesignDoc">blocking-resistance design</a>. This involves
Roger Dingledine link to the wiki gsoc blurb...

Roger Dingledine authored 17 years ago

en/volunteer.wml 155) fleshing out the design, modifying many different pieces of Tor, adapting
en/volunteer.wml 156) <a href="http://vidalia-project.net/">Vidalia</a> so it supports the
en/volunteer.wml 157) new features, and planning for deployment.</li>
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 158) <li>We need a flexible simulator framework for studying end-to-end
en/volunteer.wml 159) traffic confirmation attacks. Many researchers have whipped up ad hoc
en/volunteer.wml 160) simulators to support their intuition either that the attacks work
en/volunteer.wml 161) really well or that some defense works great. Can we build a simulator
en/volunteer.wml 162) that's clearly documented and open enough that everybody knows it's
en/volunteer.wml 163) giving a reasonable answer? This will spur a lot of new research.
en/volunteer.wml 164) See the entry <a href="#Research">below</a> on confirmation attacks for
en/volunteer.wml 165) details on the research side of this task &mdash; who knows, when it's
en/volunteer.wml 166) done maybe you can help write a paper or three also.</li>
en/volunteer.wml 167) <li>We need a measurement study of <a
en/volunteer.wml 168) href="http://www.pps.jussieu.fr/~jch/software/polipo/">Polipo</a>
en/volunteer.wml 169) vs <a href="http://www.privoxy.org/">Privoxy</a>. Is Polipo in fact
en/volunteer.wml 170) significantly faster, once you factor in the slow-down from Tor? Are the
en/volunteer.wml 171) results the same on both Linux and Windows? Related, does Polipo handle
en/volunteer.wml 172) more web sites correctly than Privoxy, or vice versa? Are there stability
en/volunteer.wml 173) issues on any common platforms, e.g. Windows?</li>
en/volunteer.wml 174) <li>Related on the above, would you like to help port <a
en/volunteer.wml 175) href="http://www.pps.jussieu.fr/~jch/software/polipo/">Polipo</a> so it
en/volunteer.wml 176) runs stably and efficiently on Windows?</li>
Roger Dingledine a few more design/coding it...

Roger Dingledine authored 17 years ago

en/volunteer.wml 177) <li>We need a distributed testing framework. We have unit tests,
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 178) but it would be great to have a script that starts up a Tor network, uses
en/volunteer.wml 179) it for a while, and verifies that at least parts of it are working.</li>
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 180) <!--
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml 181) <li>Right now the hidden service descriptors are being stored on just a
en/volunteer.wml 182) few directory servers. This is bad for privacy and bad for robustness. To
en/volunteer.wml 183) get more robustness, we're going to need to make hidden service
en/volunteer.wml 184) descriptors even less private because we're going to have to mirror them
en/volunteer.wml 185) onto many places. Ideally we'd like to separate the storage/lookup system
en/volunteer.wml 186) from the Tor directory servers entirely. The first problem is that we need
en/volunteer.wml 187) to design a new hidden service descriptor format to a) be ascii rather
en/volunteer.wml 188) than binary for convenience; b) keep the list of introduction points
en/volunteer.wml 189) encrypted unless you know the <tt>.onion</tt> address, so the directory
en/volunteer.wml 190) can't learn them; and c) allow the directories to verify the timestamp
en/volunteer.wml 191) and signature on a hidden service descriptor so they can't be tricked
en/volunteer.wml 192) into giving out fake ones. Second, any reliable distributed storage
en/volunteer.wml 193) system will do, as long as it allows authenticated updates, but as far
en/volunteer.wml 194) as we know no implemented DHT code supports authenticated updates.</li>
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 195) -->
Roger Dingledine add some more coding tasks...

Roger Dingledine authored 17 years ago

en/volunteer.wml 196) <li>Tor 0.1.1.x and later include support for hardware crypto accelerators
en/volunteer.wml 197) via
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   198) OpenSSL. Nobody has ever tested it, though. Does somebody want to get
volunteer.html   199) a card and let us know how it goes?</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   200) <li>Perform a security analysis of Tor with <a
volunteer.html   201) href="http://en.wikipedia.org/wiki/Fuzz_testing">"fuzz"</a>. Determine
Roger Dingledine fix wordo

Roger Dingledine authored 19 years ago

en/volunteer.wml 202) if there are good fuzzing libraries out there for what we want. Win fame by
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   203) getting credit when we put out a new release because of you!</li>
Roger Dingledine and i would like a pony.

Roger Dingledine authored 19 years ago

volunteer.html   204) <li>Tor uses TCP for transport and TLS for link
volunteer.html   205) encryption. This is nice and simple, but it means all cells
volunteer.html   206) on a link are delayed when a single packet gets dropped, and
volunteer.html   207) it means we can only reasonably support TCP streams. We have a <a
volunteer.html   208) href="http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#TransportIPnotTCP">list
Roger Dingledine revamp the list of voluntee...

Roger Dingledine authored 18 years ago

en/volunteer.wml 209) of reasons why we haven't shifted to UDP transport</a>, but it would
en/volunteer.wml 210) be great to see that list get shorter. We also have a proposed <a
Roger Dingledine ask santa for five new ponies

Roger Dingledine authored 17 years ago

en/volunteer.wml 211) href="<svnsandbox>doc/spec/proposals/100-tor-spec-udp.txt">specification
en/volunteer.wml 212) for Tor and
Roger Dingledine &mash; is not the same as &...

Roger Dingledine authored 18 years ago

en/volunteer.wml 213) UDP</a> &mdash; please let us know what's wrong with it.</li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   214) <li>We're not that far from having IPv6 support for destination addresses
volunteer.html   215) (at exit nodes). If you care strongly about IPv6, that's probably the
volunteer.html   216) first place to start.</li>
Roger Dingledine link to the 2007 roadmap to...

Roger Dingledine authored 17 years ago

en/volunteer.wml 217) <li>Don't like any of these? Look at the <a
en/volunteer.wml 218) href="<svnsandbox>doc/design-paper/roadmap-2007.pdf">Tor development
en/volunteer.wml 219) roadmap</a> for more ideas.</li>
en/volunteer.wml 220) <li>Don't see your idea here? We probably need it anyway! Contact
en/volunteer.wml 221) us and find out.</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   222) </ol>
volunteer.html   223) 
Roger Dingledine put anchors into the volunt...

Roger Dingledine authored 18 years ago

en/volunteer.wml 224) <a id="Research"></a>
en/volunteer.wml 225) <h2><a class="anchor" href="#Research">Research</a></h2>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   226) <ol>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   227) <li>The "website fingerprinting attack": make a list of a few
volunteer.html   228) hundred popular websites, download their pages, and make a set of
volunteer.html   229) "signatures" for each site. Then observe a Tor client's traffic. As
volunteer.html   230) you watch him receive data, you quickly approach a guess about which
volunteer.html   231) (if any) of those sites he is visiting. First, how effective is
volunteer.html   232) this attack on the deployed Tor codebase? Then start exploring
volunteer.html   233) defenses: for example, we could change Tor's cell size from 512
volunteer.html   234) bytes to 1024 bytes, we could employ padding techniques like <a
volunteer.html   235) href="http://freehaven.net/anonbib/#timing-fc2004">defensive dropping</a>,
volunteer.html   236) or we could add traffic delays. How much of an impact do these have,
volunteer.html   237) and how much usability impact (using some suitable metric) is there from
volunteer.html   238) a successful defense in each case?</li>
Roger Dingledine point to a paper that might...

Roger Dingledine authored 19 years ago

volunteer.html   239) <li>The "end-to-end traffic confirmation attack":
volunteer.html   240) by watching traffic at Alice and at Bob, we can <a
volunteer.html   241) href="http://freehaven.net/anonbib/#danezis:pet2004">compare
volunteer.html   242) traffic signatures and become convinced that we're watching the same
volunteer.html   243) stream</a>. So far Tor accepts this as a fact of life and assumes this
volunteer.html   244) attack is trivial in all cases. First of all, is that actually true? How
volunteer.html   245) much traffic of what sort of distribution is needed before the adversary
volunteer.html   246) is confident he has won? Are there scenarios (e.g. not transmitting much)
volunteer.html   247) that slow down the attack? Do some traffic padding or traffic shaping
volunteer.html   248) schemes work better than others?</li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   249) <li>The "routing zones attack": most of the literature thinks of
volunteer.html   250) the network path between Alice and her entry node (and between the
volunteer.html   251) exit node and Bob) as a single link on some graph. In practice,
volunteer.html   252) though, the path traverses many autonomous systems (ASes), and <a
volunteer.html   253) href="http://freehaven.net/anonbib/#feamster:wpes2004">it's not uncommon
volunteer.html   254) that the same AS appears on both the entry path and the exit path</a>.
volunteer.html   255) Unfortunately, to accurately predict whether a given Alice, entry,
volunteer.html   256) exit, Bob quad will be dangerous, we need to download an entire Internet
volunteer.html   257) routing zone and perform expensive operations on it. Are there practical
volunteer.html   258) approximations, such as avoiding IP addresses in the same /8 network?</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   259) <li>Tor doesn't work very well when servers have asymmetric bandwidth
volunteer.html   260) (e.g. cable or DSL). Because Tor has separate TCP connections between
volunteer.html   261) each hop, if the incoming bytes are arriving just fine and the outgoing
volunteer.html   262) bytes are all getting dropped on the floor, the TCP push-back mechanisms
volunteer.html   263) don't really transmit this information back to the incoming streams.
volunteer.html   264) Perhaps Tor should detect when it's dropping a lot of outgoing packets,
volunteer.html   265) and rate-limit incoming streams to regulate this itself? I can imagine
volunteer.html   266) a build-up and drop-off scheme where we pick a conservative rate-limit,
volunteer.html   267) slowly increase it until we get lost packets, back off, repeat. We
volunteer.html   268) need somebody who's good with networks to simulate this and help design
volunteer.html   269) solutions; and/or we need to understand the extent of the performance
volunteer.html   270) degradation, and use this as motivation to reconsider UDP transport.</li>
volunteer.html   271) <li>A related topic is congestion control. Is our
volunteer.html   272) current design sufficient once we have heavy use? Maybe
volunteer.html   273) we should experiment with variable-sized windows rather
volunteer.html   274) than fixed-size windows? That seemed to go well in an <a
volunteer.html   275) href="http://www.psc.edu/networking/projects/hpn-ssh/theory.php">ssh
volunteer.html   276) throughput experiment</a>. We'll need to measure and tweak, and maybe
volunteer.html   277) overhaul if the results are good.</li>
Roger Dingledine revamp again

Roger Dingledine authored 19 years ago

volunteer.html   278) <li>To let dissidents in remote countries use Tor without being blocked
volunteer.html   279) at their country's firewall, we need a way to get tens of thousands of
volunteer.html   280) relays, not just a few hundred. We can imagine a Tor client GUI that
volunteer.html   281) has a "help China" button at the top that opens a port and relays a
volunteer.html   282) few KB/s of traffic into the Tor network. (A few KB/s shouldn't be too
volunteer.html   283) much hassle, and there are few abuse issues since they're not being exit
volunteer.html   284) nodes.) But how do we distribute a list of these volunteer clients to the
volunteer.html   285) good dissidents in an automated way that doesn't let the country-level
volunteer.html   286) firewalls intercept and enumerate them? Probably needs to work on a
Roger Dingledine more detail on the communic...

Roger Dingledine authored 19 years ago

en/volunteer.wml 287) human-trust level. See our <a
en/volunteer.wml 288) href="http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#China">FAQ
en/volunteer.wml 289) entry</a> on this, and then read the <a
en/volunteer.wml 290) href="http://freehaven.net/anonbib/topic.html#Communications_20Censorship">censorship
en/volunteer.wml 291) resistance section of anonbib</a>.</li>
Roger Dingledine one pony is not enough.

Roger Dingledine authored 19 years ago

volunteer.html   292) <li>Tor circuits are built one hop at a time, so in theory we have the
volunteer.html   293) ability to make some streams exit from the second hop, some from the
volunteer.html   294) third, and so on. This seems nice because it breaks up the set of exiting
volunteer.html   295) streams that a given server can see. But if we want each stream to be safe,
volunteer.html   296) the "shortest" path should be at least 3 hops long by our current logic, so
volunteer.html   297) the rest will be even longer. We need to examine this performance / security
volunteer.html   298) tradeoff.</li>
volunteer.html   299) <li>It's not that hard to DoS Tor servers or dirservers. Are client
volunteer.html   300) puzzles the right answer? What other practical approaches are there? Bonus
volunteer.html   301) if they're backward-compatible with the current Tor protocol.</li>
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   302) </ol>
volunteer.html   303) 
Roger Dingledine un-list the installer todo...

Roger Dingledine authored 18 years ago

en/volunteer.wml 304) <a href="<page contact>">Let us know</a> if you've made progress on any
en/volunteer.wml 305) of these!
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   306) 
Peter Palfrader Move website to wml

Peter Palfrader authored 19 years ago

en/volunteer.wml 307)   </div><!-- #main -->
Roger Dingledine revamp the volunteer page....

Roger Dingledine authored 19 years ago

volunteer.html   308) 
Peter Palfrader Move website to wml

Peter Palfrader authored 19 years ago

en/volunteer.wml 309) #include <foot.wmi>