<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=gb2312" http-equiv=Content-Type>
<STYLE>BLOCKQUOTE {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px; MARGIN-LEFT: 2em
}
OL {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
UL {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
</STYLE>

<META name=GENERATOR content="MSHTML 8.00.6001.18812"></HEAD>
<BODY style="MARGIN: 10px">
<DIV><FONT color=#000080 size=2 face=Verdana>
<DIV><FONT size=2 face=Verdana>
<DIV><FONT color=#000000 size=2 face=Verdana></FONT>&nbsp;</DIV>
<DIV style="TEXT-INDENT: 2em"><FONT color=#000000>Seems that it's a weak point 
of current Tor architecture. From a network manager's point of view,&nbsp;simply 
blocking the&nbsp;Tor nodes&nbsp;posted in&nbsp;Tor directory 
servers&nbsp;will&nbsp;infuence&nbsp;Tor users dramatically in the local 
network.&nbsp;</FONT></DIV>
<DIV><FONT color=#000000></FONT>&nbsp;</DIV></FONT></FONT><FONT 
color=#c0c0c0></DIV></DIV>
<DIV><FONT color=#000000 size=2 face=Verdana>
<TABLE width="100%">
  <TBODY>
  <TR>
    <TD width="100%">
      <BLOCKQUOTE 
      style="BORDER-LEFT: #000000 2px solid; PADDING-LEFT: 5px; PADDING-RIGHT: 0px; MARGIN-LEFT: 5px; MARGIN-RIGHT: 0px">
        <DIV>Fyi</DIV>
        <DIV></DIV>
        <DIV>(For&nbsp;those&nbsp;of&nbsp;you&nbsp;who&nbsp;want&nbsp;to&nbsp;be&nbsp;on&nbsp;tor-relays,&nbsp;you&nbsp;can&nbsp;learn&nbsp;more&nbsp;about</DIV>
        <DIV>it&nbsp;at&nbsp;https://www.torproject.org/documentation.html.en#MailingLists&nbsp;)</DIV>
        <DIV></DIV>
        <DIV>--Roger</DIV>
        <DIV></DIV>
        <DIV>-----&nbsp;Forwarded&nbsp;message&nbsp;from&nbsp;Roger&nbsp;Dingledine&nbsp;&lt;arma@MIT.EDU&gt;&nbsp;-----</DIV>
        <DIV></DIV>
        <DIV>From:&nbsp;Roger&nbsp;Dingledine&nbsp;&lt;arma@MIT.EDU&gt;</DIV>
        <DIV>To:&nbsp;tor-relays@torproject.org</DIV>
        <DIV>Subject:&nbsp;Tor&nbsp;partially&nbsp;blocked&nbsp;in&nbsp;China;&nbsp;change&nbsp;your&nbsp;relay's&nbsp;IP&nbsp;address?</DIV>
        <DIV>Delivery-Date:&nbsp;Wed,&nbsp;30&nbsp;Sep&nbsp;2009&nbsp;04:23:28&nbsp;-0400</DIV>
        <DIV></DIV>
        <DIV>Hi&nbsp;folks,</DIV>
        <DIV></DIV>
        <DIV>China&nbsp;blocked&nbsp;about&nbsp;80%&nbsp;of&nbsp;the&nbsp;public&nbsp;Tor&nbsp;relays&nbsp;last&nbsp;week:</DIV>
        <DIV>https://blog.torproject.org/blog/tor-partially-blocked-china</DIV>
        <DIV></DIV>
        <DIV>They're&nbsp;really&nbsp;focused&nbsp;on&nbsp;circumvention&nbsp;tools&nbsp;this&nbsp;week&nbsp;in&nbsp;preparation</DIV>
        <DIV>for&nbsp;their&nbsp;upcoming&nbsp;Oct&nbsp;1:</DIV>
        <DIV>http://en.wikipedia.org/wiki/National_Day_of_the_People's_Republic_of_China</DIV>
        <DIV></DIV>
        <DIV>Many&nbsp;bridges&nbsp;are&nbsp;still&nbsp;working&nbsp;fine,&nbsp;though&nbsp;they&nbsp;did&nbsp;block&nbsp;quite&nbsp;a&nbsp;few</DIV>
        <DIV>of&nbsp;them&nbsp;too.&nbsp;Eventually&nbsp;it&nbsp;would&nbsp;be&nbsp;good&nbsp;to&nbsp;shift&nbsp;your&nbsp;Tor&nbsp;relay&nbsp;onto</DIV>
        <DIV>an&nbsp;IP&nbsp;address&nbsp;that&nbsp;isn't&nbsp;blocked.</DIV>
        <DIV></DIV>
        <DIV>There&nbsp;are&nbsp;two&nbsp;ways&nbsp;that&nbsp;they're&nbsp;doing&nbsp;blocking.&nbsp;One&nbsp;is&nbsp;to&nbsp;filter&nbsp;your</DIV>
        <DIV>whole&nbsp;IP&nbsp;address:&nbsp;no&nbsp;packets&nbsp;get&nbsp;in&nbsp;or&nbsp;out.&nbsp;You&nbsp;can&nbsp;check&nbsp;if&nbsp;this&nbsp;has</DIV>
        <DIV>happened&nbsp;to&nbsp;you&nbsp;by&nbsp;trying&nbsp;to&nbsp;reach&nbsp;baidu.com&nbsp;from&nbsp;your&nbsp;IP&nbsp;address.&nbsp;The</DIV>
        <DIV>other&nbsp;blocking&nbsp;approach&nbsp;is&nbsp;to&nbsp;send&nbsp;TCP&nbsp;reset&nbsp;packets&nbsp;when&nbsp;connections</DIV>
        <DIV>are&nbsp;attempted&nbsp;to&nbsp;your&nbsp;IP:port.&nbsp;That's&nbsp;harder&nbsp;to&nbsp;check.&nbsp;I&nbsp;did&nbsp;a&nbsp;scan&nbsp;last</DIV>
        <DIV>week&nbsp;from&nbsp;inside&nbsp;China,&nbsp;and&nbsp;I've&nbsp;put&nbsp;the&nbsp;result&nbsp;for&nbsp;your&nbsp;IP&nbsp;address&nbsp;up</DIV>
        <DIV>at&nbsp;http://freehaven.net:8081/2009-09-24/&lt;IP&gt;</DIV>
        <DIV>e.g.&nbsp;http://freehaven.net:8081/2009-09-24/128.31.0.34</DIV>
        <DIV></DIV>
        <DIV>Note&nbsp;that&nbsp;the&nbsp;above&nbsp;URL&nbsp;includes&nbsp;answers&nbsp;about&nbsp;both&nbsp;known-blocked&nbsp;relays</DIV>
        <DIV>and&nbsp;also&nbsp;known-blocked&nbsp;bridges.</DIV>
        <DIV></DIV>
        <DIV>It's&nbsp;possible&nbsp;that&nbsp;they'll&nbsp;remove&nbsp;the&nbsp;blocking&nbsp;all&nbsp;by&nbsp;themselves&nbsp;in&nbsp;a</DIV>
        <DIV>few&nbsp;days,&nbsp;once&nbsp;Oct&nbsp;1&nbsp;passes.&nbsp;It's&nbsp;also&nbsp;possible&nbsp;they'll&nbsp;do&nbsp;another&nbsp;round</DIV>
        <DIV>of&nbsp;blocking&nbsp;real&nbsp;soon&nbsp;now.&nbsp;Hard&nbsp;to&nbsp;say.</DIV>
        <DIV></DIV>
        <DIV>So&nbsp;if&nbsp;it's&nbsp;hard&nbsp;for&nbsp;you&nbsp;to&nbsp;get&nbsp;a&nbsp;new&nbsp;IP&nbsp;address,&nbsp;I&nbsp;recommend&nbsp;waiting</DIV>
        <DIV>until&nbsp;at&nbsp;least&nbsp;next&nbsp;week.&nbsp;But&nbsp;if&nbsp;you&nbsp;have&nbsp;plenty&nbsp;to&nbsp;spare&nbsp;(or&nbsp;you're</DIV>
        <DIV>on&nbsp;a&nbsp;cable/DSL&nbsp;system&nbsp;that&nbsp;will&nbsp;give&nbsp;you&nbsp;a&nbsp;new&nbsp;IP&nbsp;address&nbsp;if&nbsp;you&nbsp;just</DIV>
        <DIV>poweroff&nbsp;your&nbsp;cable&nbsp;modem&nbsp;for&nbsp;a&nbsp;while),&nbsp;then&nbsp;now&nbsp;would&nbsp;be&nbsp;a&nbsp;fine&nbsp;time</DIV>
        <DIV>to&nbsp;switch&nbsp;to&nbsp;a&nbsp;new&nbsp;one.</DIV>
        <DIV></DIV>
        <DIV>Remember&nbsp;that&nbsp;if&nbsp;you're&nbsp;on&nbsp;a&nbsp;multi-homed&nbsp;computer&nbsp;and&nbsp;moving&nbsp;to&nbsp;a</DIV>
        <DIV>non-default&nbsp;IP,&nbsp;you&nbsp;will&nbsp;want&nbsp;to&nbsp;set&nbsp;both&nbsp;Address&nbsp;and&nbsp;OutboundBindAddress</DIV>
        <DIV>in&nbsp;your&nbsp;torrc.</DIV>
        <DIV></DIV>
        <DIV>Thanks!</DIV>
        <DIV>--Roger</DIV>
        <DIV></DIV>
        <DIV>-----&nbsp;End&nbsp;forwarded&nbsp;message&nbsp;-----</DIV>
        <DIV></DIV>
        <DIV>***********************************************************************</DIV>
        <DIV>To&nbsp;unsubscribe,&nbsp;send&nbsp;an&nbsp;e-mail&nbsp;to&nbsp;majordomo@torproject.org&nbsp;with</DIV>
        <DIV>unsubscribe&nbsp;or-talk&nbsp;&nbsp;&nbsp;&nbsp;in&nbsp;the&nbsp;body.&nbsp;<A 
        href="http://archives.seul.org/or/talk/">http://archives.seul.org/or/talk/</A></DIV></BLOCKQUOTE></TD></TR></TBODY></TABLE></FONT></DIV>
<DIV><FONT color=#000000 size=2 face=Verdana></FONT>&nbsp;</DIV>
<DIV><FONT color=#000000 size=2 face=Verdana>Allen 
Ling</FONT></DIV></FONT></BODY></HTML>