[tor-project] Anti-censorship team meeting notes, 2022-03-10
meskio at torproject.org
Thu Mar 10 18:20:19 UTC 2022
Here are our meeting logs:
And our meeting pad:
Anti-censorship work meeting pad
Next meeting: Thursday March 17th 16:00 UTC
Weekly meetings, every Thursday at 16:00 UTC, in #tor-meeting at OFTC (channel is logged while meetings are in progress)
== Goal of this meeting ==
Weekly checkin about the status of anti-censorship work at Tor.
Coordinate collaboration between people/teams on anti-censorship at Tor.
== Links to Useful documents ==
* Our anti-censorship roadmap:
* Roadmap: https://gitlab.torproject.org/groups/tpo/anti-censorship/-/boards
* The anti-censorship team's wiki page:
* Past meeting notes can be found at:
* Tickets that need reviews: from sponsors we are working on:
* All needs review tickets: https://gitlab.torproject.org/groups/tpo/anti-censorship/-/merge_requests?scope=all&utf8=%E2%9C%93&state=opened&assignee_id=None
* Sponsor 30
* Sponsor 28
* must-do tickets: https://gitlab.torproject.org/groups/tpo/-/milestones/10
* possible tickets: https://gitlab.torproject.org/groups/tpo/-/issues?scope=all&utf8=%E2%9C%93&state=opened&label_name%5b%5d=Sponsor%2028&milestone_title=None
== Announcements ==
== Discussion ==
* (from March 11th) Reach an agreement on distributed Snowflake (Broker)|(Server) design. Shel: are you going to be workign on https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/issues/28651 ? What else we need to move forward on it? -- from gaba
* The client telling the broker what bridge it wants to use: https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/merge_requests/81
* missing pieces:
* broker having a list of known bridge fingerprints
* proxies telling the broker what bridges they know about in their poll messages
* might be a good next step
* arlo is happy to pick this up, if it's helpful +1
* broker matching clients with proxies, considering not only NAT compatibility but bridge fingerprint
* proxies will need to both (1) know how to interpret the broker's instructions as to what websocket server to connect to, and (2) know how to forward the client's requested bridge fingerprint to the websocket server.
* a proxy that does not signal such support to the broker can be matched only with clients that either: do not specify a bridge fingerprint, or specify the current default 2B280B23E1107BB62ABFC40DDCC8824814F80A72
* proxies forwarding bridge fingerprint to snowflake-server intheir websocket connection
* snowflake-server having its own internal mapping of bridge fingerprint -> ExtORPort address
* needs a configuration file or something, can no longer come from TOR_PT_EXTENDED_SERVER_PORT environment variable since there may be more than one
* Next steps:
* who is doing what?
* snowflake proxy auto-update?
* webextensions have their usual update mechanism
* docker auto-update if enabled
* deb package updates
* people compiling and running their own go-proxy, no updates or notifications of updates
* the web badge does a page refresh (i think)
== Actions ==
== Interesting links ==
* running snowflake proxy on OpenBSD
== Reading group ==
* We will discuss "Throttling Twitter: an emerging censorship technique in Russia" on 17 March
* Questions to ask and goals to have:
* What aspects of the paper are questionable?
* Are there immediate actions we can take based on this work?
* Are there long-term actions we can take based on this work?
* Is there future work that we want to call out, in hopes that others will pick it up?
== Updates ==
- What you worked on this week.
- What you are planning to work on next week.
- Something you need help with.
- Increase timeout check cycles for default-bridge-felix-1 and default-bridge-felix-2 as they have been generating too many alerts: https://gitlab.torproject.org/tpo/anti-censorship/monit-configuration/-/merge_requests/1
cecylia (cohosh): last updated 2022-03-10
- worked on setting up a dev environment for conjure
- some reviews
- continued work on conjure PT
- continue to monitor snowflake broker stats
- review rdsys!15
Needs help with:
- worked on aquiring resources for better hosting for the snowflake bridge
- posted summary of snowflake amp cache https://github.com/net4people/bbs/issues/109
- posted observations on multi-instance metrics graphs https://gitlab.torproject.org/tpo/network-health/metrics/onionoo/-/issues/40022#note_2783524
- posted summary of last week's discussion about multiple snowflake bridges https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/issues/28651#note_2783541
- posted notes about IGD port forwarding https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/issues/40106#note_2784834
- review arlo's bridge fingerprint forwarding change https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/merge_requests/81
- Continued work on gettor-twitter
- Hopefully finish the task
- Pass bridge fingerprint in SOCKS param to the broker
- Revise !81
- Start on the next piece of the multiple bridge design
- Figure out where in pion/webrtc ALPN should be configured and used
- Maybe add Chacha20Poly1305 to pion/dtls
- Worked on https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/issues/40054 re: utls for broker negotiation
- Had conversation with someone about upstream utls http round tripper https://github.com/refraction-networking/utls/pull/74
- Too busy with work :/
- _Really_ want to get a PR for utls round tripper
- use bridge-distribution-request in rdsys (rdsys#93)
- use rdsys bridges in circumvention settings (bridgedb#40045)
- send the right assingments.log to the metrics
- add some untilisting mechanism to circumvention settings (rdsys#79)
- [Merge Request Awaiting] Add SOCKS5 forward proxy support to snowflake (snowflake!64)
- [Merge Request Awaiting] uTLS for broker negotiation(Updated)
- [Coding & Deployment] Proposal: Centralized Probe Result Collector (anti-censorship/team#54)
- [Deployment] Vantage Point in Vinnica, Ukraine
- [Discussion] Centralized Probe Log Collection Ascension Request
- [Discussion] Hosting Centralized Probe Log Collection Server on TPA managed VPS
- [Coding] Add SOCKS5 forward proxy support to snowflake (snowflake!64) - built-in DNS
Setup web mirror on tor.encryptionin.space
Get (new VPs with) new IP and setup new web mirror on new domain
- Submitted MR for bridgestrap issue #14
- Finish bridgestrap #14
- Find new issue to work on
meskio | https://meskio.net/
My contact info: https://meskio.net/crypto.txt
Nos vamos a Croatan.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
More information about the tor-project