From 5a4dba5010f68a53537dc9c3311f9566b3f26d6d Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sat, 30 Jul 2016 17:46:38 -0400 Subject: [PATCH 1/6] Update common.yml --- common.yml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/common.yml b/common.yml index e7228c2..d016a8b 100644 --- a/common.yml +++ b/common.yml @@ -95,7 +95,7 @@ - "# Your IPsec server is running. #" - "# Config files and X.509 certificates in the directory: ./configs/ #" - "# After connect go to https://www.dnsleaktest.com/ #" - - "# and ensure that all your traffic pass through the VPN. #" + - "# and ensure that all your traffic passes through the VPN. #" - "#----------------------------------------------------------------------#" handlers: @@ -110,5 +110,3 @@ - name: flush routing cache shell: echo 1 > /proc/sys/net/ipv4/route/flush - - From 54c5889e0928f9c691341cb718494d9b0a6d11f4 Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sat, 30 Jul 2016 17:50:10 -0400 Subject: [PATCH 2/6] Update README.md --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 9e100e4..b2b06a8 100644 --- a/README.md +++ b/README.md @@ -15,7 +15,7 @@ Algo (short for "Al Gore", the **V**ice **P**resident of **N**etworks everywhere ## Anti-features -* Does not support legacy cipher suites or protocols, like L2TP or IKEv1 +* Does not support legacy cipher suites or protocols like L2TP or IKEv1 * Does not install Tor, OpenVPN, or other insecure servers * Does not require client software on most platforms * Does not claim to provide anonymity @@ -50,4 +50,4 @@ No. This project is under active development. We're happy to [accept and fix iss ### Why aren't you using Tor? -The goal of this project is not to provide anonymity, but to ensure confidentiality of network traffic while traveling. Tor introduces new risks that are unsuitable for algo's intended usesrs. Namely, with algo, users are in control over the gateway routing their traffic. With Tor, users are at the mercy of [actively](https://www.securityweek2016.tu-darmstadt.de/fileadmin/user_upload/Group_securityweek2016/pets2016/10_honions-sanatinia.pdf) [malicious](https://chloe.re/2015/06/20/a-month-with-badonions/) [exit](https://community.fireeye.com/people/archit.mehta/blog/2014/11/18/onionduke-apt-malware-distributed-via-malicious-tor-exit-node) [nodes](https://www.wired.com/2010/06/wikileaks-documents/). +The goal of this project is not to provide anonymity, but to ensure confidentiality of network traffic while traveling. Tor introduces new risks that are unsuitable for algo's intended users. Namely, with algo, users are in control over the gateway routing their traffic. With Tor, users are at the mercy of [actively](https://www.securityweek2016.tu-darmstadt.de/fileadmin/user_upload/Group_securityweek2016/pets2016/10_honions-sanatinia.pdf) [malicious](https://chloe.re/2015/06/20/a-month-with-badonions/) [exit](https://community.fireeye.com/people/archit.mehta/blog/2014/11/18/onionduke-apt-malware-distributed-via-malicious-tor-exit-node) [nodes](https://www.wired.com/2010/06/wikileaks-documents/). From ab0c66393bc2f257d67b7ef03c5393ae6664abf8 Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sat, 30 Jul 2016 17:50:41 -0400 Subject: [PATCH 3/6] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index b2b06a8..a4b5ea3 100644 --- a/README.md +++ b/README.md @@ -46,7 +46,7 @@ ansible-playbook users.yml -i inventory_users -l example.com ### Has this been audited? -No. This project is under active development. We're happy to [accept and fix issues](https://github.com/trailofbits/algo/issues) as they are identified. +No. This project is under active development. Use algo at your own risk. We're happy to [accept and fix issues](https://github.com/trailofbits/algo/issues) as they are identified. ### Why aren't you using Tor? From e1ce366cc8b73977157afc0a4ce4047423ddc231 Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sat, 30 Jul 2016 17:51:13 -0400 Subject: [PATCH 4/6] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index a4b5ea3..5a30f0a 100644 --- a/README.md +++ b/README.md @@ -46,7 +46,7 @@ ansible-playbook users.yml -i inventory_users -l example.com ### Has this been audited? -No. This project is under active development. Use algo at your own risk. We're happy to [accept and fix issues](https://github.com/trailofbits/algo/issues) as they are identified. +No. This project is under active development. We're happy to [accept and fix issues](https://github.com/trailofbits/algo/issues) as they are identified. Use algo at your own risk. ### Why aren't you using Tor? From 4fea57afdcae962ed85ff94477e216a30e89b78e Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sat, 30 Jul 2016 18:20:01 -0400 Subject: [PATCH 5/6] Update README.md --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 5a30f0a..87a3c95 100644 --- a/README.md +++ b/README.md @@ -15,8 +15,9 @@ Algo (short for "Al Gore", the **V**ice **P**resident of **N**etworks everywhere ## Anti-features -* Does not support legacy cipher suites or protocols like L2TP or IKEv1 +* Does not support legacy cipher suites or protocols like L2TP, IKEv1, or RSA * Does not install Tor, OpenVPN, or other insecure servers +* Does not depend on the security of TLS * Does not require client software on most platforms * Does not claim to provide anonymity * Does not claim to protect you from the [FSB](https://en.wikipedia.org/wiki/Federal_Security_Service), [MSS](https://en.wikipedia.org/wiki/Ministry_of_State_Security_(China)), [DGSE](https://en.wikipedia.org/wiki/Directorate-General_for_External_Security), or [FSM](https://en.wikipedia.org/wiki/Flying_Spaghetti_Monster) From a3f45a6eee6dbf406411335d958e4fb472ab79a6 Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sun, 31 Jul 2016 01:17:11 -0400 Subject: [PATCH 6/6] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 87a3c95..9131fda 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,7 @@ Algo (short for "Al Gore", the **V**ice **P**resident of **N**etworks everywhere * Does not support legacy cipher suites or protocols like L2TP, IKEv1, or RSA * Does not install Tor, OpenVPN, or other insecure servers -* Does not depend on the security of TLS +* Does not depend on the security of [TLS](https://tools.ietf.org/html/rfc7457) * Does not require client software on most platforms * Does not claim to provide anonymity * Does not claim to protect you from the [FSB](https://en.wikipedia.org/wiki/Federal_Security_Service), [MSS](https://en.wikipedia.org/wiki/Ministry_of_State_Security_(China)), [DGSE](https://en.wikipedia.org/wiki/Directorate-General_for_External_Security), or [FSM](https://en.wikipedia.org/wiki/Flying_Spaghetti_Monster)