We've Moved! Visit our NEW FORUM to join the latest discussions. This is an archive of our previous conversations...

You can find the login page for the old forum here.
CHATPRIVACYDONATELOGINREGISTER
DMT-Nexus
FAQWIKIHEALTH & SAFETYARTATTITUDEACTIVE TOPICS
(Summoning Traveler) Simple improvements to the chat/forum Options
 
nexalizer
#1 Posted : 12/28/2016 8:29:47 PM
El viajero, I humbly suggest two simple improvements to the forum:

1) anoniem should be using https:// (the site is capable of it, but the forum software is not linking to https://)
2) for .onion links, anoniem should not be used (like the way links to the forum already bypass anoniem), possibly a red [TOR] warning so that people know not to click it if they're not on a tor-capable browser (nothing major, but a dns leak will then occur).

And possibly a third that would personally make me overjoyed with.. well, joy:

3) Provide two .onion hidden services, one for the forum, one for the chat. Given the nature of our research and the inherent dangers associated with it when it comes to interacting with the law, offering the possibility for users to not even have to leave the tor network to access the forum/chat would be a great improvement.


Thank you for considering these improvements, and may the bright light of 500mg of mescaline continue to (allegedly) shine on you.

<3



This is the time to really find out who you are and enjoy every moment you have. Take advantage of it.
 
pitubo
Senior Member
#2 Posted : 12/28/2016 9:34:09 PM
4. Disable embedding of external content, such as youtube and image hosters.

Every time I visit a page on dmt-nexus that embeds one of the above, automatically a request bearing my ip is sent to the 3rd party website. Even more worrisome, if I am correct, is that also a "Referer" http request header indicating "dmt-nexus.me" is sent to the external site hosting the content embedded on the dmt-nexus page. This is potentially compromising information leakage.

Apart from altogether banning embedding, I see two ways of dealing with this:
- an "anoniem" type construct could be created for iframes.
- theoretically, a low res version or thumbnail could be cached on the dmt-nexus site and the actual iframe is only activated after clicking on it or the browser is simply pointed to another page, via the anoniem service. However, in practice, the creation of a locally cached version of the content would mean users triggering scripts to process off-site untrusted data, this is obviously a very bad idea.

Personally, I would vote for no more embedding. Writers will still be able to use hyperlinks to link to their off site content and readers will be free to choose if they want to visit the 3rd party site. As a bonus, threads with 50 youtube iframes will no longer freeze older computers for minutes.

5. links to wiki.dmt-nexus.me do not need to be gated through anoniem.org.
 
 
Users browsing this forum
Guest

DMT-Nexus theme created by The Traveler
This page was generated in 0.009 seconds.