Re: Freenet in Whonix

Arne Babenhauserheide <arne_bab-S0/[email protected]>
Newsgroups gmane.network.freenet.devel
Message-ID <[email protected]>
[email protected] writes:
> * Whonix Gateway is a separate VM that forces all traffic thru any 
> anonymous network of choice
> * Whonix Workstation - The untrusted VM where users run applications 
> configured with safe defaults that can only access the network via a 
> virtual isolated NIC connected only to Whonix Gateway.
>
>
> For this to work with Freenet we need to make sure that:
>
> * Freenet on the the Gateway can be locked down preventing malicious 
> commands from affecting its configuration.

Freenet has a "public gateway" mode which limits the amount of changes
the user can do to the Freenet instance.

* Public gateway mode? (Only applies to allowed but non-full-access connections)
  Should we enable public gateway mode? For IPs which are allowed to
  access Freenet, but are not allowed full access, this option disables
  the download queue and anything else that might conceivably be abused
  to attack the Freenet node, while still allowing browsing
  freesites. They will also only see the default bookmarks, not your
  bookmarks. IP addresses with full access will be allowed to configure
  the node. You will still need to configure allowed addresses and bind
  address to get a true public gateway; you should do this after
  restarting.

→ http://127.0.0.1:8888/config/fproxy?fproxyAdvancedMode=2

* Hosts allowed full access 
  IP addresses which are allowed full access to your Freenet
  node. Clients on these IPs may restart Freenet, reconfigure it,
  etc. Note that ALL clients are allowed to do direct disk I/O!

→ http://127.0.0.1:8888/config/fcp?fproxyAdvancedMode=2

> * A second Freenet instance in the Workstation is running in a dummy 
> mode thats used to run Freenet plugins/applications and connects via the 
> Gateway Freenet to make network requests while any data is cached only 
> on the workstation.

Sounds good.

You can either connect the second instance to the workstation via
friend-to-friend mode (this won’t be very fast, though, since load
balancing will give you only a fair fraction of the bandwidth of the
gateway), or you can SSH-forward the FCP and web port of the gateway to
the local system (this is what I do: Freenet runs on my homeserver and
the local system only gets the ports via SSH). Then the applications can
run on the local system (but plugins still run on the gateway).

This is in my /etc/local.d/freenet-forward.start:

    su [user] -c "while true; do ssh -NL 8888:localhost:8888 -L 9481:localhost:9481 -L 8080:localhost:8080 -L 4025:localhost:4025 -L 4143:localhost:4143 [host] ; sleep 5; done &"

→ web-interface 8888, fcp 9481, FMS (forums) 8080, smtp 4025, imap 4143

To still restrict access when ssh forwarding, you can change the full
access connections from 127.0.0.1 and 0:…:1 to 127.0.0.4 and 0:…:4 to
block localhost, too, and only adjust dangerous settings by shutting
down the node, editing freenet.ini and starting it up again.
(though the additional security of this might be limited, see
http://serverfault.com/a/752076/229575)

→ http://127.0.0.1:8888/config/fproxy?fproxyAdvancedMode=2

and

http://127.0.0.1:8888/config/fcp

In freenet.ini:

    fproxy.allowedHostsFullAccess=127.0.0.1,0:0:0:0:0:0:0:1

Best wishes,
Arne
-- 
Unpolitisch sein
heißt politisch sein
ohne es zu merken

_______________________________________________
Devl mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/devl
signature.asc (application/pgp-signature, 800 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJYVmfEAAoJEBPvjUUkA8PrEgQP/1G0k8/h/ZBTGIyFm9guMs72
8BGpmXkgOMosZyNx7Vg6mqUJ8ZJI4xVdpPx4c8BJ1SABvsb6TvH/yGlYkE2Rh16o
B2EkMywKt3EGVRI8M2fPTYOQ9fW/0g6oaaEq9YwVzXqg9oslGO0wPM8eFFRGkpzD
jpvtrN+MNVzlEhmLamJKiHBEXJqBFJeuqYSJNTGWM+Bfws/7ne06EhGi10mbdwFC
/OTMaCqbmd/6EacgUMoc9Ik+kC/esIeVjqTg9Mh2qtNCJeq4wc5sreaEUCdyjW2f
iSijcf/qRqzZr9pqF3iKAl/wseG0W7D9Iyv7ked3+cc3o3REYVPjxBPrRLHDAN1X
LROpRhqy47h2q18E0V8gYNEQafKDbgl+rxT1OJ+fghXli3OmvKIdcDUrmWbrncgW
lSrXIN3N91VOSP7vL7UX//4TubCjtZrImsCuBD1fBcE8KV/tyWb+szEN8dq2Lm/W
iH4kXhRj2l1idNlOnVKTTheZRagvEL2Al/h27tCWdiwyeB7e+rAwUcXWVD+apB51
PRa6mDRpvQkIm3Vje2TEm04FRUrM5Ah5R4s91X7Pd8+FN0MdkwBC9BsJgCkfTHyM
s40w6ODB7tfpsMxet2YfCPA5KpbSxzgsKmnmISCsuam0u2dNaO8QgbYW3VP/dWwJ
DNSzkRazSi52mcFGWm03
=YvCY
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.