[jump to content]
Processrun@status
Freenet 20117628 WARN 5107down: 0 30261 latest 5109
I2P latest 20068315 WARN 0.8.8down: 2011-08-23
I2P router1 20068315 W 0.8.7-0down: OK 4d t:1025+63+12 m:14408/224888
I2P router2 88325505 0.7.5-34-rcdown: OK 45h t:411+13+18 m:52992/58828
Reachability 60 185/166/256good: 1 (1-1)
deadloop 46 224/323pop.postman.i2p
hourly 8 123/211lib.i2p
probeloop 34 758/2364game.i2p
[ Home | Status | Graph | FAQ | Links | More.. ]
I2P router currently down!
Your IP is 38.107.179.223, you are probably not anonymous (i2p.to).
Contact General Technical Legal Policy Information Administrative Background

FAQ

Q: I want to contact you (anonymously) / I have a FAQ which is not answered here / I have a feature request

A: Please send your question/report to me using my pager under http://hydra.geht.net/pager.php. From within I2P you can reach it as http://www.tino.i2p/pager.php as well. Do this as follows:

Don't forget to make this message important if it is really important (important for me, like there is a legal threat against me).
You can send me messages in English and German language. Messages in other languages I cannot read and therefor cannot answer, sorry.
Anonymous messages are welcome. That's what the pager is for. So post a message and leave away your name or eMail-address if you like!

Q: What is I2P?

A: I2P is an anonymous network within the Internet which tries to protect the anonymity of the I2P users. If you want to know more:

Here is an incomplete list of other types of anonymous networks which try to ensure that people can stay anonymous even against very powerful adversaries (like states):

Please do not confuse anonymous networks with anonymity proxy services, even that TOR provides one. And please note that this here is not I2P. It is only a proxy to a part of I2P.

Q: What is this place here?

A: This is the web frontend of one of the public proxies into the I2P network. Or a little more explained:

To stress it:
Q: Are there other proxies into the I2P network?

A: Yes, check the links, I call those I2PinProxies. However this list may be incomplete.

Q: This FAQ is quite long

A: Yes. But searching a single web page is more easy than do this with a bunch of pages.

Q: This FAQ is a bit redundant

A: Please forgive me, no time to reorganize.

Q: How can I add my eepsite to this proxy service? Can you add my eepsite to your service?

A: This is a fully automatic process. I cannot and will not speed up this process, but perhaps you can complete the steps (noted below) more quickly. To find out if an eepsite is already known and which keys are used to access it, look into my hosts.txt:

If the eepsite is unknown yet we have to wait until the site becomes available in addresshelper. Then the automated process picks up the new destination. The destination will then be listed here after the next probe round, which takes a day or two. This works as follows:

Q: Can you support SSL for i2p.to?

A: Technically speaking, this is impossible on IPv4 as long as TLS1.1 must be supported. But there is help:

However it is a little bit different than accessing EEPSITEs directly via HTTPS. Please note:

Frankly speaking, you do not gain much profit from using HTTPS, except that somebody at your side must be a little bit more powerful to read your traffic. (Note that powerful adversaries like your employer can manipulate your browser such that they can decode all your HTTPS traffic.)

Some note about Firesheep: Firesheep steals Cookies from WLAN connections and similar. I do not consider this a problem with I2P. It is very dangerous to use credentials over a proxy like mine if you cannot ultimately trust the person who operates the proxy. There is not a big difference in trusting me or the WLAN you are using. A third party could be able to gain access to the data you send. Again to stess it: This proxy is not thought to be used to access sensible data. If you need more trust or security, install I2P.

Q: Can the inProxy provide access to xmpp(jabber) or other services?

A: Sorry, no. The destination must talk the HTTP protocol. Please note that this question is very close to the SSL question.

Does anybody know about a good image for a Linux appliance which comes with I2P in it?

Q: Why can .b32.i2p addresses not be accessed through your proxy?

A: Because this feature is new and I did not came around to implement it properly.

Why this is the proper way to do it:

On the long term this means:

Also note, that this method can get rid of the need for addresshelper. All you need is some lookup service, which translates a name to the hash destination. Generally speaking: .b32.i2p destinations are good, but for some sad reason, I cannot support them now.

Q: Why are logins not supported / Why are cookies not working correctly?

A: Session Cookies which are non-permanent do work for this proxy, so perhaps certain login features work as expected. But logins and permanent cookie support is missing from this inproxy, and this might lead to errors.

Q: I found illegal content on your pages.

A: If you found an eepsite with illegal content (see verboten content below) please leave me a message on my pager (see above).
State the eepsite name (URL) and a short remark why you think the content must be blocked.

Notes:

Q: I found something with copyright infringement on your pages.

A: Please report it using my pager, see above.

Please note:

Some additional words: As a software programmer I hate people violating copyright. Being in an anonymous network does not give anybody the right to ignore the rules. So if you are pirated, you have my sympathy, read: I will block it unconditionally, of course. Promised.

Q: I found something awful / intimidating / fraudulent content on your pages.

A: Again, these are not "my pages", these are eepsite. If you think, the content on the eepsite breaks the law, either in Germany or in your country (like insults, terrorism, etc.), then please report it to me using my pager, see above. Please state (in short!) why you think this content must be blocked.

Q: I found unprotected content which is not suitable to children on your pages. (Content which is not unlawful in other respects.)

A: I repeat, these are not "my pages". If the content of an eepsite is bad for children and there is no protection to that content, such that childs can unknowingly and unexpedtedly stumble upon this content, and it looks like the eepsite owner is willing to accept that children are harmed by the content, then I will place a block. This is not to obey some law, this is to protect innocent children. However, please read on.

Please do not understand me wrong:

BTW: I have a minor son. And therefor I know it is my task to protect him from Internet odds. Because I do this I know the law is corrupt, as it does more harm than it can help me to do so. In fact, the law makes things worse, as I have less time to educate my son properly because of I have to follow such very stupid laws, like enforcing things which cannot be enforced, or explaining things (like this here) which really do not need to be explained in any free and reasonable society. (However it must be explained, because there is more than a tendency for our civilization to become self-righteous, over-protective and mentally unfree.)

So if I block adult content, I think of my son. I consider, whether there is the possibility that he is harmed by this content. And if I can answer his question when he ever ever asks me why I assisted in taking away the freedeom from the Internet by placing blocks in this inProxy. Please keep this in mind when asking me to block content, you think is not suitable for children.

Q: How is child porn (CP) treated in Germany?

Please note that IANAL, so what you read here is my personal interpretation:

Q: Which content is verboten in Germany?

I really do not know everything, as according to the FUD from Microsoft, anything not approved by Bill Gates shall be illegal. Well, it's not all that bad in Germany, so here is, what I know of which is strictly illegal:

Q: Why do you block? Why don't you enable my eepsite?

A: Here are some clarifications about blocking and stuff.

Notes and clarifications:

Q: Why do you censor? What does "XXX destination(s) not shown/censored" mean?

A: Well, yes, I call it censoring, because basically it is similar to that. I like to use clear words which express the real thing. However I dislike to do things in the dark, that is why this inProxy tells you the fact something is hidden from public.

Please understand, that there are things I do not want to promote. This is a purely personal thing for now.

Notes:

Q: Why do you block me when I use a download accelerator? Why am I blocked?

A: I do not block you. The default settings of most download accelerators are a braindead. By using them you are unfriendly because you are stealing more bandwidth which belong to others. This braindead technology perhaps can help to download braindead content provided by braindead people, but when it comes to I2P these "accelerators" become extremely harmful.

My system here has limited capacity. It can survive 1 or 2 such braindead accelerators, but if 5 people start to use them with the default settings (or what they think are "improved" settings) this is like a DDoS-Attack seen here, as this accelerators then eat up all possible connections and there is nothing left for others.

Therefor my system blocks you if your resource consumption becomes too high. In stress situations the default setting of many browsers (more than 2 parallel connects) might trigger this blocking already. (In extreme stress situations, my machine will already block you after your first request.)

This blocking is a fully automatic defense system to allow others to be not harmed by those which access the web with braindead settings. If you use a download accelerator and you do not configure it to friendly settings (this is: No more than 1 request in parallel, retry wait period of 1 minute) to back off from heavily loaded systems, this will certainly block you very quickly.

This blocking now is sustained as long as the wrong behavior is seen. It even might "burn" your IP, currently there is no limit (which can be considered a bug), so IPs might get blocked for years. (Before if was a little bit random, now the blocking is fixed to be more predictable.)

You can see how long you are blocked if you try to access I2P over this proxy. DO NOT RELOAD THE PAGE, to stay informed, AS THIS MIGHT RAISE YOUR COUNT. Stay calm and wait the given time. And wait 15 minutes more or so. Note that it depends on your IP stack and your ISP how long my system sees you. If your ISP has a transparent proxy this might improve your situation or even hinder you, it depends.

Note that you are not treated differently from others like robots or crawlers. However crawlers usually are very well designed, only do 1 request in seconds and have a well behaving IP stack. This is honored by my system here because it then is unlikely that these are blocked.

Windows IP stacks are known to be extremely "dirty", so they often leave half open connections to other systems. This is penalized here, as this can quickly raise your blocking count to hours. I cannot help for this, except that it is your fault to use such unfriendly systems to surf the web. So there is nothing wrong at my side here. If you are blocked, there is something at your side.

Q: Why are you blocking freenet URLs?

A: Because I dislike to wake up with a S.W.A.T.'s gun in my nose and afterwards being thrown into jail for the rest of my life. For more information, see Which content is verboten in Germany?.

So best is to block it in advance. Just to be sure.
Q: Why are you blocking some I2P BitTorrent trackers?

A: This is a big misunderstanding. This proxy here is to promote I2P contents, and not to help with data distribution. Non I2P-based BitTorrent clients are too numerous and impose too much load to this system here, such that this eats up more than the available capacity on this machine.

The currently available solution to keep this system here alive is to block all BitTorrent tracker traffic if there is a problem with it. This usually happens when the machine gets overloaded and my monitoring tells me about the fact that the machine is on fire. As I cannot ban URLs here, only destinations, this means that I have to block the complete destination.

This will be done until I have a better way to do it. Please note, if you are interested in BitTorrent and I2P, try installing I2P and start to use I2Psnark.

Q: Why are you blocking my hightraffic site ****.i2p

A: The resources on this machine are somewhat limited. Some destinations in I2P just consume too much connections in parallel. Sometimes these destinations have so many clients, that my automated blocking does not help.

In this case I will block the destination until I have a better solution. I am working on a way to even support destinations with a lot of connections, however I currently have no working solution to this.

If you see your site blocked, try my pager. I will try my best to reenable your site, but this will take 48hrs to complete. However we must find another solution for this, as I cannot provide continuous service for such sites.

Q: What is the first line of defense?

Q: What is the second line of defense?

Q: What is the third line of defense?

Q: Can I talk to you more directly?

A: The fastest way is to call my mobile if you have the number.

Note that my native language is German. (As an european I am allowed to use English to explain things, too.)

Q: I've deleted my eepsite. Please stop listing the name at inproxy.tino.i2p.

A: Sorry, I thank you for your wish to cooperate with others and would like to do so, but I cannot do that. Simply because there is no way to do it properly today.

And BTW when the I2P hosts.txt distribution methods start to fail, I could implement my own:
The probing code could try to access http://eepsite.i2p/hosts.txt and stuff all found hosts.txt keys into http://tino.i2p/hosts.txt
However there are others today who exactly do this, which is important, as I don't want my inProxy to play an important role in I2P, just in case it must vanish.
Q: I've re-created my old eepsite under a new destination. Please update inproxy.tino.i2p so that it has the new destination.

A: Sorry, it's not my task to do so. There seems to be some misunderstanding how name resolving in I2P and my inProxy works:

Note that I posted a request to zzz.i2p/zzz.i2p.to to be able to automate such updates using revocations. If - what I doubt - the I2P developers would change your destinations in their hosts.txt file and in i2phost.i2p, I might consider to delete the old destination from my hosts.txt file and let my routers re-learn the new one.
But I will not start to spread updated and unverified destinations myself. Sorry, this is not my role in the I2P project.

Q: Where can I find a full latest hosts.txt?

My hosts.txt is at http://tino.i2p/hosts.txt (I2P) or http://tino.i2p.to/hosts.txt (Internet). However there is no guarantee that my list is complete nor is there any guarantee that it is current.

It's not that easy. There might be a lot of different hosts.txt files out there in the I2P network. And some entries in one hosts.txt might even point to different eepsites than my hosts.txt. In I2P there is no single central source of truth, it is an anonymity network where you can share your opinion with other people. So all you see in my inProxy is just my opinion (or even more my router's opinion) of the I2P network.
You can share it, or not. If in doubt, throw a dice.

Q: Why do you do this here?

A: Because I can. If those wouldn't do it, who can do it, who else would do it?

Q: What does this textbox on the top right ("deadloop" etc.) tell me?

A: The proxy polls all Eepsites and connected parts and shows the status there.

If the hourly-probing takes longer than 1 hour multiple entries can show up.
The numbers in the "run" column are seconds. Positive means "state change N seconds ago". Negative means "next run in -N seconds".
Colors are OK=green, WARN=yellow, ERR=red. If a count has a WARN label, this is a notifier for me that somethings wants manual fixes ;)

Q: Did you ever consider Opt-In?

A: Yes, but I rejected it for several reasons.

Q: Did you ever consider automated Opt-Out?

A: Yes, and I am working on this issue.

My plans are as follows:

Please also note, that there will be the time coming where we have to coordinate all efforts. It is futile to fight the same battle each time at different places. So the blocking process must be some open process accessible and easy to implement by others, such that you (the copyright owner, etc.) do not have to fight this battle all over and again and again.
Really, I do not know where this leads, but there certainly is the need for a solution on a global basis, not only for I2P. But if it works for an anonymous, free and uncensored network like I2P, it can work everywhere. (This probably means, blocking is not enforced, but suggested to all people, who want to be honest, nice and friendly. I really think, this is the majority. If I am wrong we do not need this all here anyway.)

Q: Why are your pages are so square? Why do your pages look so bad?

A: Well, I am not a web designer, I am only a full-heart techie.

Please note that this only applies to i2p.to and not to the eepsites. Eepsites are not contrlled by me and may have any look.

Also if you think you can create a better design, send me the CSS please. If you need certain CSS hooks, tell me, please, so I can add these to the pages. I then will provide a way to switch the CSS, and I will place your name on my inProxy if you like.

Please note that I will not keep contributed CSS current. But I will allow to add your own CSS (like in csszengarden.com).

Q: Are you real?

A: Yes, or to be more elaborate:

Q: You have balls!

A: Not quite:

Q: Can I trust you?

A: The safe bet is "no":

The wise bet still is "no":

Please keep this all in mind when you access my freenet gateway fproxy.tino.i2p. However as you can only do this from within I2P this probably is not a big problem.

Q: Are you affiliated to I2P?

A: Not really.

For the inProxy case the best thing would be if somebody else starts to create an alternative to my inProxy. Or to found a group who operates it. The solution here is able to scale, in that, it is easy to add other relays to it in a round robin fashion. I will happily dedicate the domain i2p.to into such a project, as well as the complete code base of this inProxy. However this group, in contrasts to the I2P team, must stay fully publicly.


[jump to content] [hacker culture] Valid HTML 4.01 Transitional Valid HTML 4.01 Transitional (Bitte dem Link zum Impressum folgen. Diesem ist eine Erklärung vorgeschaltet, damit man besser versteht, worum es sich bei diesem Proxy handelt.)
[ms] (user+sys)/run (30+0)/723 -- According to German law, I must give a link to an Imprint in German language.
$Date: 2011-05-22 14:11:11 $ Valentin Hilbig