[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #28496 [Circumvention/BridgeDB]: Consider dropping yahoo from the bridgedb email domains



#28496: Consider dropping yahoo from the bridgedb email domains
------------------------------------------+---------------------------
 Reporter:  arma                          |          Owner:  dgoulet
     Type:  enhancement                   |         Status:  assigned
 Priority:  Medium                        |      Milestone:
Component:  Circumvention/BridgeDB        |        Version:
 Severity:  Normal                        |     Resolution:
 Keywords:  anti-censorship-roadmap-2019  |  Actual Points:
Parent ID:                                |         Points:  1
 Reviewer:                                |        Sponsor:  Sponsor19
------------------------------------------+---------------------------

Comment (by phw):

 I learned from a researcher that Yahoo lets you create up to 500
 disposable email addresses, which are intended for third-party
 newsletters:

 [[Image(yahoo.png)]]

 BridgeDB interprets these disposable addresses as unique users, which
 makes it easy for an attacker to get a disproportionately large number of
 bridges. We could teach BridgeDB to recognise disposable Yahoo addresses
 but at this point the better way forward may be to just disable Yahoo
 altogether.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/28496#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs