[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] #7149 [Tor]: Don't serve or accept hidden service descs over non-tunneled connections



#7149: Don't serve or accept hidden service descs over non-tunneled connections
--------------------+-------------------------------------------------------
 Reporter:  nickm   |          Owner:                    
     Type:  defect  |         Status:  new               
 Priority:  normal  |      Milestone:  Tor: 0.2.3.x-final
Component:  Tor     |        Version:                    
 Keywords:  tor-hs  |         Parent:                    
   Points:          |   Actualpoints:                    
--------------------+-------------------------------------------------------
 rransom suggests that we enforce a rule that hidden service material can
 only be served or published over a tunnelled connection.  Though it isn't
 secret per se, it's always incorrect to receive it or send it unencrypted,
 and keeping it sent over Tor may reduce our attack surface slightly.

 Seems worth merging.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7149>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs