[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: Family-ID for bridges
- To: "support and questions about running Tor relays (exit, non-exit, bridge)" <tor-relays@xxxxxxxxxxxxxxxxxxxx>
- Subject: [tor-relays] Re: Family-ID for bridges
- From: Roger Dingledine via tor-relays <tor-relays@xxxxxxxxxxxxxxxxxxxx>
- Date: Mon, 14 Sep 2026 17:33:13 -0400
- Cc: Roger Dingledine <arma@xxxxxxxxxxxxxx>
- In-reply-to: <2284937.Mh6RI2rZIc@t520>
- List-id: "support and questions about running Tor relays (exit, non-exit, bridge)" <tor-relays.lists.torproject.org>
- References: <2284937.Mh6RI2rZIc@t520>
- Reply-to: "support and questions about running Tor relays (exit, non-exit, bridge)" <tor-relays@xxxxxxxxxxxxxxxxxxxx>
On Sat, Sep 12, 2026 at 07:27:36PM +0200, boldsuck via tor-relays wrote:
> I'm unsure whether I should apply a "Family key" to my bridges.
>
> - tor-spec says: we get bridge families "for free"
> https://spec.torproject.org/proposals/321-happy-families.html#a-note-on-bridges
>
> - hiro says Serge & rdsys is not ready yet:
> https://forum.torproject.org/t/tor-relays-does-c-tor-support-happy-family-on-bridges/21419
> I don't mind. I would like to change the bridges from ciissversion:2 'proof:dns-rsa'
> to ciissversion:3 'proof:dns-familyid-ed25519'. Because I don't know how
> much longer nusenu will continue to support 'proof:dns-rsa' on OrNetStats.
Hi! I haven't coordinated with other people, so don't take this as an
'official' answer, but my two cents:
* When clients use public Tor relays, the clients don't fetch the full
relay descriptors, so they can't see and verify the family-cert lines
from those relays, and that's why the directory authorities need to do
the verification and vouching. But for bridges, clients do fetch the
full bridge descriptor, so they can see the family-cert line themselves.
* So (as I understand it) there weren't and won't be any changes needed
on Serge.
* But I don't know if anybody actually programmed the part where clients
read the family-cert themselves and take it into account along with
the family-ids lines they see in relay microdescriptors. I suspect they
didn't, because of the design concern that Mike raised.
* You could test this yourself, in practice, by configuring your client
to use a bridge that sets its family-cert, and watching your logs to
see whether your client notices it.
* I don't see any downside to adding your family-cert to your
bridge. Clients may or may not know how to honor it yet, but that's
their problem, not your problem.
* If C-Tor clients turn out to not have that feature yet (i.e. to not
know how to incorporate bridge family certs), it's reasonable to expect
that it will be a long while if ever before they get that support,
since we're focusing lately on LLM-derived security reports. But if
Arti doesn't have the feature yet, that sounds to me like a legitimate
feature request that the Arti people might be interested in.
--Roger
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx