[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-talk] Awareness for identity correlation through circuit sharing is almost zero.



Thus spake Nick Mathewson (nickm@xxxxxxxxxxxx):

> On Mon, Mar 5, 2012 at 7:20 PM,  <proper@xxxxxxxxxxxxxxx> wrote:
> >> (Note that usernames and/or passwords can be used to separate
> >> streams, too.)
> >
> > Is this documented somewhere?
> 
> If you're asking this question, you *really* want to check out all the
> isolation flags in the documentation for SocksPort in the Tor 0.2.3.x
> manpage.  For a more full discussion of how it was designed, see
> proposal 171.  If there's anything missing in the manpage, please let
> us know.
> 
> Stream isolation is one of the big features in Tor 0.2.3.x, but it's a
> bit hard to figure out how to use it up most effectively.  This is
> something I hope people can help come up with good ideas and
> documentation for.

The plan for TBB is to use the "Request Origin" as the SOCKS password to
isolate web activity by urlbar domain/navigation session. The "Request
Origin" roughly translates to the referer domain.

https://trac.torproject.org/projects/tor/ticket/3455

We'll probably also use "mozilla" or "TBB" as the SOCKS username, to
address Robert's concerns in
https://trac.torproject.org/projects/tor/ticket/3455#comment:1


-- 
Mike Perry

Attachment: signature.asc
Description: Digital signature

_______________________________________________
tor-talk mailing list
tor-talk@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk