[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-dev] Using Tor as a library



"Fabio Pietrosanti (naif)" <lists-BEJ3GKOyH/EwUp2xcto6ig@xxxxxxxxxxxxxxxx> writes:
> That's the future of Tor, to be integrated as a library just like an
> encryption library into application.

No, it's not.  Embedding a Tor client in another application cripples
auditability, configurability, updateability etc. of Tor.  So does
embedding a controller.  Even worse, an application trying to outsmart
the user by controlling Tor on its own poses a severe security risk.

Other than an encryption library, there is no well-defined output to an
input that a Tor library should produce.

Tor is a vivid, organic ecosystem of different, replaceable projects
that integrate into each other.  Embedding a static subset of these in
an application is wrong.

        Christopher
_______________________________________________
tor-dev mailing list
tor-dev@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev