Family-ID for bridges
Hiho, I'm unsure whether I should apply a "Family key" to my bridges. - tor-spec says: we get bridge families "for free" https://spec.torproject.org/proposals/321-happy-families.html#a-note-on-brid... - hiro says Serge & rdsys is not ready yet: https://forum.torproject.org/t/tor-relays-does-c-tor-support-happy-family-on... I don't mind. I would like to change the bridges from ciissversion:2 'proof:dns-rsa' to ciissversion:3 'proof:dns-familyid-ed25519'. Because I don't know how much longer nusenu will continue to support 'proof:dns-rsa' on OrNetStats. - mikeperry suggests against that we have family sets that includes both the bridges and (at least) exit: https://gitlab.torproject.org/tpo/core/tor/-/work_items/40935#note_3351211 Mmmh, should I publish one family key for bridges and another for relays? I assume _Hidden_ Bridges won't get one. ;-) -- ╰_╯ Ciao Marco! Debian GNU/Linux It's free software and it gives you freedom!
On Sat, Sep 12, 2026 at 07:27:36PM +0200, boldsuck via tor-relays wrote:
I'm unsure whether I should apply a "Family key" to my bridges.
- tor-spec says: we get bridge families "for free" https://spec.torproject.org/proposals/321-happy-families.html#a-note-on-brid...
- hiro says Serge & rdsys is not ready yet: https://forum.torproject.org/t/tor-relays-does-c-tor-support-happy-family-on... I don't mind. I would like to change the bridges from ciissversion:2 'proof:dns-rsa' to ciissversion:3 'proof:dns-familyid-ed25519'. Because I don't know how much longer nusenu will continue to support 'proof:dns-rsa' on OrNetStats.
Hi! I haven't coordinated with other people, so don't take this as an 'official' answer, but my two cents: * When clients use public Tor relays, the clients don't fetch the full relay descriptors, so they can't see and verify the family-cert lines from those relays, and that's why the directory authorities need to do the verification and vouching. But for bridges, clients do fetch the full bridge descriptor, so they can see the family-cert line themselves. * So (as I understand it) there weren't and won't be any changes needed on Serge. * But I don't know if anybody actually programmed the part where clients read the family-cert themselves and take it into account along with the family-ids lines they see in relay microdescriptors. I suspect they didn't, because of the design concern that Mike raised. * You could test this yourself, in practice, by configuring your client to use a bridge that sets its family-cert, and watching your logs to see whether your client notices it. * I don't see any downside to adding your family-cert to your bridge. Clients may or may not know how to honor it yet, but that's their problem, not your problem. * If C-Tor clients turn out to not have that feature yet (i.e. to not know how to incorporate bridge family certs), it's reasonable to expect that it will be a long while if ever before they get that support, since we're focusing lately on LLM-derived security reports. But if Arti doesn't have the feature yet, that sounds to me like a legitimate feature request that the Arti people might be interested in. --Roger
Hello! On 12/09/2026 19.27, boldsuck via tor-relays wrote:
I'm unsure whether I should apply a "Family key" to my bridges.
I just spoke with Mike about this topic. For now, our advice is for operators to split their families into two: one family for their bridges and one family for their non-bridge relays (guard, middle, and exit nodes). We plan to relax the restrictions we currently apply to our path selection algorithms. This topic is described in proposal #354[1], and we are actively seeking funding to fix it in Arti and our bridge distribution services. Cheers, Alex [1]: https://spec.torproject.org/proposals/354-relaxed-restrictions.html -- Alexander Hansen Færøy
participants (3)
-
Alexander Hansen Færøy -
boldsuck -
Roger Dingledine