[tbb-bugs] #20212 [Applications/Tor Browser]: Tor can be forced to open too many circuits by embedding .onion resources

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 19 14:55:41 UTC 2018


#20212: Tor can be forced to open too many circuits by embedding .onion resources
-------------------------------------------------+-------------------------
 Reporter:  gacar                                |          Owner:  tbb-
                                                 |  team
     Type:  enhancement                          |         Status:  new
 Priority:  Medium                               |      Milestone:  Tor:
                                                 |  unspecified
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  guard-discovery,                     |  Actual Points:
  TorBrowserTeam201803                           |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by gk):

 * cc: mcs, brade (added)
 * keywords:  guard-discovery => guard-discovery, TorBrowserTeam201803


Comment:

 Replying to [comment:7 gk]:
 > Replying to [comment:6 asn]:
 > > How should we proceed here? Leif suggested we introduce a
 `Max3rdPartyOnions` option ''to limit the number of onion addresses that
 an origin is allowed to cause the browser to make connections to''.
 > >
 > > Do we think this is a reasonable approach? And what should the default
 value be? Can we add this to our TB roadmap in some capacity?
 >
 > You mean this should be fixed on the browser side? It seems to me having
 a patch in tor makes more sense.

 After some more discussion happened, let's try to fix that on the browser
 side (first). mcs/brade: can you look into it?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20212#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list