[tor-bugs] #7149 [Tor]: Don't serve or accept hidden service descs over non-tunneled connections

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Fri Oct 19 06:52:12 UTC 2012


#7149: Don't serve or accept hidden service descs over non-tunneled connections
--------------------+-------------------------------------------------------
 Reporter:  nickm   |          Owner:                    
     Type:  defect  |         Status:  new               
 Priority:  normal  |      Milestone:  Tor: 0.2.3.x-final
Component:  Tor     |        Version:                    
 Keywords:  tor-hs  |         Parent:                    
   Points:          |   Actualpoints:                    
--------------------+-------------------------------------------------------
 rransom suggests that we enforce a rule that hidden service material can
 only be served or published over a tunnelled connection.  Though it isn't
 secret per se, it's always incorrect to receive it or send it unencrypted,
 and keeping it sent over Tor may reduce our attack surface slightly.

 Seems worth merging.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7149>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list