[tor-bugs] #9854 [Tor]: Removing or not sanitizing ContactInfo lines in bridge descriptors

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Sep 30 16:48:28 UTC 2013


#9854: Removing or not sanitizing ContactInfo lines in bridge descriptors
-------------------------+------------------------------
     Reporter:  karsten  |      Owner:
         Type:  defect   |     Status:  new
     Priority:  normal   |  Milestone:  Tor: unspecified
    Component:  Tor      |    Version:
   Resolution:           |   Keywords:  tor-bridge
Actual Points:           |  Parent ID:
       Points:           |
-------------------------+------------------------------

Comment (by sysrqb):

 Replying to [comment:2 wfn]:
 > I don't know what other bridge operators put in the ContactInfo; perhaps
 someone with access to non-sanitized descriptors could try and browse
 through a representative sample, to see if anyone is including any
 critical info

 Over 90% contain email addresses. A few only contain handles, a small
 fraction contain openpgp short ids or fingerprints, some actually contain
 an entire public key. Some contain a URL. (These properties are not
 necessarily disjoint, e.g. some have email address and pgp short id).

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9854#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list