[tor-bugs] #13154 [Tor]: Debian's "popularity contest" package as threat vector?

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Nov 14 10:44:16 UTC 2014


#13154: Debian's "popularity contest" package as threat vector?
-----------------------------+------------------------------------
     Reporter:  saint        |      Owner:  saint
         Type:  enhancement  |     Status:  accepted
     Priority:  normal       |  Milestone:
    Component:  Tor          |    Version:
   Resolution:               |   Keywords:  tor-hs, Debian, Stormy
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+------------------------------------
Changes (by saint):

 * component:  - Select a component => Tor


Old description:

> I am wondering whether to force-uninstall Debian's `popularity-contest`
> package as part of Stormy's installation process.  It would be good to
> have an idea how popular Stormy is, but on the other hand, I'm not sure
> how anonymous the reporting is on Debian's end.
>
>   This is also relevant for users of the `tor` package, who might also be
> at mild risk (though far less so because the number of users is so high,
> and doesn't reveal location of location-hidden services).
>
>   Anyone have opinions on this?  I'm leaning towards checking if
> popularity-contest is installed and then asking if the user would like it
> to be removed.

New description:

 I am wondering whether to force-uninstall Debian's `popularity-contest`
 package as part of Stormy's installation process.  It would be good to
 have an idea how popular Stormy is, but on the other hand, I'm not sure
 how anonymous the reporting is on Debian's end.

   This is also relevant for users of the `tor` package, who might also be
 at mild risk (though far less so because the number of users is so high,
 and doesn't reveal location of location-hidden services).

   Anyone have opinions on this?  I'm leaning towards checking if
 popularity-contest is installed and then asking if the user would like it
 to be removed.

 EDIT: We should also discuss whether to remove it as part of Tor's
 installation process overall.

--

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13154#comment:7>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list