[tor-bugs] #18938 [Core Tor/Tor]: Authorities should reject non-ASCII content in ExtraInfo descriptors

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jul 8 00:33:48 UTC 2016


#18938: Authorities should reject non-ASCII content in ExtraInfo descriptors
----------------------------------+------------------------------------
 Reporter:  teor                  |          Owner:
     Type:  defect                |         Status:  new
 Priority:  Medium                |      Milestone:  Tor: 0.2.9.x-final
Component:  Core Tor/Tor          |        Version:
 Severity:  Normal                |     Resolution:
 Keywords:  needs-proposal-maybe  |  Actual Points:
Parent ID:  #18656                |         Points:  1
 Reviewer:                        |        Sponsor:
----------------------------------+------------------------------------

Comment (by teor):

 So I propose we do the following:
 * 0.2.9: check all documents published by relays
 * 0.3.0 or 0.3.1: a new consensus method where authorities refuse to vote
 for relays with non-ASCII descriptors
 * 0.3.2 (or whenever we use that consensus method): Authorities can reject
 non-ASCII uploads

 I assume "printing ASCII" means "space to tilde, tab, and linefeed" but we
 should also clarify that in the torspec.

 I'm not sure if it's possible to get non-ASCII content in a hidden service
 descriptor without memory corruption. But in any case, hidden services,
 HSDirs, and clients should reject that, too. I've split the HS part off
 into #19647.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18938#comment:15>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list