[tor-bugs] #28496 [Circumvention/BridgeDB]: Consider dropping yahoo from the bridgedb email domains

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri May 31 17:19:33 UTC 2019


#28496: Consider dropping yahoo from the bridgedb email domains
------------------------------------------+---------------------------
 Reporter:  arma                          |          Owner:  dgoulet
     Type:  enhancement                   |         Status:  assigned
 Priority:  Medium                        |      Milestone:
Component:  Circumvention/BridgeDB        |        Version:
 Severity:  Normal                        |     Resolution:
 Keywords:  anti-censorship-roadmap-2019  |  Actual Points:
Parent ID:                                |         Points:  1
 Reviewer:                                |        Sponsor:  Sponsor19
------------------------------------------+---------------------------

Comment (by phw):

 I learned from a researcher that Yahoo lets you create up to 500
 disposable email addresses, which are intended for third-party
 newsletters:

 [[Image(yahoo.png)]]

 BridgeDB interprets these disposable addresses as unique users, which
 makes it easy for an attacker to get a disproportionately large number of
 bridges. We could teach BridgeDB to recognise disposable Yahoo addresses
 but at this point the better way forward may be to just disable Yahoo
 altogether.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/28496#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list