[tbb-bugs] #14026 [Tor Browser]: torproject.org as a hidden service
Tor Bug Tracker & Wiki
blackhole at torproject.org
Thu Dec 25 19:09:26 UTC 2014
#14026: torproject.org as a hidden service
-------------------------+--------------------------
Reporter: cypherpunks | Owner: tbb-team
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor Browser | Version:
Keywords: | Actual Points:
Parent ID: | Points:
-------------------------+--------------------------
Accessing torproject.org through exit nodes is not good. Replace it with
hidden service for TBB. Of course, HTTPS over TOR (as Facebook have done)
to make use of PKI to verify that it is torproject's site, not John Doe's
site.
To prevent attack with registering .onion address by provider just
hardcode into TB that .onion addresses MUST be downloaded through proxy.
Don't forget about third-party proxy addons, such as FoxyProxy (used in
TAILS), make sure that this wouldn't have broken them.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/14026>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tbb-bugs
mailing list