Thu Sep 1 21:38:26 UTC 2011

#3892: Controlport behavior changed in - CookieAuthentication now
required to access control port
 Reporter:  cypherpunks  |          Owner:                    
     Type:  defect       |         Status:  new               
 Priority:  normal       |      Milestone:  Tor: 0.2.2.x-final
Component:  Tor Client   |        Version:  Tor:     
 Keywords:               |         Parent:                    
   Points:               |   Actualpoints:                    

Comment(by cypherpunks):

 Also relevant

 From the tor wiki stable and dev manuals on torrc options


 CookieAuthentication 0|1

     If this option is set to 1, don’t allow any connections on the control
 port except when the connecting process knows the contents of a file named
 "control_auth_cookie", which Tor will create in its data directory. This
 authentication method should only be used on systems with good filesystem
 security. (Default: 0)

