[tor-bugs] #5820 [Vidalia]: Vidalia Relay Bundle installer starts relay on Administrator login

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Thu May 10 04:06:47 UTC 2012


#5820: Vidalia Relay Bundle installer starts relay on Administrator login
----------------------+-----------------------------------------------------
 Reporter:  marshray  |          Owner:  chiiph       
     Type:  defect    |         Status:  new          
 Priority:  normal    |      Milestone:               
Component:  Vidalia   |        Version:  Tor: 0.2.2.35
 Keywords:            |         Parent:               
   Points:            |   Actualpoints:               
----------------------+-----------------------------------------------------
 (Same installation as bug #5803)
 Downloaded Vidalia Relay Bundle from
 https://www.torproject.org/download/download.html.en
 vidalia-relay-bundle-0.2.2.35-0.2.17.exe
 sha1sum 6157dfb5fa8690e3451beefcb003bc4999dd8508

 MS Win 7 64 bit
 Ran installer as normal user but allowed elevation to Admin user when
 requested.
 Accepted default installation path.
 Did not opt to run directly after installing.

 When I log in as the Administrator account Vidalia starts immediately and
 begins relaying traffic before I can stop it. This is bad.

 When I log in as the normal user account the relay is not started. I can
 start it manually. This is not bad.

 There is no entry in the 'Start menu' 'Startup' folder. It seems likely
 that the installer (which had been elevated to Admin) is adding an entry
 to the HKCU current user registry key which launches new apps at login.

 Ideally the installer could be run as non-Admin. Few if any app installers
 ever pull this off.

 The installer could also offer to create a service. This would require
 local Admin, but AFAICT there's no reason Tor.exe should need to run with
 Admin privileges.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5820>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list