[tor-bugs] #9854 [Tor]: Removing or not sanitizing ContactInfo lines in bridge descriptors
Tor Bug Tracker & Wiki
blackhole at torproject.org
Mon Sep 30 16:48:28 UTC 2013
#9854: Removing or not sanitizing ContactInfo lines in bridge descriptors
-------------------------+------------------------------
Reporter: karsten | Owner:
Type: defect | Status: new
Priority: normal | Milestone: Tor: unspecified
Component: Tor | Version:
Resolution: | Keywords: tor-bridge
Actual Points: | Parent ID:
Points: |
-------------------------+------------------------------
Comment (by sysrqb):
Replying to [comment:2 wfn]:
> I don't know what other bridge operators put in the ContactInfo; perhaps
someone with access to non-sanitized descriptors could try and browse
through a representative sample, to see if anyone is including any
critical info
Over 90% contain email addresses. A few only contain handles, a small
fraction contain openpgp short ids or fingerprints, some actually contain
an entire public key. Some contain a URL. (These properties are not
necessarily disjoint, e.g. some have email address and pgp short id).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9854#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list