[tor-bugs] #18938 [Core Tor/Tor]: Authorities should reject non-ASCII content in ExtraInfo descriptors
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Jul 8 00:33:48 UTC 2016
#18938: Authorities should reject non-ASCII content in ExtraInfo descriptors
----------------------------------+------------------------------------
Reporter: teor | Owner:
Type: defect | Status: new
Priority: Medium | Milestone: Tor: 0.2.9.x-final
Component: Core Tor/Tor | Version:
Severity: Normal | Resolution:
Keywords: needs-proposal-maybe | Actual Points:
Parent ID: #18656 | Points: 1
Reviewer: | Sponsor:
----------------------------------+------------------------------------
Comment (by teor):
So I propose we do the following:
* 0.2.9: check all documents published by relays
* 0.3.0 or 0.3.1: a new consensus method where authorities refuse to vote
for relays with non-ASCII descriptors
* 0.3.2 (or whenever we use that consensus method): Authorities can reject
non-ASCII uploads
I assume "printing ASCII" means "space to tilde, tab, and linefeed" but we
should also clarify that in the torspec.
I'm not sure if it's possible to get non-ASCII content in a hidden service
descriptor without memory corruption. But in any case, hidden services,
HSDirs, and clients should reject that, too. I've split the HS part off
into #19647.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18938#comment:15>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list