[tor-dev] Proposal 203: Avoiding censorship by impersonating an HTTPS server

Jens Kubieziel maillist at kubieziel.de
Wed Jul 11 21:43:33 UTC 2012


* Nick Mathewson schrieb am 2012-06-26 um 00:23 Uhr:
> Side note: What to put on the webserver?
> 
>    To credibly pretend not to be ourselves, we must pretend to be
>    something else in particular -- and something not easily identifiable
>    or inherently worthless.  We should not, for example, have all

Some ideas:
- some random content with a CC license
  We could have a list or something of CC-licensed content. The
  webserver mirrors either the whole site or some subsites. I'm thinking
  of some Wikipedia sites or books from Project Gutenberg.
- country related content
  We could check the users IP address and try to geolocate it. Based on
  that country information the webserver could deliver some local
  content. But where should we get country-specific content.
- 451
  If someone is in trolling mood, he just can deliver a 451 error. ;)
- Login page/random fresh installation
  We could also present some page which looks like a valid login page or
  a fresh installation (Apache, Mediawiki or something other popular).
  Another similar idea is it to deliver some error page, like a blank
  page with a MySQL-, PHP-, Tomcat or any other error message.

-- 
Jens Kubieziel                                   http://www.kubieziel.de
Die größten Menschen sind jene, die anderen Hoffnung geben können. Jean
Jaurès
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <http://lists.torproject.org/pipermail/tor-dev/attachments/20120711/86108e87/attachment.pgp>


More information about the tor-dev mailing list