HelloZeroNet / HelloZeroNet/Documentation

Insecure instructions for using ZeroNet with Tor Browser

Open
#84 3 comments 0 reactions 0 assignees View on GitHub
help wanted
Dominant language
JavaScript
Stars
79
Forks
118
PR merge metrics
No merged PRs in 30d

Description

[How to use ZeroNet in Tor browser?](https://github.com/HelloZeroNet/Documentation/blob/4e33a16401a63c107d3415c315488c57204b597c/docs/faq.md#how-to-use-zeronet-in-tor-browser) advices telling TB to not send traffic to 127.0.1 through Tor. While this is required for ZeroNet to work, this might also allow malicious sites to fetch content from other ports and allow fingerprinting users.

I am thinking of http://127.0.0.1:631 which is CUPS/printing web interface (often used in Linux, macOS), http://127.0.0.1:8080/ can be anything (IPFS uses it by default, I have Syncthing there, I think µTorrent also uses it for remote UI), transmission-daemon uses 9091 if I recall correctly.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.