HelloZeroNet / HelloZeroNet/ZeroNet

[security] Please add --tor_control_method command line option to allow use of control socket

Offen
#1,083 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
JavaScript
Sterne
18.8k
Forks
2.3k
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Currently, ```--tor=always``` implies the use of control port (9051 by default). Tor control port is less secure in that it by default allows empty authentication.

Please implement:
```
self.parser.add_argument('--tor_control_method', help='Tor control method', metavar='tor:control_method', default='control-port')
```
with possible values {control-port|control-socket}

```--tor_controller``` then will be dependent on ```--tor_control_method```. In case of ```--tor_control_method=control-port```, it will be an IP host/port with default='127.0.0.1:9051', and for ```--tor_control_method=control-socket``` it will be a file name with the default corresponding to Tor's default control socket location.

In case of ```--tor_control_method=control-socket```, ZeroNet will use control socket and authentication cookie on disk. It will have to be run with _tor group in order to have access to the authentication cookie.

It is more secure to not require control port, and to use control socket with authentication cookie.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.