HelloZeroNet / HelloZeroNet/ZeroNet

[security] Please add --tor_control_method command line option to allow use of control socket

Aperta
#1,083 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
JavaScript
Stelle
18.8k
Fork
2.3k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Currently, ```--tor=always``` implies the use of control port (9051 by default). Tor control port is less secure in that it by default allows empty authentication.

Please implement:
```
self.parser.add_argument('--tor_control_method', help='Tor control method', metavar='tor:control_method', default='control-port')
```
with possible values {control-port|control-socket}

```--tor_controller``` then will be dependent on ```--tor_control_method```. In case of ```--tor_control_method=control-port```, it will be an IP host/port with default='127.0.0.1:9051', and for ```--tor_control_method=control-socket``` it will be a file name with the default corresponding to Tor's default control socket location.

In case of ```--tor_control_method=control-socket```, ZeroNet will use control socket and authentication cookie on disk. It will have to be run with _tor group in order to have access to the authentication cookie.

It is more secure to not require control port, and to use control socket with authentication cookie.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.