HelloZeroNet / HelloZeroNet/ZeroNet

[security] Please add --tor_control_method command line option to allow use of control socket

未关闭
#1,083 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
18.8k
派生
2.3k
PR 合并指标
30 天内没有已合并 PR

描述

Currently, ```--tor=always``` implies the use of control port (9051 by default). Tor control port is less secure in that it by default allows empty authentication.

Please implement:
```
self.parser.add_argument('--tor_control_method', help='Tor control method', metavar='tor:control_method', default='control-port')
```
with possible values {control-port|control-socket}

```--tor_controller``` then will be dependent on ```--tor_control_method```. In case of ```--tor_control_method=control-port```, it will be an IP host/port with default='127.0.0.1:9051', and for ```--tor_control_method=control-socket``` it will be a file name with the default corresponding to Tor's default control socket location.

In case of ```--tor_control_method=control-socket```, ZeroNet will use control socket and authentication cookie on disk. It will have to be run with _tor group in order to have access to the authentication cookie.

It is more secure to not require control port, and to use control socket with authentication cookie.

贡献指南

这个仓库没有索引到贡献指南

调研方向

Start at the command-line parser entry point containing self.parser.add_argument and trace the existing --tor_controller handling. Verify the two documented methods, their defaults, and the control-socket authentication-cookie behavior, then confirm that --tor=always uses the selected method.

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
cli, security
Issue 类型
功能
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。