HelloZeroNet / HelloZeroNet/ZeroNet
Use Stealth or Basic Authentication
- 主要言語
- JavaScript
- スター
- 18.8k
- フォーク
- 2.3k
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
This is a proposal.
ZeroNet has an "onion pooling" feature, creating "fake" identities to resist some basic fingerprinting attacks. There is a safer way to do this -- Stealth or Basic Authentication.
https://lists.torproject.org/pipermail/tor-talk/2017-November/043797.html
Use _basic_ authentication, so that you don't need to generate additional RSA keys. For basic authentication, the acceptable passwords can be the addresses of the sites which the onion service claims to be hosting.
> \>\>\> Hosting?
> I host `addr_1`, `addr_2` and `addr_3`.
> \>\>\> Give me some `addr_4` stuff!
> Authentication failed. Access denied.
There is certainly "implementation overhead." I recommend you use the `stem` control library. Fun fact: [it does not need any dependency](https://stem.torproject.org/faq.html#does-stem-have-any-dependencies) if you don't use its fanciest features.
API for creating these authenticated onion services: [`stem.control.Controller.create_ephemeral_hidden_service`](https://stem.torproject.org/api/control.html#stem.control.Controller.create_ephemeral_hidden_service)
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
Start by reviewing ZeroNet's existing onion pooling implementation and the Stem Controller.create_ephemeral_hidden_service API linked in the proposal. Define how authenticated onion services would fit the current architecture, including how hosted addresses become acceptable passwords. Done should include an agreed design, implementation, and verification that unauthorized address requests are denied.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- python
- 領域
- authentication, networking, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 20/100