4 ms·
Couldn't CloudFlare track a Tor user by tracking the tokens it gave to a particular user, then track them when their client used one of those tokens to validate
by slester 10y ago
Couldn't CloudFlare track a Tor user by tracking the tokens it gave to a particular user, then track them when their client used one of those tokens to validate?
- Ar-Curunir 10y agoI think that's what the "blind" portion of token authentication is for.
- mirimir 10y agoHow would users know that tokens had actually been signed blindly?
- yorwba 10y agoIf the tokens are never sent, only their blinded versions, it is pretty much guaranteed that the signature you get back was made without looking at the actual token.
- mirimir 10y agoI get that. What I wonder is who would nontechnical users need to trust about that? CloudFlare? The Tor Project?
- Ar-Curunir 10y agoI'm not sure, but it can be done with just CloudFlare changes; if the plugin is open source it should be fine. Maybe if Tor Browser integrates the plugin it should be fine too.
- mirimir 10y agoOptimal would be only needing to trust the Tor Project.