Should Onion Location require full v3 addresses?
Currently, Onion-Location
accepts any URL whose hostname ends with .onion
, and only refuses v2 hostnames.
So, any onion alias mechanism (e.g. SecureDrop's) will also work, but this could be used to target users of third-party mechanisms (e.g., namecoin or stuff using prop 279?).
Should we enforce Onion-Location to accept only addresses with full v3 hostnames? (Maybe check the length and that they are in base32, the additional math checks on the key aren't probably worth it, as tor will not connect to invalid hostnames).
Edited by Pier Angelo Vendrame