Skip to content

Merge Prop#344 to top-level Tor Spec; Officially update Tor Threat Model

@ahf suggested (and I agree) that we promote Prop#344 to spec top-level.

With the changes in #277 (closed) (MR: !355 (merged)), Prop#344 now categorizes the info leak vectors into three conceptual categories:

  1. Internal Covert Channels
  2. Behavioral Manipulation
  3. Augmented Observation

It now also proposes that these three categories be explicitly added to Tor's threat model. Previously, they were either explicitly excluded, or ambiguous.

This ticket will serve as source of comments + checklist of what we need to do to make this all happen. This description will be updated. I will start Cc'ing the usual suspects after the MR lands.

We may want to make this official at the end of Project 112 (this November, I think?), and probably do a blog post, etc about the threat model update, plus the fixes from P112.

Here's a checklist of updates I will do (will edit):

Edited by Mike Perry
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information