[ ijbswa-Feature Requests-3541363 ] support IsolateSOCKSAuth (preventing identity correlation)
SourceForge.net <[email protected]>
| Newsgroups | gmane.comp.web.privoxy.devel |
|---|---|
| Message-ID | <[email protected]> |
Feature Requests item #3541363, was opened at 2012-07-08 05:39 Message generated for change (Tracker Item Submitted) made by sharepass11 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=361118&aid=3541363&group_id=11118 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: None Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: james mitch (sharepass11) Assigned to: Nobody/Anonymous (nobody) Summary: support IsolateSOCKSAuth (preventing identity correlation) Initial Comment: How to force redirect each application through separate Tor circuit, thus preventing identity correlation through circuit sharing? Many applications, such as wget, apt-get, gpg, etc. do not speak socks, are unlikely to speak socks anytime soon, but support http. torsocks is of no big help either. I think it has been designed, when identity correlation wasn't a big topic. By default torsocks uses /etc/torsocks.conf and also presses all applications started with usewithtor <app> into the same SocksPort (identity correlation again [1]). To me it also looks like torsocks is practically unmaintained, there is a critical bug open, IPv6 can leak real IP, no progress for a very long time. [2] In an ideal world, Tor wouldn't only offer multiple SocksPorts, but also multiple HttpPorts. That's for some reasons, either not going to happen anytime soon. [3] Previous discussion: https://lists.torproject.org/pipermail/tor-talk/2012-June/024497.html Now I try to come up with a better suggestion. IsolateSOCKSAuth ( https://www.torproject.org/docs/tor-manual-dev.html.en ) will be soon available when Tor 0.2.3 gets released (soon, already available in the Tor stable deb repository). How I wish it to work: - user adds multiple http or socks ports to privoxy.conf - if the parent proxy is a socks5 proxy (Tor) - and if an option with a name like "IsolateSOCKSAuth" gets activated in privoxy.conf - then use username:password@parent_proxy_ip:parent_proxy_port (Username and password can be anything and doesn't matter. Simplest thing would be to use for example if http proxy port = 8119, socks_username = $http_proxy_port, socks_password = $http_proxy_port.) Subsequently different http or socks listen ports were redirected to the same parent proxy ip/port, but using different socks auth and socks password, therefore streams would get isolated by Tor. [1] https://trac.torproject.org/projects/tor/ticket/6102 [2] https://code.google.com/p/torsocks/issues/detail?id=37 [3] https://trac.torproject.org/projects/tor/ticket/6060 ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=361118&aid=3541363&group_id=11118 ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/