Fabio (naif) Pietrosanti

Results 148 comments of Fabio (naif) Pietrosanti

Tor2web does not have a data directory now (no db) except for logs it could generate, if enabled. For that reasons, and also to replicate the same approach of Tor...

I think that "templates" can be assimilated to "configuration" and not to "data", because they do not get changed by the software but are one-off configuration by the admin (if...

Addition: The main goal of tor2web is to expose Tor Hidden Services to the internet, but not to replace their functionalities completely. So it maybe reasonable to limit functionalities that...

Yeah, from technical point of view it would be something like a matter of handling withe filename extensions, http headers such as Content-Type and Content-Length

@evilaliv3 reported that should not be possible to detect file size on Chunked-Transfer encoding.

In the mailing list the discussion goes in the direction that: - bittorrent and magnet should not be blocked - .exe are dangerous and could be blocked - java applet...

Regarding the .exe a possible tradeoff would be to provide a warning to be accepted by the end-user (with Javascript interaction). That way legitimate download files still will work but...

That probably require to integrate meejah's txtorcon to get back the messages based on Tor Control Port. In case you integrate it for the purpose of this ticket, please consider...

Properly fine tuning of ciphers is something that would require some a) logging all SSL negotiation to understand what went wrong/when b) restrict it to only few PFS ciphers c)...

A quick 'n' dirty workaround is to uninstall python-zone.interface, tor2web and then re-install tor2web: apt-get remove python-zope.interface tor2web apt-get install tor2web