Skip to content

Big file, Torrent, Executable download policy proposal for Tor2web #67

Open
@fpietrosanti

Description

@fpietrosanti

Premise:

  • Tor is not considered useful for file sharing as it hurt tor network
  • Sometime t2w node administrator receive DMCA Takedown notice due to copyright
  • Transfer of big files, seriously harm the Tor2web networks of proxy performance
  • Having bittorrent tracker exposed may bring to some additional liability
  • Having some malware (.exe trojan) hosted on Tor2web exposed websites
  • Having Java Applet / ActiveX exploits

For the reason explained above i'd suggest to consider that Tor2web by default will have a policy so that it kindly ask Tor Hidden Service operator not to use tor2web to transfer big files, use Tor2web for any hacking, or use tor2web to host bittorrent trackers.

Tor2web will then handle a feature in a kind way, so that when the user is going to download a file bigger than X (where X maybe bigger than 10MB?), it will be redirected to a web page (landing page).

That landing page invite the user to download Tor Browser Bundle (for his platform), proposing him (for usability):

  • the URL to be copy&pasted to access the file he was trying to download (under .onion url)
  • the URL to be copied & pasted to access the referral webpage (under .onion url)

The very same behavior should apply to executable files *.exe, ActiveX, Java Applet and certain file types.

That way Tor2web can mitigate/discourage the use of Tor2web for file sharing purposes, downloading executable or bittorrent, without blocking the action itself, but again inviting the user to download the file directly over Tor.

The very same policy should be applied to Bittorrent trackers, that should provide the very same behavior, to bring the end-user to accessing directly and anonymously the tracker he is trying to download.

This set of action enforce the message that Tor2web should always try to drive the end-user into installing Tor and accessing content directly.

Such a feature should be enabled by default, by the tor2web node maintainer should be allowed to disable it.

By using such an approach we can foster a wider adoption of Tor Hidden Services, but in the proper way, by using directly Tor Browser Bundle, by reducing liabilities and performance hit of Tor2web network.

Cc @vecna @hellais @evilaliv3


Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions