Re: [tor-dev] Proposal xxx: Safe cookie authentication

2012-02-06 Thread Damian Johnson
> See branch safecookie of > https://gitweb.torproject.org/rransom/torspec.git for a revised ‘safe > cookie authentication’ protocol The spec still doesn't look reader friendly but guess we won't be expecting too many clients to implement this. One other note is that keywords like 'must' should be

Re: [tor-dev] Proposal xxx: Safe cookie authentication

2012-02-06 Thread Robert Ransom
See branch safecookie of https://gitweb.torproject.org/rransom/torspec.git for a revised ‘safe cookie authentication’ protocol (in spec-patch form); see branch safecookie-023 of https://gitweb.torproject.org/rransom/tor.git for a completely untested implementation on Tor 0.2.3.x. This needs testin