diff --git a/README.md b/README.md index 5d297af..b2379b2 100644 --- a/README.md +++ b/README.md @@ -1,10 +1,8 @@ -tor-control-port-proxy -====================== +# tor-control-port-proxy A whitelisting proxy for the Tor control port. -Rationale ---------- +## Rationale The Tor Browser, when not used in "Transparent Torification" mode, requires access to the Tor control port so that it can test that the browser is configured to use Tor correctly and send a NEWNYM signal when the "New @@ -20,23 +18,26 @@ she controls or get the IP address of the machine running Tor by using the Inspired by a [similar project written as part of Whonix](https://www.whonix.org/wiki/Dev/Control_Port_Filter_Proxy), I wrote a simple proxy that only allows commands necessary for operation of the Tor -Browser and rejects all others. It's still in a fairly early state, but it -should work without issue. +Browser and rejects all others. -Prerequisites -------------- +Note that this simple proxy does not enforce authentication; I do not believe +there are anonymity concerns with this, but this does present an increased +attack risk if someone compromises a user account on your machine. In the +future, I may add support for a separate auth cookie for the proxy itself, so +that authentication can be used without exposing the main Tor auth cookie to +your Torified VMs. + +## Prerequisites * Python 3+ -* [stem](https://stem.torproject.org/) -Usage ------ +## Usage 1. Install the proxy. Arch users can use the included PKGBUILD; other users should copy tor-control-port-proxy to /usr/bin, and tor-control-port-proxy.service to /etc/systemd/system. (If you're not using systemd, you'll need to write your own initscript.) -2. Configure Tor: set `ControlPort 9051` and `CookieAuthentication 1`. Then - restart Tor. +2. Configure Tor: set `ControlSocket /run/tor/control` and + `CookieAuthentication 1`. Then restart Tor. 3. Start the proxy: `sudo systemctl start tor-control-port-proxy.service`.