Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

distributed trust #112

Closed
adrelanos opened this issue May 29, 2013 · 3 comments
Closed

distributed trust #112

adrelanos opened this issue May 29, 2013 · 3 comments

Comments

@adrelanos
Copy link

From the Tails Time Syncing Design page.

HTP source pools

What sources should be trusted? [...]

The HTP pools used by Tails are based on stable and reliable webservers that get great amounts of traffic. They are categorized into three different pools according to their members relationship to the members in the other pools; any member in a one pool should be unlikely to share logs (or other identifying data), or to agree to send fake time information, with a member from the the other pools. The pools are as follows:

  • The "pal" pool are run by groups that are likely to take great care of their visitors' privacy.
  • The "foe" pool are managed by adversaries of the "pal" pool.
  • The "neutral" pool members have a neutral relationship to both the "pal" and "foe" pool.

The pools are listed in config/chroot local-includes/etc/default/htpdate.

Basically, Tails htpdate pick three random servers (one from each pool), and then build the mediate of the three advertised dates.

Could you please add such a feature to tlsdate as well?

@ioerror
Copy link
Owner

ioerror commented Oct 23, 2013

It's in the TODO list - if you want to submit a patch, I'd be happy to review it and I'll probably merge it.

@adrelanos
Copy link
Author

I don't speak C, don't wait for me.

@ioerror
Copy link
Owner

ioerror commented Oct 31, 2013

This is a TODO item - I don't think it needs an open bug. If someone wants to implement it, I'd be happy to review the patch but it's low on my list of tasks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants