Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removed member should not be able to know if a member is online #690

Open
holmesworcester opened this issue Jul 5, 2022 · 1 comment
Open
Labels
Projects

Comments

@holmesworcester
Copy link
Contributor

Tor authentication alone will not stop a removed member from knowing if a member is online. To the extent Tor permits (it currently does not seem to--see: https://gitlab.torproject.org/tpo/core/torspec/-/issues/119) we should use Tor to prevent this, so that removed members cannot "stalk" members and learn about their usage patterns.

@holmesworcester holmesworcester created this issue from a note in Quiet (Blocked) Jul 5, 2022
@holmesworcester holmesworcester moved this from Blocked to Backlog - Desktop & Backend in Quiet Jul 5, 2022
@holmesworcester
Copy link
Contributor Author

This might be a reason to use the "waiting room network" approach to removing users, where we have a persistent network for peer discovery and joining, and an ephemeral one for communication that can be destroyed and recreated with new onion addresses when a user is removed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Backlog - Desktop & Backend
Quiet
Backlog - Desktop & Backend
Development

No branches or pull requests

1 participant