Browse Source

Bug 25870: Mention path restriction differences in manpage.

Mike Perry 6 years ago
parent
commit
e716c92127
1 changed files with 16 additions and 0 deletions
  1. 16 0
      doc/tor.1.txt

+ 16 - 0
doc/tor.1.txt

@@ -1573,6 +1573,14 @@ The following options are useful only for clients (that is, if
     ExcludeNodes have higher priority than HSLayer2Nodes,
     ExcludeNodes have higher priority than HSLayer2Nodes,
     which means that nodes specified in ExcludeNodes will not be
     which means that nodes specified in ExcludeNodes will not be
     picked.
     picked.
+ +
+    When either this option or HSLayer3Nodes are set, the /16 subnet
+    and node family restrictions are removed for hidden service
+    circuits. Additionally, we allow the guard node to be present
+    as the Rend, HSDir, and IP node, and as the hop before it. This
+    is done to prevent the adversary from inferring information
+    about our guard, layer2, and layer3 node choices at later points
+    in the path.
  +
  +
     This option is meant to be managed by a Tor controller such as
     This option is meant to be managed by a Tor controller such as
     https://github.com/mikeperry-tor/vanguards that selects and
     https://github.com/mikeperry-tor/vanguards that selects and
@@ -1619,6 +1627,14 @@ The following options are useful only for clients (that is, if
     ExcludeNodes have higher priority than HSLayer3Nodes,
     ExcludeNodes have higher priority than HSLayer3Nodes,
     which means that nodes specified in ExcludeNodes will not be
     which means that nodes specified in ExcludeNodes will not be
     picked.
     picked.
+ +
+    When either this option or HSLayer2Nodes are set, the /16 subnet
+    and node family restrictions are removed for hidden service
+    circuits. Additionally, we allow the guard node to be present
+    as the Rend, HSDir, and IP node, and as the hop before it. This
+    is done to prevent the adversary from inferring information
+    about our guard, layer2, and layer3 node choices at later points
+    in the path.
   +
   +
     This option is meant to be managed by a Tor controller such as
     This option is meant to be managed by a Tor controller such as
     https://github.com/mikeperry-tor/vanguards that selects and
     https://github.com/mikeperry-tor/vanguards that selects and