Skip to content

Allow bridge/relay mode without bundled hidden-service hosting #30

Description

@alru78

Prerequisites

  • I searched this repository's existing issues and this is not already requested.
  • This is about the StartOS package — what it exposes, configures, or automates. A feature of the software itself belongs with the upstream project, not here.

What kind of change?

Expose a config option

Problem & use case

Running the Tor package purely as a bridge/relay (no interest in hosting any app behind a .onion address on this instance), but enabling relay/bridge mode produces this warning in the logs:

[warn] Tor is currently configured as a relay and a hidden service. That's not very secure: you should probably run your hidden service in a separate Tor process, at least -- see https://bugs.torproject.org/tpo/core/tor/8742.

This appears to be because the package always runs onion-service hosting (for its SOCKS5 proxy / other integration purposes) in the same Tor process as the optional relay/bridge feature, per the current README. Tor's own upstream guidance (linked in the warning) is that relay and hidden-service roles shouldn't share a process, since an adversary observing the relay's traffic patterns could potentially help correlate/deanonymize the hidden service running alongside it in the same daemon.

Proposed solution

Request: a way to run this package in a bridge/relay-only configuration with no hidden service active at all — either a toggle to disable onion-service hosting independently of the relay/bridge setting, or a separate bridge-only variant/mode of the package that never sets HiddenServiceDir.

Alternatives considered

No response

Anything else?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions