freedomofpress / securedrop-docs

Documentation for the SecureDrop project
https://docs.securedrop.org/
Other
22 stars 26 forks source link

document Tor proof-of-work defense #568

Closed cfm closed 2 months ago

cfm commented 2 months ago

Describe the change

What documentation should we offer for the Tor proof-of-work defense implemented in freedomofpress/securedrop#7175?

How will this impact SecureDrop users?

Additional context

cfm commented 2 months ago

@zenmonkeykstop and @nathandyer, let me know what documentation you think will be most useful here, and I'll draft it.

nathandyer commented 2 months ago

My instinct here is that this is the sort of feature that requires minimal documentation, as it doesn't really have many user-facing implications. I don't expect that active monitoring will be something that admins will need to do, and I think even mentioning onionprobe might be a bit far since it requires the extra package install in Tails (and is broken in bookworm/Tails6.x).

I think documenting this as part of the ./securedrop-admin sdconfig workflow is likely sufficient, noting that the option exists, and briefly explaining why an admin may or may not want to enable it (similar to how we handle the SSH-over-Tor option).

cfm commented 2 months ago

Thanks, @nathandyer. This is ready for review in #569.