Skip to content
This repository was archived by the owner on Feb 20, 2020. It is now read-only.

Change External File Advice Using Tor - #179

Open
tommycollison wants to merge 1 commit into
freedomofpress:masterfrom
tommycollison:Tor_external_file_advice
Open

Change External File Advice Using Tor#179
tommycollison wants to merge 1 commit into
freedomofpress:masterfrom
tommycollison:Tor_external_file_advice

Conversation

@tommycollison

Copy link
Copy Markdown
Contributor

As per Micah's out-of-band comment, changed the advice for opening files using Tor to be more general, and mention pdf.js.

As per Micah's out-of-band comment, changed the advice for opening files using Tor to be more general, and mention pdf.js.
@harlo

harlo commented Aug 25, 2015

Copy link
Copy Markdown

nitpick on "anonymously": isn't more of a sandboxing mechanism?

Comment thread encryption_works.md

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree with @harlo - anonymously isn't the right word to use here. You're more concerned about potential malware (including malware that could de-anonymize you, yes, but really any kind of malware) so I'd say "securely" view PDF's would be a better word choice. Although given recent events, we should probably not tout pdf.js as a secure solution for viewing PDF's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, "securely" is better phrasing, but I agree that PDF.js has had a rough summer. If we don't recommend PDF.js, however, we'll need to remove the recommendation not to use external apps.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should say "be careful" or "think twice" about downloads that require external apps. I'm not sure if it's realistic to say "don't open them", since that's kind of a big part of what the Internet is for. You should only download files like that from sites you trust that use HTTPS (to avoid exit node tampering).

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants