From 9afeacac3b8742c75e36a8b68a9f93ac8c292c07 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Thu, 22 Dec 2005 19:29:31 +0000 Subject: [PATCH] Note that you should not download by ID fingerprint. svn:r5634 --- doc/dir-spec.txt | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/doc/dir-spec.txt b/doc/dir-spec.txt index aaecac08b2..65b2ddb878 100644 --- a/doc/dir-spec.txt +++ b/doc/dir-spec.txt @@ -305,10 +305,15 @@ $Id$ fingerprint of should be available at: http:///tor/server/fp/.z - The most recent descriptors for servers with fingerprints ,, - should be available at: + The most recent descriptors for servers with identity fingerprints + ,, should be available at: http:///tor/server/fp/++.z + (NOTE: Implementations SHOULD NOT download descriptors by identity key + fingerprint. This allows a corrupted server (in collusion with a cache) to + provide a unique descriptor to a client, and thereby partition that client + from the rest of the network.) + The descriptor for a server whose digest (in hex) is should be available at: http:///tor/server/d/.z