AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

Tor settings

Public commit record

What the developer wrote

Authored by Keeqler

18/100 · Opaque
Tor settings
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
The short version

What changed, and why it matters

This commit adds user-configurable Tor settings to the Skylight Wallet app. Users can now choose between built-in Tor, an external Tor proxy, or disabling Tor entirely. It also updates how the app fetches exchange rates and blockchain heights so they respect the new Tor setting. There is no clear security bug in the patch itself, but it introduces a 'Tor disabled' mode and changes how network traffic is routed, which could affect user privacy if the settings are mishandled or bypassed.

Recommended action

Review the full diff and any follow-up commits to confirm that all network paths in the wallet (daemon sync, LWS, fiat API, fee fetching) consistently honor TorSettingsService. Pay special attention to the FIXME in lib/util/height.dart where getCurrentBlockchainHeight() returns 0 when Tor is disabled. Consider validating the external SOCKS proxy more robustly and warning users clearly when Tor is disabled.

Security signals we found

01

New 'disabled' Tor mode allows wallet traffic to bypass Tor entirely

02

External Tor mode lets users specify an arbitrary SOCKS port, which may be misconfigured or point to a non-Tor proxy

03

Connection test only validates external Tor against check.torproject.org/api/ip, which can give false confidence

04

getCurrentBlockchainHeight() returns 0 with a FIXME comment when Tor is disabled, potentially causing restore-height issues

05

Fiat rate service now stops when Tor is disabled, but other wallet traffic paths need review to confirm they also respect the setting

06

SharedPreferences-backed Tor settings are not integrity-protected or encrypted

Risk score

Why this scored 34/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 5/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.