> My proposal for using this to enable tor users to play at Wikipedia is as
> follows:
> 1. Install a token server on a public IP.  The token server can optionally be
> provided Wikipedia's blocked-IP list and refuse to issue tokens to offending
> IPs.  Tor users use their real IP to obtain a blinded token.
> 2. Install a CA as a hidden service.  Tor users use their unblinded tokens to
> obtain a client certificate, which they install in their browser.
> 3. Install a wikipedia-gateway SSL web proxy (optionally also a hidden service)
> which checks client certs and communicates a client identifier to MediaWiki,
> which MediaWiki will use in place of the REMOTE_ADDR (client IP address) for
> connections from the proxy.  When a user misbehaves, Wikipedia admins block the
> client identifier just as they would have blocked an offending IP address---------------------------------------------------------------------
