[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #5131 [Obfsproxy]: auditing obfsproxy



#5131: auditing obfsproxy
-------------------------+--------------------------------------------------
 Reporter:  ioerror      |          Owner:  asn         
     Type:  enhancement  |         Status:  needs_review
 Priority:  normal       |      Milestone:              
Component:  Obfsproxy    |        Version:              
 Keywords:  security     |         Parent:              
   Points:               |   Actualpoints:              
-------------------------+--------------------------------------------------

Comment(by nickm):

 Oh; also, it would be neat if there were a comment before each compiler
 option explaining where to find the documentation on what it does.

 Also -fcatch-undefined-c99-behavior seems like more of a debugging option
 than a hardening option.  According to one page, it supposedly has up to a
 3x slowdown for crypto code, and it looks like it can introduce timing
 leaks where there were none before.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5131#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs