[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #18940 [- Select a component]: Danger : verifying digital certificate and fake response !



#18940: Danger : verifying digital certificate and  fake response !
----------------------------------+-------------------------
 Reporter:  safeless              |          Owner:
     Type:  defect                |         Status:  closed
 Priority:  Medium                |      Milestone:
Component:  - Select a component  |        Version:
 Severity:  Normal                |     Resolution:  invalid
 Keywords:                        |  Actual Points:
Parent ID:                        |         Points:
 Reviewer:                        |        Sponsor:
----------------------------------+-------------------------
Changes (by yawning):

 * status:  new => closed
 * resolution:   => invalid


Comment:

 > Iran cyber Army can generate a fake response for this! (connections on
 port number 80 is not encrypted )

 a) "All definitive response messages SHALL be digitally signed."
 (https://tools.ietf.org/html/rfc6960)
 b) It's Microsoft's signature scheme, mechanism and implementation.  Go
 complain to them.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18940#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs