[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #16846 [Tor]: Include sizeof(void *) in your extrainfo.



#16846: Include sizeof(void *) in your extrainfo.
-------------------------+-------------------------------------------------
     Reporter:  yawning  |      Owner:
         Type:           |     Status:  new
  enhancement            |  Milestone:  Tor: 0.2.8.x-final
     Priority:  normal   |    Version:  Tor: unspecified
    Component:  Tor      |   Keywords:  tor-core, extrainfo, metrics,
   Resolution:           |  lorax, 028-triage
Actual Points:           |  Parent ID:
       Points:           |    Sponsor:
-------------------------+-------------------------------------------------

Comment (by mikeperry):

 FWIW, this seems OK to gather in aggregate, but I am a bit nervous about
 exposing specific platform details in individual extra-info since that
 will aid in targeted attacks. For example, ASLR is significantly weaker on
 32 bit systems. Similarly, the attacker will know that things like ASAN
 could not have been used to build the Tor binary on a 32 bit system (and
 so has much less risk of an 0day being captured by a 32 bit relay
 operator).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16846#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs