[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #31460 [Circumvention/Snowflake]: Don't reveal proxy IDs in broker /debug (was: Can attackers disable proxies by using their ID?)



#31460: Don't reveal proxy IDs in broker /debug
-------------------------------------+------------------------
 Reporter:  phw                      |          Owner:  (none)
     Type:  defect                   |         Status:  new
 Priority:  Medium                   |      Milestone:
Component:  Circumvention/Snowflake  |        Version:
 Severity:  Normal                   |     Resolution:
 Keywords:                           |  Actual Points:
Parent ID:                           |         Points:
 Reviewer:                           |        Sponsor:
-------------------------------------+------------------------

Comment (by dcf):

 Yes, I think it is a security bug that /debug reveals proxy IDs. We should
 be scrubbing those somehow, by reporting `xxxxxxxx`, hashing them, or just
 reporting a total count.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31460#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs