David Fifield via tor-project:
I was looking at this 2020 research paper: https://ieeexplore.ieee.org/document/9343014/ https://sci-hub.ru/10.1109/TrustCom50675.2020.00097 "Napping Guard: Deanonymizing Tor Hidden Service in a Stealthy Way" Chen Muqian, Wang Xuebin, Shi Jinqiao, Zhao Can, Wang Meiqi, Fang Binxing In the abstract and introduction, they say: In addition, we also propose a mitigation of Napping Guard attack, and report the design flaw to the Tor project. But they don't give details of reporting the flaw or what happened after that, as far as I can see. Did the reporting happen, and did it result in changes in Tor?
I am not sure for that one but I could not find anything doing a cursory search in my inbox.
I also noticed this more recent paper by some of the same authors: https://ieeexplore.ieee.org/document/10570737 "Knock-Knock: De-Anonymise Hidden Services by Exploiting Service Answer Vulnerability" Zhang Qingfeng, Chen Muqian, Wang Xuebin, Zhao Can, Liu Qingyun, Shi Jinqiao This one, too, says "Lastly, we present a method to mitigate watermark attacks and report the design flaw to the Tor Project." Did that happen?
I looked over the mail archive of our security@ alias at least but wasn't able to find that one (but maybe they reported via other mechanisms I am not aware of or I looked not close enough). However, we have brought up that paper at different locations. A public (unresolved) ticket for it is:
https://gitlab.torproject.org/tpo/core/tor/-/work_items/41063 Georg _______________________________________________
tor-project mailing list -- tor-project@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-project-leave@xxxxxxxxxxxxxxxxxxxx
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ tor-project mailing list -- tor-project@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-project-leave@xxxxxxxxxxxxxxxxxxxx