[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Long-term effect of Heartbleed on Tor
What's the long-term effect of Heartbleed on Tor?
* Should we consider every key that was created before Tuesday a bad key
and lower their consensus weight?
* Should authorities scan for bad OpenSSL versions and force their
weight down to 20?
A lot of relays will continue running bad OpenSSL versions which
seriously hurts the security of Tor. A month from now the
NSA/CGHQ/CIVD/etc may know the private keys of a large chunk of these
relays and possibly be able to decode a big chunk of traffic...
Tom
_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays