[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
TorChat is a security hazard
- To: or-talk@xxxxxxxx
- Subject: TorChat is a security hazard
- From: Paul Campbell <campbell_paul@xxxxxxxxxxxxxx>
- Date: Tue, 23 Feb 2010 19:38:38 -0800 (PST)
- Delivered-to: archiver@xxxxxxxx
- Delivered-to: or-talk-outgoing@xxxxxxxx
- Delivered-to: or-talk@xxxxxxxx
- Delivery-date: Tue, 23 Feb 2010 22:38:49 -0500
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rocketmail.com; s=s1024; t=1266982719; bh=lY4rXVGfPQL/pui+7NmQqVa/zeBxGiFkD0w/dOxbV/8=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=GryHzsDHrkEK4r8pXP8UOpxljqPQGaGa4vV0TBbDZSfMTwTPg/WxqtA70Qk7OyvrSsdlvJXvw9aGbModIZ4iLOLuW0JLMYX63F8jnPvVV/6Fj4RXqPGLVflIaC46vFl65MCEFS+GOL+XmZFNu3I9+n/RMlu/vDlF+gnO3zFM+zI=
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws;  s=s1024; d=rocketmail.com;  h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;  b=ZtlB3NLpm+dBC/JpPfJOZuA9/g/yaMzl+rmdIPjNQS0BVA/g5HAIKEBoHHkb1s7ANUU6LHgRQrLoPSeF7tC5utdeGb7nBO+YRFsUideyad19yi0+7kYpvaz9ZKjPh50kXhHUttAI8vRwqwE2j0mzFY02vCBoSzVuj8CW2TC/amg=;
- Reply-to: or-talk@xxxxxxxxxxxxx
- Sender: owner-or-talk@xxxxxxxxxxxxx
Hello.
I'm in no way a security expert.  I never ran "TorChat" but I did read the source code. Read on why I haven't run it.
"TorChat" is an inofficial chat client for the Tor network.  I like the idea behind "TorChat": easy to use, usb-stick portable and runs on Windows 98.
These are the problems I see with "TorChat":
1. No authentication.  There is no way you can know for sure that the person you are chatting with is the person you chatted with yesterday.  Tor's hidden services don't make any such guarantees about incoming connections. The clients stay anonymous.
2. To make things even worse, the only information needed to impersonate a buddy is their .onion address.
3. Buddies have control over your buddylist.  It is just a matter of identifying as a buddy and telling the software to remove this said buddy.
I don't think these are the only problems, but the first one alone is enough to conclude that "TorChat" cannot give adequate security.  It's too easy to impersonate people.  "TorChat" lives off the name of the Tor Project, but unfortunately doesn't deliver.
It is possible to run Off-the-Record Messaging over Tor.  Off-the-Record Messaging has all kinds of features: encryption, perfect forward secrecy and deniable authentication.  And it doesn't have the problems of "TorChat".
Best regards,
Paul
      
***********************************************************************
To unsubscribe, send an e-mail to majordomo@xxxxxxxxxxxxxx with
unsubscribe or-talk    in the body. http://archives.seul.org/or/talk/