[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #23841 [Internal Services/Service - trac]: Some asshole deleted cypherpunks account
#23841: Some asshole deleted cypherpunks account
----------------------------------------------+----------------------------
Reporter: cypherpunks | Owner: qbi
Type: defect | Status: closed
Priority: Medium | Milestone:
Component: Internal Services/Service - trac | Version:
Severity: Normal | Resolution: worksforme
Keywords: | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
----------------------------------------------+----------------------------
Comment (by cypherpunks):
You meant it has been recreated. But before recreation there is an amount
of time when the account is not recreated. It is possible to remove an
account by having a bot that tries to login periodically and deletes the
account. Given that the period of the check is just a bit longer an
adversary can effectively make the account unusable. You need to hardcode
the check disallowing deletion or changing the password of the account
with the name "cypherpunks". It's just 2 if in the right places!
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23841#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs