[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Long-term effect of Heartbleed on Tor



What's the long-term effect of Heartbleed on Tor?

* Should we consider every key that was created before Tuesday a bad key and lower their consensus weight? * Should authorities scan for bad OpenSSL versions and force their weight down to 20?

A lot of relays will continue running bad OpenSSL versions which seriously hurts the security of Tor. A month from now the NSA/CGHQ/CIVD/etc may know the private keys of a large chunk of these relays and possibly be able to decode a big chunk of traffic...

Tom
_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays