[tbb-dev] Plan for new TBBs re Openssl bug?

Tom Ritter tom at ritter.vg
Mon Apr 7 20:52:05 UTC 2014


This is a server-side attack, so clients don't need to make any
change, but you should look at the server configuration and see what
version of what SSL library you're running.  And actually, now that I
think of it, look at tor itself and see how it impacts it.  Worst case
scenario would be people being able to steal tor node identity
keys....

-tom

On 7 April 2014 16:41, Roger Dingledine <arma at mit.edu> wrote:
> https://www.openssl.org/news/vulnerabilities.html#2014-0160
> http://heartbleed.com/
>
> Is TBB affected? Is there a plan for an update?
>
> --Roger
>
> _______________________________________________
> tbb-dev mailing list
> tbb-dev at lists.torproject.org
> https://lists.torproject.org/cgi-bin/mailman/listinfo/tbb-dev


More information about the tbb-dev mailing list