[tor-bugs] #2988 [Tor Relay]: information disclosure: operating system and platform

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Tue Apr 26 16:51:10 UTC 2011


#2988: information disclosure: operating system and platform
-----------------------+----------------------------------------------------
 Reporter:  tagnaq     |          Owner:     
     Type:  defect     |         Status:  new
 Priority:  normal     |      Milestone:     
Component:  Tor Relay  |        Version:     
 Keywords:             |         Parent:     
   Points:             |   Actualpoints:     
-----------------------+----------------------------------------------------

Comment(by arma):

 Replying to [comment:15 Sebastian]:
 > But as soon as we have that info in, relays' versions are again
 detectable (at least in a certain range of versions) because they will
 advertise different capabilities

 The applied security people I talk to make a big deal out of whether the
 identification is exact or almost exact. The distinction is whether your
 exploit has zero chance of being noticed (because you target only and
 exactly the vulnerable versions) or close-to-zero chance of being noticed.
 So I think they would regard "in a certain range of versions" as a huge
 improvement.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2988#comment:16>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list