[tor-bugs] #2988 [Tor Relay]: information disclosure: operating system and platform

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Tue May 10 10:44:25 UTC 2011


#2988: information disclosure: operating system and platform
-----------------------+----------------------------------------------------
 Reporter:  tagnaq     |          Owner:                  
     Type:  defect     |         Status:  new             
 Priority:  normal     |      Milestone:  Tor: unspecified
Component:  Tor Relay  |        Version:                  
 Keywords:             |         Parent:                  
   Points:             |   Actualpoints:                  
-----------------------+----------------------------------------------------
Changes (by linus):

 * cc: linus@… (added)


Comment:

 Replying to [comment:15 Sebastian]:
 > Also, if we stop putting in the version, we will need to add more flags
 showing the compatibility with certain protocol features. I think we
 should do that, because putting in the version is a prohibitor for
 alternative relay implementations of Tor. Not that there are any
 currently, but hey. But as soon as we have that info in, relays' versions
 are again detectable (at least in a certain range of versions) because
 they will advertise different capabilities. I don't really see a way to
 solve this.

 +1 -- capabilities should not be encoded in the version number of a
 software package.

 Regarding detecting relay version based on capabilities, my guess is that
 capabilities won't change frequently enough for such a detection to be a
 issue in practice.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2988#comment:20>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list