[tor-bugs] #7098 [Tor]: Add safe-cookie authentication to Extended ORPort and TransportControlPort

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Nov 19 18:45:06 UTC 2012


#7098: Add safe-cookie authentication to Extended ORPort and TransportControlPort
------------------------+---------------------------------------------------
 Reporter:  asn         |          Owner:                    
     Type:  defect      |         Status:  needs_review      
 Priority:  normal      |      Milestone:  Tor: 0.2.4.x-final
Component:  Tor         |        Version:                    
 Keywords:  tor-bridge  |         Parent:  #4773             
   Points:              |   Actualpoints:                    
------------------------+---------------------------------------------------

Comment(by rransom):

 Why not `HMAC-SHA256(CookieString, "ExtORPort authentication safe cookie
 client-to-server hash" || ClientNonce || ServerNonce)`?  Putting a header
 on the cookie file solves the ‘it might be my Ed25519 secret key’ problem.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7098#comment:16>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list