[tor-bugs] #8217 [Obfsproxy]: obfsproxy: obfs2: When deriving padding keys we truncate the shared-secret hash

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Feb 12 21:15:50 UTC 2013


#8217: obfsproxy: obfs2: When deriving padding keys we truncate the shared-secret
hash
-----------------------+----------------------------------------------------
 Reporter:  asn        |          Owner:  asn             
     Type:  defect     |         Status:  new             
 Priority:  normal     |      Milestone:                  
Component:  Obfsproxy  |        Version:  Obfsproxy: 0.1.4
 Keywords:             |         Parent:                  
   Points:             |   Actualpoints:                  
-----------------------+----------------------------------------------------

Comment(by asn):

 Replying to [comment:1 nickm]:
 > I don't know that this is worth breaking compatibility for; 16 bytes is
 plenty here.
 >

 I was not worrying about security that much; mostly about the elegance and
 beauty of the spec. If you think it's worth sacrificing to preserve
 backwards compatibility then I'm more than fine with it.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/8217#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list