[tor-bugs] #13169 [Tor Browser]: Make SSP use Windows-specifc RNG

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Sep 20 05:50:01 UTC 2014


#13169: Make SSP use Windows-specifc RNG
-----------------------------+--------------------------
     Reporter:  mikeperry    |      Owner:  tbb-team
         Type:  defect       |     Status:  new
     Priority:  normal       |  Milestone:
    Component:  Tor Browser  |    Version:
   Resolution:               |   Keywords:  tbb-security
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+--------------------------

Comment (by cypherpunks):

 > It looks like it is trying to use the Windows crypto provider instead of
 /dev/urandom? Is that correct?

 Yes.

 > What is this patch applying to? gcc or binutils?

 GCC.

 In Windows you can to create any directories for any disks(C:, D:, .. Z:),
 only system directories (Windows directory, Program files, etc) are
 protected. Any process with privileges of any standard user can to create
 C:\dev\urandom file and to fill it by any stuff.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13169#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list