[tor-bugs] #14788 [Tor]: Use unpredictability better on Windows

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Feb 10 16:13:11 UTC 2015


#14788: Use unpredictability better on Windows
-----------------------------+--------------------------------
     Reporter:  anon         |      Owner:
         Type:  enhancement  |     Status:  new
     Priority:  normal       |  Milestone:  Tor: 0.2.7.x-final
    Component:  Tor          |    Version:
   Resolution:               |   Keywords:
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+--------------------------------

Comment (by cypherpunks):

 > Do we know anything about what post-XP windows does here? I don't think
 we support windows 2000, right?

 Some information from https://en.wikipedia.org/wiki/CryptGenRandom
 > A 2007 paper from Hebrew University suggested security problems in the
 Windows 2000 implementation of CryptGenRandom (assuming the attacker has
 control of the machine). Microsoft later acknowledged that the same
 problems exist in Windows XP, but not in Vista. Microsoft released a fix
 for the bug with Windows XP Service Pack 3 in mid-2008.

 > Did anybody save that privatepaste thing? It seems to have expired.

 I think it was off-topic here, patch was about hardening libssp (GCC).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/14788#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list