[tor-bugs] #18927 [Obfuscation/meek]: Check meek fingerprint on ESR 45

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat May 21 01:29:52 UTC 2016


#18927: Check meek fingerprint on ESR 45
------------------------------+------------------------
 Reporter:  dcf               |          Owner:  dcf
     Type:  task              |         Status:  closed
 Priority:  Medium            |      Milestone:
Component:  Obfuscation/meek  |        Version:
 Severity:  Normal            |     Resolution:  fixed
 Keywords:                    |  Actual Points:
Parent ID:                    |         Points:
 Reviewer:                    |        Sponsor:
------------------------------+------------------------
Changes (by dcf):

 * status:  new => closed
 * resolution:   => fixed


Comment:

 It looks like there's no problem.

 Firefox 45.0.2esr
 [[doc/meek/SampleClientHellos#Firefox45.0.2esronDebianstretchsid2016-05-20]]

 Tor Browser 6.0a5 with meek
 [[doc/meek/SampleClientHellos#TorBrowser6.0a5basedonFirefox45ESRwithmeek-
 clientonDebianstretchsid2016-05-20]]

 diff
 {{{
  Secure Sockets Layer
      TLSv1.2 Record Layer: Handshake Protocol: Client Hello
          Content Type: Handshake (22)
          Version: TLS 1.0 (0x0301)
          Length: 187
          Handshake Protocol: Client Hello
              Handshake Type: Client Hello (1)
              Length: 183
              Version: TLS 1.2 (0x0303)
              Random
 -                GMT Unix Time: Feb 20, 2060 19:25:19.000000000 PST
 -                Random Bytes:
 54f218375ad711853b36f8becbd4b085f0e3f53bb48d4149...
 +                GMT Unix Time: Mar 10, 2094 14:10:31.000000000 PST
 +                Random Bytes:
 77ef56686f7f9a68867ade6d9c036db5832e2a7ed5aacab2...
              Session ID Length: 0
              Cipher Suites Length: 22
              Cipher Suites (11 suites)
                  Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
 (0xc02b)
                  Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
 (0xc02f)
                  Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
 (0xc00a)
                  Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
 (0xc009)
                  Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
                  Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)
                  Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x0033)
                  Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039)
                  Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA (0x002f)
                  Cipher Suite: TLS_RSA_WITH_AES_256_CBC_SHA (0x0035)
                  Cipher Suite: TLS_RSA_WITH_3DES_EDE_CBC_SHA (0x000a)
              Compression Methods Length: 1
              Compression Methods (1 method)
                  Compression Method: null (0)
              Extensions Length: 120
              Extension: server_name
                  Type: server_name (0x0000)
                  Length: 23
                  Server Name Indication extension
                      Server Name list length: 21
                      Server Name Type: host_name (0)
                      Server Name length: 18
                      Server Name: ajax.aspnetcdn.com
              Extension: renegotiation_info
                  Type: renegotiation_info (0xff01)
                  Length: 1
                  Renegotiation Info extension
                      Renegotiation info extension length: 0
              Extension: elliptic_curves
                  Type: elliptic_curves (0x000a)
                  Length: 8
                  Elliptic Curves Length: 6
                  Elliptic curves (3 curves)
                      Elliptic curve: secp256r1 (0x0017)
                      Elliptic curve: secp384r1 (0x0018)
                      Elliptic curve: secp521r1 (0x0019)
              Extension: ec_point_formats
                  Type: ec_point_formats (0x000b)
                  Length: 2
                  EC point formats Length: 1
                  Elliptic curves point formats (1)
                      EC point format: uncompressed (0)
              Extension: SessionTicket TLS
                  Type: SessionTicket TLS (0x0023)
                  Length: 0
                  Data (0 bytes)
              Extension: next_protocol_negotiation
                  Type: next_protocol_negotiation (0x3374)
                  Length: 0
              Extension: Application Layer Protocol Negotiation
                  Type: Application Layer Protocol Negotiation (0x0010)
                  Length: 23
                  ALPN Extension Length: 21
                  ALPN Protocol
                      ALPN string length: 2
                      ALPN Next Protocol: h2
                      ALPN string length: 8
                      ALPN Next Protocol: spdy/3.1
                      ALPN string length: 8
                      ALPN Next Protocol: http/1.1
              Extension: status_request
                  Type: status_request (0x0005)
                  Length: 5
                  Certificate Status Type: OCSP (1)
                  Responder ID list Length: 0
                  Request Extensions Length: 0
              Extension: signature_algorithms
                  Type: signature_algorithms (0x000d)
                  Length: 22
                  Signature Hash Algorithms Length: 20
                  Signature Hash Algorithms (10 algorithms)
                      Signature Hash Algorithm: 0x0401
                          Signature Hash Algorithm Hash: SHA256 (4)
                          Signature Hash Algorithm Signature: RSA (1)
                      Signature Hash Algorithm: 0x0501
                          Signature Hash Algorithm Hash: SHA384 (5)
                          Signature Hash Algorithm Signature: RSA (1)
                      Signature Hash Algorithm: 0x0601
                          Signature Hash Algorithm Hash: SHA512 (6)
                          Signature Hash Algorithm Signature: RSA (1)
                      Signature Hash Algorithm: 0x0201
                          Signature Hash Algorithm Hash: SHA1 (2)
                          Signature Hash Algorithm Signature: RSA (1)
                      Signature Hash Algorithm: 0x0403
                          Signature Hash Algorithm Hash: SHA256 (4)
                          Signature Hash Algorithm Signature: ECDSA (3)
                      Signature Hash Algorithm: 0x0503
                          Signature Hash Algorithm Hash: SHA384 (5)
                          Signature Hash Algorithm Signature: ECDSA (3)
                      Signature Hash Algorithm: 0x0603
                          Signature Hash Algorithm Hash: SHA512 (6)
                          Signature Hash Algorithm Signature: ECDSA (3)
                      Signature Hash Algorithm: 0x0203
                          Signature Hash Algorithm Hash: SHA1 (2)
                          Signature Hash Algorithm Signature: ECDSA (3)
                      Signature Hash Algorithm: 0x0402
                          Signature Hash Algorithm Hash: SHA256 (4)
                          Signature Hash Algorithm Signature: DSA (2)
                      Signature Hash Algorithm: 0x0202
                          Signature Hash Algorithm Hash: SHA1 (2)
                          Signature Hash Algorithm Signature: DSA (2)
 }}}

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18927#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list