[tor-bugs] #23841 [Internal Services/Service - trac]: Some asshole deleted cypherpunks account
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Oct 27 08:46:22 UTC 2017
#23841: Some asshole deleted cypherpunks account
----------------------------------------------+----------------------------
Reporter: cypherpunks | Owner: qbi
Type: defect | Status: closed
Priority: Medium | Milestone:
Component: Internal Services/Service - trac | Version:
Severity: Normal | Resolution: worksforme
Keywords: | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
----------------------------------------------+----------------------------
Comment (by cypherpunks):
You meant it has been recreated. But before recreation there is an amount
of time when the account is not recreated. It is possible to remove an
account by having a bot that tries to login periodically and deletes the
account. Given that the period of the check is just a bit longer an
adversary can effectively make the account unusable. You need to hardcode
the check disallowing deletion or changing the password of the account
with the name "cypherpunks". It's just 2 if in the right places!
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23841#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list