[tor-bugs] #23841 [Internal Services/Service - trac]: Some asshole deleted cypherpunks account

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Oct 27 08:46:22 UTC 2017


#23841: Some asshole deleted cypherpunks account
----------------------------------------------+----------------------------
 Reporter:  cypherpunks                       |          Owner:  qbi
     Type:  defect                            |         Status:  closed
 Priority:  Medium                            |      Milestone:
Component:  Internal Services/Service - trac  |        Version:
 Severity:  Normal                            |     Resolution:  worksforme
 Keywords:                                    |  Actual Points:
Parent ID:                                    |         Points:
 Reviewer:                                    |        Sponsor:
----------------------------------------------+----------------------------

Comment (by cypherpunks):

 You meant it has been recreated. But before recreation there is an amount
 of time when the account is not recreated. It is possible to remove an
 account by having a bot that tries to login periodically and deletes the
 account. Given that the period of the check is just a bit longer an
 adversary can effectively make the account unusable. You need to hardcode
 the check disallowing deletion or changing the password of the account
 with the name "cypherpunks". It's just 2 if in the right places!

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23841#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list