[tor-bugs] #8742 [Core Tor/Tor]: Byte history leaks information about local usage/hidden services

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jan 9 02:47:19 UTC 2018


#8742: Byte history leaks information about local usage/hidden services
-------------------------------------------------+-------------------------
 Reporter:  alphawolf                            |          Owner:  (none)
     Type:  defect                               |         Status:  closed
 Priority:  High                                 |      Milestone:  Tor:
                                                 |  0.2.8.x-final
Component:  Core Tor/Tor                         |        Version:  Tor:
                                                 |  0.2.7
 Severity:  Blocker                              |     Resolution:  fixed
 Keywords:  byte-history, stats, tor-hs,         |  Actual Points:
  privacy, tor-relay, 026-triaged-1,             |
  027-triaged-1-in, PostFreeze027                |
Parent ID:                                       |         Points:  medium
 Reviewer:                                       |        Sponsor:
                                                 |  SponsorR
-------------------------------------------------+-------------------------
Changes (by 43901348):

 * severity:   => Blocker


Comment:

 '''PLEASE '''reopen this. Having "fixed" the issue by only adding a
 startup warning is inaccurate and insufficient:

  * Some admins will never see the warning
  * Some admins will see the warning, come to this link, see the issue is
 fixed and conclude the warning is out of date
  * The list of proposed solutions in the issue summary does not include
 "just add a startup warning, but don't address the issue itself"

 This can easily lead to misunderstandings. Please keep the issue open, or
 if you don't think it's worth fixing, please then mark it as WONTFIX.

 Anything but what you have now would be a good start, but a more robust
 solution would be to ensure that administrators see this warning, and
 ideally have to acknowledge that they know what they are doing by setting
 a configuration switch in torrc to allow a relay and HS to be run in the
 same instance.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/8742#comment:19>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list