[tor-bugs] #31460 [Circumvention/Snowflake]: Don't reveal proxy IDs in broker /debug (was: Can attackers disable proxies by using their ID?)

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 22 16:58:08 UTC 2019


#31460: Don't reveal proxy IDs in broker /debug
-------------------------------------+------------------------
 Reporter:  phw                      |          Owner:  (none)
     Type:  defect                   |         Status:  new
 Priority:  Medium                   |      Milestone:
Component:  Circumvention/Snowflake  |        Version:
 Severity:  Normal                   |     Resolution:
 Keywords:                           |  Actual Points:
Parent ID:                           |         Points:
 Reviewer:                           |        Sponsor:
-------------------------------------+------------------------

Comment (by dcf):

 Yes, I think it is a security bug that /debug reveals proxy IDs. We should
 be scrubbing those somehow, by reporting `xxxxxxxx`, hashing them, or just
 reporting a total count.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31460#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list