[tor-relays] Recommended reject lines for relays affected by Heartbleed

Andrea Shepard andrea at torproject.org
Thu Apr 17 01:24:40 UTC 2014

A list of 1777 proposed reject lines of fingerprints which have
ever turned up as potentially exposed by Heartbleed in my scans
is available at the URL below.  This was generated with the following

(select distinct
  hb.probe_identity_digest as identity_digest
  heartbleed_probe_results hb
  hb.probe_has_heartbleed and
(select distinct
  hb.expected_identity_digest as identity_digest
  heartbleed_probe_results hb
  hb.probe_has_heartbleed and
  not hb.probe_tor_checked_identity)
order by

That is, it includes all probe results for which a Tor handshake was
actually completed with the identity digest in question *and* a response
to the Heartbleed probe was seen (1729 digests) or for identity digests we
expected to see for that IP/port pair for which the handshake did not succeed
but a Heartbleed response was seen (additional 48 digests).

The target list is all IP/port pairs which have ever appeared in a consensus
or vote during the time I've been scanning, so some of these may not be
in the current consensus or have ever appeared, or they may no longer be
vulnerable but not have changed keys properly.  There are a bit over 900
vulnerable relays in the latest consensus.


