[tor-relays] security update for obfs4proxy

meskio meskio at torproject.org
Tue Jan 10 18:51:49 UTC 2023


We have made public the details of the distinguishability bugs that were 
affecting obfs4:
https://gitlab.torproject.org/tpo/anti-censorship/team/-/issues/91
https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/obfs4/-/issues/40007

Most bridges are already upgraded, thank you all bridge operators for the work 
here.

Quoting meskio (2022-10-14 11:28:44)
> Hello,
> 
> The latest version of obfs4proxy (0.0.14) comes with an important security fix.
> If you are running a obfs4 Tor bridge please upgrade as soon as possible.
> 
> If you use debian you can find the Debian package in stable-backports:
>   https://packages.debian.org/stable-backports/obfs4proxy
> 
> If you use docker you'll find the latest version in docker hub:
>   https://hub.docker.com/r/thetorproject/obfs4-bridge/
> 
> Or you can find the source code in the upstream repository:
>   https://gitlab.com/yawning/obfs4
> 
> If you need help upgrading your relay, please use this mailing list or the Tor 
> Forum:
>   https://forum.torproject.net/c/support/relay-operator/17
> 
> We appreciate a lot your effort and time!
> 
> Thank you

-- 
meskio | https://meskio.net/
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
 My contact info: https://meskio.net/crypto.txt
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Nos vamos a Croatan.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: signature
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20230110/e87cd388/attachment.sig>


More information about the tor-relays mailing list