Tor security advisory: Debian flaw causes weak identity keys

coderman coderman at gmail.com
Tue May 13 18:11:18 UTC 2008


On Tue, May 13, 2008 at 8:55 AM, Roger Dingledine <arma at mit.edu> wrote:
> ...
>  Finally, while we don't know of any attacks that will reveal the
>  location of a weak-key hidden service, an attacker could derive its
>  secret key and then pretend to be the hidden service.


MITM'ing an .onion; now that's quite a trick...



More information about the tor-talk mailing list