[tor-talk] New Software: P2P filesharing designed to use Tor

Full Name freedomfighter3 at myway.com
Wed Jan 7 18:25:37 UTC 2015


yes i have changed now to SHA-256 because it is said to be more secure, thank you.
Also i introduced a fourth Hash-level in the hash-tree (of 5k Blocks). They are only used now to build the higher level hashes, they are not transmitted. If needed, they can be transmitted also to do more fine grained validation.

@Aymeric Vitte
Thanks i have learned a lot now. I also saw that Tribler has published a warning that security has not yet matured.
I think file sharing of small files should work, for big files people should not use tor if they have other sources available.




-----Original Message-----
From: "SecTech" [tech at firemail.de]
Date: 01/07/2015 11:18 AM
To: tor-talk at lists.torproject.org
Subject: Re: [tor-talk] New Software: P2P filesharing designed to use Tor

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hey,
maybe I am paranoid, but could you implement an second hash computed
out of the file. SHA-256 would be perfect, because when you have
security in mind, NSA could break SHA-1. When you are using two hashing
algos than it is even harder to attack it.


- -- 
SecTech <tech at firemail.de>
GPG-ID: 0x364CFE05

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJUrVw5AAoJENR4jiM2TP4FQkoP/0ECBcr86rqpZC/+b9bC5bSE
LlGzW0G8KrbGJzIix2ZqYfFKKIBhqCVQdWhEkR5lRGgN1KHbev9qCJ7jLihsTQqZ
jmp/4WIs2gAh5BEB5i0hAzubDSrIdvkBz1O46UeT3oe7O3jfhlIpSo3QTdkRh6CX
aXn0DJyz83WdEGG3DGuByJwr0BNrutNdOEkYlyIzfyjW3rVlIlPuycqUaf0DQuP7
9tZ8N6eh7FMQvMQh+ECXOlXmiWmHGwYU0FksUa1M8Ohpxye1YL6KA04inJYg9Kn9
fGtJ6UJXDyvWTrqxERu2NKAQ9s8F+wxmgOEZ26cLfcNA/QQIWpy9gGFm4Ilfwp5m
smQk/+NZAcZNM9VwiDrXtyB5dFTONJwMQ3WTBlb04QLo8GDHGfCXM0j0kxZEX1o0
iElxIbdI6RinT7yHpkBxoOQH6NNSGuMbfDSf2v0luqY1r47Uxtwo4C3pGtxBVxU4
iTNJ+D3ni0MoGO7TWY7G9/4e8VeJUNwZq3G+xxQyXvbWcG6UwMXHe6iO+7s5Lwqt
7modBG4N6mC2XSmmRwJrHsOJPwASeCNIQnD6Vxw+zoCQv56/aOmSRkZra26ZzDHl
ahUbKF+lS/GUmKip2J9UiCglzaHbv/CdOPrMJfs2jbu79mMp/y7YMDMxBFZLOwDu
r2BrBlPQwTF5a3YnKSNj
=VRxF
-----END PGP SIGNATURE-----
-- 
tor-talk mailing list - tor-talk at lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk




More information about the tor-talk mailing list