[tor-bugs] #1796 [Tor - Relay]: write-history and read-history in extra-infos leaks the relay's used bandwith if the bandwidth limit is changed
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Wed Aug 4 12:41:40 UTC 2010
#1796: write-history and read-history in extra-infos leaks the relay's used
bandwith if the bandwidth limit is changed
------------------------------+---------------------------------------------
Reporter: lancelot666 | Type: defect
Status: new | Priority: minor
Milestone: | Component: Tor - Relay
Version: Tor: unspecified | Keywords: write-history read-history
Parent: |
------------------------------+---------------------------------------------
If a user changes the bandwidth limit to a different value, the next
update of the write/read-history (after a reload of the config) contains
different values. By the difference of the values an attacker could infer
how much bandwidth the user used by himself.
Lets assume the extra info reports 18432000 (B) for a 15 min period. After
increasing the bandwidth limit and reloading the server, the next update
reports 23404544 (B) for the same 15 min period. Thus, an attacker can
infer how much bandwidth the user/relay used by its own in this period.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/1796>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list