[tor-bugs] #2988 [Tor Relay]: information disclosure: operating system and platform
    Tor Bug Tracker & Wiki 
    torproject-admin at torproject.org
       
    Tue Apr 26 16:51:10 UTC 2011
    
    
  
#2988: information disclosure: operating system and platform
-----------------------+----------------------------------------------------
 Reporter:  tagnaq     |          Owner:     
     Type:  defect     |         Status:  new
 Priority:  normal     |      Milestone:     
Component:  Tor Relay  |        Version:     
 Keywords:             |         Parent:     
   Points:             |   Actualpoints:     
-----------------------+----------------------------------------------------
Comment(by arma):
 Replying to [comment:15 Sebastian]:
 > But as soon as we have that info in, relays' versions are again
 detectable (at least in a certain range of versions) because they will
 advertise different capabilities
 The applied security people I talk to make a big deal out of whether the
 identification is exact or almost exact. The distinction is whether your
 exploit has zero chance of being noticed (because you target only and
 exactly the vulnerable versions) or close-to-zero chance of being noticed.
 So I think they would regard "in a certain range of versions" as a huge
 improvement.
-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2988#comment:16>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
    
    
More information about the tor-bugs
mailing list