[tor-bugs] #22948 [Core Tor/Tor]: Padding, Keepalive and Drop cells should have random payloads

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 31 21:51:40 UTC 2017


#22948: Padding, Keepalive and Drop cells should have random payloads
--------------------------+------------------------------------
 Reporter:  teor          |          Owner:  isis
     Type:  defect        |         Status:  accepted
 Priority:  Medium        |      Milestone:  Tor: 0.3.2.x-final
Component:  Core Tor/Tor  |        Version:
 Severity:  Normal        |     Resolution:
 Keywords:  tor-spec      |  Actual Points:
Parent ID:  #18856        |         Points:  0.5
 Reviewer:                |        Sponsor:
--------------------------+------------------------------------
Changes (by isis):

 * cc: nickm (added)
 * owner:  (none) => isis
 * status:  new => accepted


Comment:

 Replying to [comment:8 isis]:
 > I think I've convinced myself this is not a security issue.
 >
 > Probably we should do a torspec fix that says something like "SHOULD be
 chosen randomly, but MAY be all zeroes, and MUST be ignored"?
 >
 > For the patch, it probably doesn't hurt to use random padding. We should
 make sure that whatever we do, we're doing the same thing for `VPADDING`,
 `PADDING`, and `DROP` cells.  I'd also want to hear what Nick thinks about
 future-compatibility w.r.t. adding extra fields if we have random padding.

 Any opinions on whether we should go with 1) actually randomise padding,
 or 2) patch torspec as above? I'm happy to do either.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22948#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list