Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Tor Circuit Entry Guard Same Family Check Design Weakness

Tor is prone to a design weakness that may assist hostile node operators in performing traffic analysis.

Tor performs a check to ensure that the entry guard is not the same node as the exit guard when building a circuit. However, Tor fails to ensure that the entry guard and exit guard are not part of the same family. This may enable hostile node operators to have purview over more of a Tor client's communication stream than intended. This weakness aids in the performance of traffic analysis.

This issue affects all versions prior to 0.1.2.14.







 

Privacy Statement
Copyright 2009, SecurityFocus