Friday, April 23, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Two Tor zero-days disclosed, more to come

July 31, 2020
in Internet Security
Mozilla offers research grant for a way to embed Tor inside Firefox
589
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Image: Tor Project

Over the past week, a security researcher has published technical details about two vulnerabilities impacting the Tor network and the Tor browser.

In blog posts last week and today, Dr. Neal Krawetz said he was going public with details on two zero-days after the Tor Project has repeatedly failed to address multiple security issues he reported throughout the past years.

You might also like

King Island connectivity upgrade to include 110km radio link across Bass Strait

Malware and ransomware gangs have found this new way to cover their tracks

Best free PC antivirus software in 2021

The researcher also promised to reveal at least three more Tor zero-days, including one that can reveal the real-world IP address of Tor servers.

Approached for comment on Dr. Krawetz’s intentions, the Tor Project did not reply to a request for comment and provide additional details on its stance on the matter.

The first Tor zero-day

Dr. Krawetz, who operates multiple Tor nodes himself and has a long history of finding and reporting Tor bugs, disclosed the first Tor zero-day last week.

In a blog post dated July 23, the researcher described how companies and internet service providers could block users from connecting to the Tor network by scanning network connections for “a distinct packet signature” that is unique to Tor traffic.

The packet could be used as a way to block Tor connections from initiating and effectively ban Tor altogether — an issue that oppressive regimes are very likely to abuse.

The second Tor zero-day

Earlier today, in a blog post shared with ZDNet, Dr. Krawetz disclosed a second issue. This one, like the first, allows network operators to detect Tor traffic.

However, while the first zero-day could be used to detect direct connections to the Tor network (to Tor guard nodes), the second one can be used to detect indirect connections.

These are connections that users make to Tor bridges, a special type of entry points into the Tor network that can be used when companies and ISPs block direct access to the Tor network.

Tor bridges act as proxy points and relay connections from the user to the Tor network itself. Because they are sensitive Tor servers, the list of Tor bridges is being constantly updated to make it difficult for ISPs to block it.

But Dr. Krawetz says connections to Tor bridges can be easily detected, as well, using a similar technique of tracking specific TCP packets.

“Between my previous blog entry and this one, you now have everything you need to enforce the policy [of blocking Tor on a network] with a real-time stateful packet inspection system. You can stop all of your users from connecting to the Tor network, whether they connect directly or use a bridge,” Dr. Krawetz said.

Both issues are specifically concerning for Tor users residing in countries with oppressive regimes.

Dissatisfaction towards the Tor Project’s security stance

The reason why Dr. Krawetz is publishing these zero-days is that he believes the Tor Project does not take the security of its networks, tools, and users seriously enough.

The security researcher cites previous incidents when he tried to report bugs to the Tor Project only to be told that they were aware of the issue, working on a fix, but never actually deploying said fix. This includes:

  • A bug that allows websites to detect and fingerprint Tor browser users by the width of their scrollbar, which the Tor Project has known about since at least June 2017.
  • A bug that allows network adversaries to detect Tor bridge servers using their OR (Onion routing) port, reported eight years ago.
  • A bug that lets attackers identify the SSL library used by Tor servers, reported on December 27, 2017.

All of these issues are still not fixed, which has led Dr. Krawetz in early June 2020 to abandon his collaboration with the Tor Project and take the current approach of publicly shaming the company into taking action.

I’m giving up reporting bugs to Tor Project. Tor has serious problems that need to be addressed, they know about many of them and refuse to do anything.

I’m holding off dropping Tor 0days until the protests are over. (We need Tor now, even with bugs.) After protests come 0days.

— Dr. Neal Krawetz (@hackerfactor) June 4, 2020


Credit: Zdnet

Previous Post

Machine Learning And Organizational Change At Southern California Edison

Next Post

Tips on building your virtual event

Related Posts

King Island connectivity upgrade to include 110km radio link across Bass Strait
Internet Security

King Island connectivity upgrade to include 110km radio link across Bass Strait

April 23, 2021
Malware and ransomware gangs have found this new way to cover their tracks
Internet Security

Malware and ransomware gangs have found this new way to cover their tracks

April 23, 2021
Best free PC antivirus software in 2021
Internet Security

Best free PC antivirus software in 2021

April 23, 2021
ServiceNow launches unified agent platform, aims to meld diagnostics with incident automation
Internet Security

ServiceNow launches unified agent platform, aims to meld diagnostics with incident automation

April 23, 2021
SolarWinds hack analysis reveals 56% boost in command server footprint
Internet Security

SolarWinds hack analysis reveals 56% boost in command server footprint

April 22, 2021
Next Post
Tips on building your virtual event

Tips on building your virtual event

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Edge Computing, The Cloud, And AI Autonomous Vehicles 
Artificial Intelligence

Edge Computing, The Cloud, And AI Autonomous Vehicles 

April 23, 2021
Data Science and Machine-Learning Platforms Market 2020 | Latest Trends, Demand, Growth, Opportunities & Outlook Till 2027 | Top Key Players: SAS, Alteryx, IBM, RapidM – KSU
Machine Learning

Data Science and Machine-Learning Platforms Market 2020 | Latest Trends, Demand, Growth, Opportunities & Outlook Till 2027 | Top Key Players: SAS, Alteryx, IBM, RapidM – KSU

April 23, 2021
King Island connectivity upgrade to include 110km radio link across Bass Strait
Internet Security

King Island connectivity upgrade to include 110km radio link across Bass Strait

April 23, 2021
IoT in Telecommunications: Challenges, Opportunities, Benefits & The Future
Data Science

IoT in Telecommunications: Challenges, Opportunities, Benefits & The Future

April 23, 2021
Your Doctor’s Assistant is AI 
Artificial Intelligence

Your Doctor’s Assistant is AI 

April 23, 2021
Machine learning model generates realistic seismic waveforms
Machine Learning

Machine learning model generates realistic seismic waveforms

April 23, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Edge Computing, The Cloud, And AI Autonomous Vehicles  April 23, 2021
  • Data Science and Machine-Learning Platforms Market 2020 | Latest Trends, Demand, Growth, Opportunities & Outlook Till 2027 | Top Key Players: SAS, Alteryx, IBM, RapidM – KSU April 23, 2021
  • King Island connectivity upgrade to include 110km radio link across Bass Strait April 23, 2021
  • IoT in Telecommunications: Challenges, Opportunities, Benefits & The Future April 23, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates