On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

June 27th, 2008

Critical security alert issued for Tor

Posted by Ryan Naraine @ 12:14 pm

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Malware, Passwords, Patch Watch, Privacy, Vulnerability research

Tags: OpenSSL, Security Alert, Tor, Ssl/Tls, Security, Ryan Naraine

Critical security alert issue for TorIf you use Tor for anonymity/privacy on the Web, you might want to pay attention to this critical security announcement from project leader Roger Dingledine.

According to the advisory, a known vulnerability in the Debian GNU/Linux distribution’s OpenSSL package could allow an attacker to figure out private keys generated by these buggy versions of the OpenSSL library. Because Tor uses OpenSSL, all private keys generated by affected versions of OpenSSL must be considered to be compromised.

The skinny:

Due to a bug in Debian’s modified version of OpenSSL 0.9.8, all generated keys (and other cryptographic material!) have a stunningly small amount of entropy. This flaw means that brute force attacks which are very hard against the unmodified OpenSSL library (e.g. breaking RSA keys) are very practical against these keys.

While we believe the v2 authority keys (used in Tor 0.1.2.x) were generated correctly, at least three of the six v3 authority keys (used in Tor 0.2.0.x) are known to be weak. This fraction is uncomfortably close to the majority vote needed to create a networkstatus consensus, so the Tor 0.2.0.26-rc release changes these three affected keys.

[ SEE: Hacker builds tracking system to nab Tor pedophiles ]

The alert applies to Tor 0.2.0.x and/or any Debian/Ubuntu/related system running any Tor version.

Dingledine warned that a  local attacker or malicious directory cache may be able to trick a client running 0.2.0.x into believing a false directory consensus, causing the client to create a path wholly owned by the attacker.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Critical security alert issued for Tor
This is more about openssl than TOR!!!! (Read the rest)
Posted by: mrOSX Posted on: 06/30/08 You are currently: a Guest | | Terms of Use
Not Only Tor  DrewBuck | 06/30/08
RE: Critical security alert issued for Tor  mrOSX | 06/30/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline