this post was submitted on 30 Jan 2024
115 points (99.1% liked)

Technology

59534 readers
3195 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Summary:

Radically Open Security conducted a comprehensive code audit for the Tor Project between April 17, 2023, and August 13, 2023. The audit covered various components of the Tor ecosystem, including Tor Browser, exit relays, exposed services, and infrastructure components. The main goals were to assess software changes aimed at improving the Tor network's speed and reliability. Recommendations included reducing the attack surface of public-facing infrastructure, addressing outdated libraries, implementing modern web security standards, and following redirects in HTTP clients by default. The audit also emphasized fixing issues related to denial-of-service vulnerabilities, local attacks, insecure permissions, and insufficient input validation. The U.S. State Department Bureau of Democracy, Human Rights, and Labor sponsored the project, aiming to enhance the Tor network's performance and reliability in regions with internet repression.

top 3 comments
sorted by: hot top controversial new old
[–] db2@lemmy.world 4 points 9 months ago (1 children)

and following redirects in HTTP clients by default

So to be more secure a site can go to a different site via redirect.. that doesn't seem like a super great idea.

[–] deur@feddit.nl 28 points 9 months ago* (last edited 9 months ago) (1 children)

The summary incorrectly describes what's happening.

From the report, http redirects being default is an attack surface they identified as needing a solution, not a suggested action.

[–] db2@lemmy.world 9 points 9 months ago

That's much more reassuring. It really didn't make sense. 😆