Re: [tor-dev] Is Taking Checksum of Packet Payloads a Vulnerability?

2011-12-19 Thread Nick Mathewson
On Mon, Dec 19, 2011 at 8:54 AM, Paul Syverson wrote: >  Onions, per > se, were never used in Tor (even though Tor's onion routing ;>) As long as we're doing historical notes, let me amend that to "onions, per se, were never used in any

Re: [tor-dev] Is Taking Checksum of Packet Payloads a Vulnerability?

2011-12-19 Thread Paul Syverson
Dave is correct. This attack will not work for the reaseons he said. Just a minor quibble: Dave is not quite correct about the origins of 'onion routing'. We called it that because of a data structure that we used in the original system (and shared by our second generation system and also ZKS Free

[tor-dev] Python SSL/TLS Security enhancement

2011-12-19 Thread Fabio Pietrosanti (naif)
Hi all, following the new Tor2web development based on Python by hellais (ongoing http://github.com/hellais/tor2web) we realized that the Python SSL binding are quite crap. We opened a set of Tickets on Python Issue tracker where i think that the Tor Project Community (that use a lot Python) coul