Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-06 Thread Mike Perry
On 2/6/20 5:54 AM, George Kadianakis wrote: > > David Goulet writes: > >> On 04 Feb (19:03:38), juanjo wrote: >> >> Greetings! >> >>> Since no one is posting it here and talking about it, I will post it. >>> >>> https://nvd.nist.gov/vuln/detail/CVE-2020-8516 >>> >>> The guy: >>> http://www.hack

Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-06 Thread George Kadianakis
David Goulet writes: > On 04 Feb (19:03:38), juanjo wrote: > > Greetings! > >> Since no one is posting it here and talking about it, I will post it. >> >> https://nvd.nist.gov/vuln/detail/CVE-2020-8516 >> >> The guy: >> http://www.hackerfactor.com/blog/index.php?/archives/868-Deanonymizing-Tor

Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-05 Thread Mike Perry
On 2/4/20 3:15 PM, David Goulet wrote: > > On 04 Feb (19:03:38), juanjo wrote: > > Greetings! > >> Since no one is posting it here and talking about it, I will post it. >> >> https://nvd.nist.gov/vuln/detail/CVE-2020-8516 >> >> The guy: >> http://www.hackerfactor.com/blog/index.php?/archives/86

Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-04 Thread s7r
juanjo wrote: > Since no one is posting it here and talking about it, I will post it. > > https://nvd.nist.gov/vuln/detail/CVE-2020-8516 > > The guy: > http://www.hackerfactor.com/blog/index.php?/archives/868-Deanonymizing-Tor-Circuits.html > > > Is this real? > > Are we actually not verifying

Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-04 Thread Paul Syverson
On Tue, Feb 04, 2020 at 04:15:23PM -0500, David Goulet wrote: > On 04 Feb (19:03:38), juanjo wrote: > [snip] > > And the reason for private nodes is probably because this way you eliminate > noise from other tor traffic so _anything_ connecting back to your ORPort is > related to the onion servic

Re: [tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-04 Thread David Goulet
On 04 Feb (19:03:38), juanjo wrote: Greetings! > Since no one is posting it here and talking about it, I will post it. > > https://nvd.nist.gov/vuln/detail/CVE-2020-8516 > > The guy: > http://www.hackerfactor.com/blog/index.php?/archives/868-Deanonymizing-Tor-Circuits.html > > Is this real? >

[tor-dev] CVE-2020-8516 Hidden Service deanonymization

2020-02-04 Thread juanjo
Since no one is posting it here and talking about it, I will post it. https://nvd.nist.gov/vuln/detail/CVE-2020-8516 The guy: http://www.hackerfactor.com/blog/index.php?/archives/868-Deanonymizing-Tor-Circuits.html Is this real? Are we actually not verifying if the IP of the Rend is a node i