David Fifield via tor-project:
I was looking at this 2020 research paper:
https://ieeexplore.ieee.org/document/9343014/
Sci-Hub: are you are robot?
"Napping Guard: Deanonymizing Tor Hidden Service in a Stealthy Way"
Chen Muqian, Wang Xuebin, Shi Jinqiao, Zhao Can, Wang Meiqi, Fang BinxingIn the abstract and introduction, they say:
In addition, we also propose a mitigation of Napping Guard
attack, and report the design flaw to the Tor project.But they don't give details of reporting the flaw or what happened after
that, as far as I can see. Did the reporting happen, and did it result
in changes in Tor?
I am not sure for that one but I could not find anything doing a cursory search in my inbox.
I also noticed this more recent paper by some of the same authors:
https://ieeexplore.ieee.org/document/10570737
"Knock-Knock: De-Anonymise Hidden Services by Exploiting Service Answer Vulnerability"
Zhang Qingfeng, Chen Muqian, Wang Xuebin, Zhao Can, Liu Qingyun, Shi JinqiaoThis one, too, says "Lastly, we present a method to mitigate watermark
attacks and report the design flaw to the Tor Project." Did that happen?
I looked over the mail archive of our security@ alias at least but wasn't able to find that one (but maybe they reported via other mechanisms I am not aware of or I looked not close enough). However, we have brought up that paper at different locations. A public (unresolved) ticket for it is:
Georg
···
_______________________________________________
tor-project mailing list -- tor-project@lists.torproject.org
To unsubscribe send an email to tor-project-leave@lists.torproject.org