[tor-project] Re: "Napping Guard" (2020)—was it reported to Tor?

David Fifield via tor-project:

I was looking at this 2020 research paper:

https://ieeexplore.ieee.org/document/9343014/
Sci-Hub: are you are robot?
"Napping Guard: Deanonymizing Tor Hidden Service in a Stealthy Way"
Chen Muqian, Wang Xuebin, Shi Jinqiao, Zhao Can, Wang Meiqi, Fang Binxing

In the abstract and introduction, they say:

  In addition, we also propose a mitigation of Napping Guard
  attack, and report the design flaw to the Tor project.

But they don't give details of reporting the flaw or what happened after
that, as far as I can see. Did the reporting happen, and did it result
in changes in Tor?

I am not sure for that one but I could not find anything doing a cursory search in my inbox.

I also noticed this more recent paper by some of the same authors:

https://ieeexplore.ieee.org/document/10570737
"Knock-Knock: De-Anonymise Hidden Services by Exploiting Service Answer Vulnerability"
Zhang Qingfeng, Chen Muqian, Wang Xuebin, Zhao Can, Liu Qingyun, Shi Jinqiao

This one, too, says "Lastly, we present a method to mitigate watermark
attacks and report the design flaw to the Tor Project." Did that happen?

I looked over the mail archive of our security@ alias at least but wasn't able to find that one (but maybe they reported via other mechanisms I am not aware of or I looked not close enough). However, we have brought up that paper at different locations. A public (unresolved) ticket for it is:

Georg

···

_______________________________________________

tor-project mailing list -- tor-project@lists.torproject.org
To unsubscribe send an email to tor-project-leave@lists.torproject.org

1 Like