Parcourir la source

Safe cookie authentication gets a changes file

Nick Mathewson il y a 13 ans
Parent
commit
9740f067c4
1 fichiers modifiés avec 9 ajouts et 0 suppressions
  1. 9 0
      changes/safecookie

+ 9 - 0
changes/safecookie

@@ -0,0 +1,9 @@
+  o Security Features:
+    - Provide controllers with a safer way to implement the cookie
+      authentication mechanism. With the old method, if another locally
+      running program could convince a controller that it was the Tor
+      process, then that program could trick the contoller into
+      telling it the contents of an arbitrary 32-byte file. The new
+      "SAFECOOKIE" authentication method uses a challenge-response
+      approach to prevent this. Fixes bug 5185, implements proposal 193. 
+