Code audit for the Tor Project completed by Radically Open Security
by 34585 - Tuesday February 6, 2024 at 07:19 AM
#1
Code audit for the Tor Project completed by Radically Open Security
https://blog.torproject.org/code-audit-t...omponents/

by pavel | January 29, 2024

Between April 17, 2023, and August 13, 2023, Radically Open Security conducted a comprehensive code audit for the Tor Project, including reporting and optional retesting.

The code audit focused on several components of the Tor ecosystem:

    Tor Browser and Tor Browser for Android,
    Exit relays (Tor core),
    Exposed services (metrics server, SWBS, Onionoo API),
    Infrastructure components (monitoring & alert), and testing/profiling tools.

The primary objective was to assess software changes made to improve the Tor network's speed and reliability and a number of recommendations were made such as:

    Reducing the potential attack surface of the public-facing infrastructure,
    Addressing outdated libraries and software,
    Implementing modern web security standards,
    And following redirects in all HTTP clients by default.

Additionally, fixing issues related to denial-of-service vulnerabilities, local attacks, insecure permissions, and insufficient input validation was deemed imperative.

We would like to thank Radically Open Security for performing the audit and the U.S. State Department Bureau of Democracy, Human Rights, and Labor (DRL) for sponsoring this project and 'Making the Tor network faster & more reliable for users in Internet-repressive places’.
For more details and information, please access the complete audit report here.

https://blog.torproject.org/code-audit-t...2023%201.0
Reply
#2
Interesting that a CSRF was labeled as the most high threat vulnerability in the report. I guess because bridges can be injected it increases the threat level. Either a good or bad sign the lack of more serious vulnerabilities.
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: None
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  ? Bill Gates Shares Microsoft’s Original Source Code Teko 4 392 08-05-2025, 04:54 AM
Last Post: arin
  EU presents strong actions to enhance security of submarine cables ewxrbg 0 462 02-25-2025, 12:51 PM
Last Post: ewxrbg
  Tails OS Had a Critical Security Bug (Mental Outlaw) MushroomQueen 1 658 01-26-2025, 05:49 AM
Last Post: Zix
  Critical 7-Zip Vulnerability Let Attackers Execute Arbitrary Code v12run 1 872 11-26-2024, 08:01 AM
Last Post: dope_dealer
  Canada orders shutdown of TikTok offices over security risks (but won’t block app) KingDice 0 1,059 11-10-2024, 08:40 AM
Last Post: KingDice

Forum Jump:


 Users browsing this thread: 1 Guest(s)