"someone" on IIP found an anon filter vulnerability. This could let a
malicious freesite author force your browser to load images from the
world wide web and therefore trace your IP address and destroy your
anonymity. It has been fixed in the latest snapshots. Everyone should
upgrade right now. Stable build 5015 and unstable build 6104 are safe
from this issue. I would just like to point out that it is always
possible that we will find new vulnerabilities in the web interface 
like this, and anyone who really values his/her anonymity should take
extra precautions - see the README for some suggestions.

Because the snapshots have been updated, new Windows users will not be
affected. I am releasing 0.5.2.1 immediately, with the fix, and the 
various minor fixes that have accumulated since 0.5.2, because unix
users will continue to install the old version unless they update until
we have a new release.
-- 
Matthew J Toseland - [EMAIL PROTECTED]
Freenet Project Official Codemonkey - http://freenetproject.org/
ICTHUS - Nothing is impossible. Our Boss says so.

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to