#7277: timestamp leaked in TLS client hello
------------------------+---------------------------------------------------
 Reporter:  proper      |          Owner:                    
     Type:  defect      |         Status:  new               
 Priority:  normal      |      Milestone:  Tor: 0.2.5.x-final
Component:  Tor         |        Version:                    
 Keywords:  tor-client  |         Parent:                    
   Points:              |   Actualpoints:                    
------------------------+---------------------------------------------------

Comment(by arma):

 Hey, isn't the timestamp in the clienthello (and serverhello), and thus
 visible to external observers too?

 So a) a passive adversary of the client can do this tracking too, not just
 the guard

 and b) if we stop putting (something similar to) the time there, we have
 introduced an "is it tor tls or other tls" identifier.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7277#comment:9>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
[email protected]
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Reply via email to