TOR issues updated software after server breach
- 25 January, 2010 06:28
- Comments
The TOR Project is advising users to upgrade to a new version of the software following a hack that compromised three of its servers.
TOR, short for "The Onion Router," is a worldwide network of servers that are used to help anonymize people's Web surfing. Web traffic is randomly routed through many servers, masking critical information such as someone's true IP (Internet Protocol) address.
TOR is often used by people who want to enhance their privacy while surfing the Internet, as IP addresses are an important piece of information to collect when monitoring Internet traffic.
Web sites will record the IP address of the last exit point out of the TOR network, which could make it appear users have an IP address from a Brazilian ISP when they are actually in Germany.
The attack did not appear to be specifically aimed at disrupting TOR or compromising people's privacy, wrote Roger Dingledine, the project's director.
Two of the seven directory authorities, which hold a list of nodes in the TOR network, were hacked along with another server that recorded statistics about TOR.
"It appears the attackers didn't realize what they broke into," Dingledine wrote. "It seems we were attacked for the CPU capacity and bandwidth of the servers, and the servers just happened to also carry out functions for TOR."
The project's operators have refreshed identity keys for the two directory authorities, which means people also need to upgrade their TOR clients to versions Tor 0.2.1.22 or 0.2.2.7-alpha.
"We've taken steps to fix the weaknesses identified and to harden our systems further," Dingledine wrote.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
-
Dymocks taps Android for e-book, tablet move
-
Droid Razr Maxx: An Android smartphone for big talkers
-
Lenovo ordered to pay €1920 for making French laptop buyer pay for Windows too
-
Wikileaks suspect to face US court-martial
-
Wikileaks suspect to face US court-martial
-
J2EE Best Practices
-
Advanced Web Metrics with Google Analytics
-
Windows 7 Secrets
-
Pocket Pcs! I Didn't Know You Could Do That... (Includes CD-ROM)
-
Building the Knowledge Management Network
-
Professional SQL Server 2008 Internals and Troubleshooting
-
Business Objects Software Solutions
-
Sensing, Intelligence, Motion
-
Linux Bible 2005 Edition











Comments
Post new comment