From 9740f067c4bed47beb63483be4f4636167a04019 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Mon, 26 Mar 2012 14:06:27 -0400 Subject: [PATCH] Safe cookie authentication gets a changes file --- changes/safecookie | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 changes/safecookie diff --git a/changes/safecookie b/changes/safecookie new file mode 100644 index 0000000000..fd7d7af2b0 --- /dev/null +++ b/changes/safecookie @@ -0,0 +1,9 @@ + o Security Features: + - Provide controllers with a safer way to implement the cookie + authentication mechanism. With the old method, if another locally + running program could convince a controller that it was the Tor + process, then that program could trick the contoller into + telling it the contents of an arbitrary 32-byte file. The new + "SAFECOOKIE" authentication method uses a challenge-response + approach to prevent this. Fixes bug 5185, implements proposal 193. + -- 2.47.3