4 ms·
> additional layer of confidentiality and authentication and additional layers of attack surfaces
by ynezz 9y ago
> additional layer of confidentiality and authentication
and additional layers of attack surfaces
- belorn 9y agoFrom a IT Security Assessment, what would those be and their associated risk and impact factors? One would naturally be the onion address. If they could break the 1024 bit RSA key, they could hijack the name. Risk of this happening: very low. Impact: massive especially outside the realm of tor. Any additional risks you were thinking about? Backdoors in tor project? Hardware malware specifically designed for tor (rather than than being general)?
- Ajedi32 9y agoI believe the main concern would be vulnerabilities in the Tor software itself. That said, I don't think there's any reason to believe Tor is any more likely to be vulnerable than any other software in your stack. The project is open source, and is very much written with a focus on security and privacy.