Release of the new stable branch Tor 0.4.6

The release of the Tor 0.4.6.5 toolkit is presented, which is used to organize the operation of the anonymous Tor network. Version Tor 0.4.6.5 is recognized as the first stable release of the 0.4.6 branch, which has been developed over the past five months. The 0.4.6 branch will be supported within the normal support cycle — updates will be discontinued in nine months or three months after the release of the 0.4.7.x branch. Long-term support (LTS) is provided for the 0.3.5 branch, with updates being released until February 1, 2022. Simultaneously, releases Tor 0.3.5.15, 0.4.4.9, and 0.4.5.9 have been formed, which eliminate DoS vulnerabilities that can cause denial of service for onion service clients and relays.

Key Changes:

  • The ability to create onion services based on the third version of the protocol with client access authentication through files in the directory ‘authorized_clients’ has been added.
  • A flag has been added for relays that allows the node operator to understand that the relay is not included in the consensus during directory selection (for example, when there are too many relays on one IP address). servers directory.
  • It is now possible to transmit overload information in extrainfo data, which can be used for load balancing in the network. The transmission of metrics is controlled using the OverloadStatistics option in torrc.
  • The DoS protection subsystem has been enhanced with the ability to limit the intensity of client connections to relays.
  • Relays have implemented the publication of statistics regarding the number of onion services based on the third version of the protocol and their traffic volume.
  • Support for the DirPorts option, which is not used for this type of node, has been removed from the relay code.
  • Code refactoring has been carried out. The DoS protection subsystem has been moved to the subsys manager.
  • Support for old onion services based on the second version of the protocol has been discontinued, as it was declared obsolete a year ago. The complete removal of the code related to the second version of the protocol is expected in the fall. The second version of the protocol was developed about 16 years ago and cannot be considered safe due to the use of outdated algorithms in modern conditions. Two and a half years ago, in release 0.3.2.9, users were offered the third version of the protocol for onion services, notable for the transition to 56-character addresses and improved protection against data leakage through servers directories, an expandable modular structure, and the use of SHA3, ed25519, and curve25519 algorithms instead of SHA1, DH, and RSA-1024.
  • Fixed vulnerabilities:
    • CVE-2021-34550 — an out-of-bounds memory access in the code for parsing onion service descriptors based on the third version of the protocol. An attacker can crash any client attempting to connect to this onion service by placing a specially crafted descriptor.
    • CVE-2021-34549 — a potential denial-of-service attack against relays. An attacker can create chains with identifiers that cause collisions in the hash function, processing of which leads to a significant CPU load.
    • CVE-2021-34548 — a relay could spoof RELAY_END and RELAY_RESOLVED cells in half-closed streams, allowing it to terminate a stream that was created without the involvement of that relay.
    • TROVE-2021-004 — additional failure checks have been added when accessing the OpenSSL random number generator (with the default RNG implementation in OpenSSL, such failures do not manifest).

    Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster