In Arti 1.1.12, the implementation of Tor in Rust, testing of onion services has begun.

The developers of the anonymous Tor network have released version Arti 1.1.12, which develops the Tor client written in Rust. The 1.x branch is marked as suitable for use by regular users and provides the same level of privacy, usability, and stability as the main implementation in C. The code is distributed under the Apache 2.0 and MIT licenses.

Unlike the C implementation, which was initially designed as a SOCKS proxy and later adapted for other needs, Arti is being developed as a modular, embeddable library that various applications can use from the outset. Additionally, the entire past experience of Tor development is taken into account in the development of this new project, allowing known architectural issues to be avoided and making the project more modular and efficient. When the Rust code reaches a level capable of fully replacing the C version, the developers plan to promote Arti to the status of the main Tor implementation and discontinue support for the C version.

The reason for rewriting Tor in Rust is mentioned as the desire to achieve a higher level of code security by using a language that ensures safe memory handling. According to Tor developers, at least half of all vulnerabilities tracked by the project will be eliminated in the Rust implementation if 'unsafe' blocks are not used in the code. Rust will also allow for a faster development speed compared to C due to the expressiveness of the language and strict guarantees that prevent time wastage on double checks and unnecessary code writing.

Version Arti 1.1.12 is notable for bringing the implementation of onion services to the point of readiness for testing and experimentation. With Arti, it is now possible not only to connect to existing onion services but also to create your own onion services. However, some privacy and security features for onion services, such as client authorization, protection against DoS attacks, and the mechanism to prevent identification of Guard nodes called 'Vanguard', are still not ready, so the implementation is not yet recommended for production deployments.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster