Ukukhutshwa kwesebe elitsha elizinzileyo leTor 0.4.1

Yaziswa ukukhululwa kwezixhobo Intambo 0.4.1.5, esetyenziselwa ukulungelelanisa ukusebenza kwenethiwekhi yeTor engaziwa. I-Tor 0.4.1.5 yamkelwa njengokhululo lokuqala oluzinzileyo lwesebe le-0.4.1, eliphuhliswe kwiinyanga ezine ezidlulileyo. Isebe 0.4.1 liya kugcinwa njengenxalenye yomjikelo wolondolozo rhoqo - uhlaziyo luya kuyekwa emva kweenyanga ezisi-9 okanye iinyanga ezi-3 emva kokukhululwa kwesebe le-0.4.2.x. Inkxaso yexesha elide (LTS) ibonelelwe kwisebe le-0.3.5, uhlaziyo oluya kukhutshwa kude kube ngumhla woku-1 kuFebruwari 2022.

Iinguqulelo eziphambili:

  • Inkxaso yovavanyo ye-padding-level-level padding iphunyeziwe ukunyusa ukhuseleko kwiindlela zokubona i-Tor traffic. Umxhasi ngoku wongeza iiseli zepadding ekuqaleni kwamatyathanga INTSHAYELELA kunye ne-RENDEZVOUS, ukwenza itrafikhi kula matyathanga ifane ngakumbi nesiqhelo esiphumayo. Iindleko zokukhuselwa okwandisiweyo kukongezwa kweeseli ezimbini ezongezelelweyo kwicala ngalinye kwiiketango ze-RENDEZVOUS, kunye nenye phezulu kunye neeseli ze-10 ezisezantsi ze-INTRODUCE chains. Indlela iyasebenza xa ukhetho lweMiddleNodes lukhankanyiwe kwizicwangciso kwaye lunokukhutshazwa ngokhetho lweSekethePadding;

    Ukukhutshwa kwesebe elitsha elizinzileyo leTor 0.4.1

  • Yongeziwe inkxaso yeeseli ze-SENDME eziqinisekisiweyo ukukhusela Ukuhlaselwa kweDoS, ngokusekelwe ekudalweni komthwalo we-parasitic kwimeko apho umxhasi ucela ukukhutshelwa kweefayile ezinkulu kunye nokumisa imisebenzi yokufunda emva kokuthumela izicelo, kodwa uqhubeka nokuthumela imiyalelo yokulawula ye-SENDME eyala ii-nodes zokufaka ukuqhubeka nokudlulisa idatha. Iseli nganye
    I-SENDME ngoku iquka i-hash ye-traffic eyivumayo, kunye nesiphelo se-node ekufumaneni iseli ye-SENDME inokuqinisekisa ukuba elinye iqela sele liyifumene i-traffic ethunyelwe xa kusetyenzwa iiseli ezidlulileyo;

  • Ulwakhiwo lubandakanya ukuphunyezwa kwe-subsystem ngokubanzi yokuhambisa imiyalezo kwimodi yomshicileli-umrhumo, ongasetyenziselwa ukuququzelela ukusebenzisana kwe-intra-modular;
  • Ukwahlulahlula imiyalelo yolawulo, inkqubo esezantsi yokwahlulahlula ngokubanzi isetyenziswa endaweni yokwahlulahlula okwahlukileyo kwedatha yegalelo lomyalelo ngamnye;
  • Ukulungiswa kokusebenza kuye kwenziwa ukunciphisa umthwalo kwi-CPU. I-Tor ngoku isebenzisa i-fast pseudo-random number generator (PRNG) kwintambo nganye, esekelwe ekusebenziseni i-AES-CTR imodi yokufihla kunye nokusetyenziswa kwe-buffering yakha njenge-libottery kunye ne-arc4random entsha () ikhowudi esuka kwi-OpenBSD. Kwidatha encinci yemveliso, i-generator ecetywayo iphantse yamaxesha angama-1.1.1 ngokukhawuleza kune-CSPRNG esuka kwi-OpenSSL 100. Nangona i-PRNG entsha ilinganiswe njenge-cryptographically enamandla ngabaphuhlisi beTor, okwangoku isetyenziswa kuphela kwiindawo ezifuna ukusebenza okuphezulu, njengekhowudi yokucwangcisa i-padding attachment;
  • Ukhetho olongezelelweyo "--list-modules" ukubonisa uluhlu lweemodyuli ezenziwe ukuba zisebenze;
  • Kwinguqulo yesithathu yeprotocol yeenkonzo ezifihliweyo, umyalelo we-HSFETCH uphunyeziwe, owawuxhaswa ngaphambili kuphela kwinguqulo yesibini;
  • Iimpazamo zilungisiwe kwikhowudi yokuqaliswa kweTor (i-bootstrap) kunye nokuqinisekisa ukusebenza kwenguqulo yesithathu yeprotocol yeenkonzo ezifihliweyo.

umthombo: opennet.ru

Yongeza izimvo