Igatsha elisha elizinzile leTor 0.4.1 selivele lethulwe

Ezinsukwini ezimbalwa ezedlule yethulwe ngeposi le-Tor Tor, futhil Ukwethulwa kwamathuluzi we-Tor 0.4.1.5 isetshenziselwe ukuhlela umsebenzi wenethiwekhi yeTor engaziwa.

Le nguqulo entsha ye I-Tor 0.4.1.5 yamukelwa njengenguqulo yokuqala ezinzile yegatsha le-0.4.1, lokho sekuthuthukile ezinyangeni ezine ezedlule. Igatsha 0.4.1 izohambisana nomjikelezo ojwayelekile wesondlo: ukukhishwa kwezibuyekezo kuzomiswa izinyanga eziyi-9 noma izinyanga ezi-3 ngemuva kokukhishwa kwegatsha 0.4.2 futhi ngaphezu kwalokho kunikezwa umjikelezo omude wokusekela (LTS) yegatsha 0.3.5, izibuyekezo zazo ezizokhishwa kuze kube nguFebhuwari 1, 2022.

Okwalabo namanje abangazi ngephrojekthi yeTor (Umzila we-anyanisi). Le phrojekthi inhloso yayo enkulu ukuthuthukisa inethiwekhi yezokuxhumana isatshalaliswa nge-latency ephansi futhi ifakwe phezulu ku-inthanethi, lapho ukuhanjiswa kwemiyalezo eshintshwe phakathi kwabasebenzisi kungakhombisi ubunikazi babo, okungukuthi, ikheli laso le-IP (ukungaziwa ezingeni lenethiwekhi) nokuthi, ngaphezu kwalokho, kugcina ubuqotho nokufihla kolwazi oluhamba ngalo.

Isistimu yakhelwe ngokuguquguquka okudingekayo ukuze ikwazi ukuthuthuka, isetshenziswe emhlabeni wangempela futhi ikwazi ukumelana nezinhlobo ezahlukene zokuhlaselwa. Noma kunjalo, inamaphuzu abuthakathaka futhi ayinakuthathwa njengohlelo olungenangqondo.

Yini okusha egatsheni elisha leTor 0.4.1

Ngokukhishwa kwaleli gatsha elisha elizinzile, ukwesekwa kokuhlola kokugcwaliswa okwengeziwe ezingeni leketanga kwenziwa, okuvumela ukuqinisa ukuvikelwa kuzindlela zokunquma ithrafikhi yeTor.

Iklayenti manje lingeza amaseli e-padding ekuqaleni kwezintambo ze-INTRODUCE ne-RENDEZVOUS, okwenza ithrafikhi kulezi zintambo ifane nethrafikhi ejwayelekile ephumayo.

Ngenkathi i ukuvikelwa okuthuthukisiwe ukwengezwa kwamaseli amabili angeziwe ohlangothini ngalunye lwezintambo ze-RENDEZVOUS, kanye neseli elikhulu kanye namaseli ayi-10 amakhulu ezintambo ZESINGENISO. Indlela iyasha lapho i-MiddleNode icacisiwe ekucushweni futhi ingakhutshazwa kusetshenziswa inketho ye-CircuitPadding.

Kungezwe ukusekelwa kwamaseli we-SENDME aqinisekisiwe ukuvikela ekuhlaselweni kwe-DoS ngokususelwa kumthwalo lapho iklayenti licela ukulanda amafayela amakhulu futhi iyeke ukusebenza kokufunda ngemuva kokuthumela izicelo, kepha iyaqhubeka nokuthumela imiyalo yokulawula ye-SENDME eyalela ama-node wokufaka ukuqhubeka nokudlulisa idatha.

Iseli ngalinye le-SENDME manje lifaka i-hash yomgwaqo, eqinisekisa futhi i-node yokugcina, lapho ithola iseli le-SENDME, ingaqinisekisa ukuthi olunye uhlangothi seluvele luyitholile ithrafikhi ethunyelwe ngokucubungula amaseli adlulisiwe.

Uhlaka lufaka phakathi ukwenziwa kohlelo olungaphansi lokuthumela imiyalezo ngemodi yokubhalisa yomshicileli, engasetshenziselwa ukuhlela ukuxhumana ngaphakathi kwemodyuli.

Ukuhlaziya imiyalo yokulawula, isistimu esezansi yokuhlaziya isetshenziswa esikhundleni sokuhlaziywa okuhlukile kwedatha yokufaka yomyalo ngamunye.

La ukusebenza kahle Kwenziwe ukunciphisa umthwalo ku-CPU. UTor manje usebenzisa i-generator mbumbulu engahleliwe yenombolo (PRNG) ekusakazeni ngakunye, okususelwa ekusetshenzisweni kwemodi yokubethela ye-AES-CTR kanye nokusetshenziswa kokwakhiwa kokubhafa okufana nelabhulali nekhodi entsha ye-OpenBSD arc4random ()

De ezinye izinguquko ezimenyezelwe kuleli gatsha, singathola:

  • Ngokukhipha okuncane, i-generator ehlongozwayo icishe iphindwe kashumi kune-OpenSSL 100's CSPRNG.
  • Ngaphandle kokuthi i-PRNG entsha ihlolwe ngabathuthukisi beTor njenge-crypto ethembekile, kuze kube manje isetshenziswa kuphela ezindaweni ezidinga ukusebenza okuphezulu, ngokwesibonelo kwikhodi ukuhlela okunamathiselwe okungeziwe kwephedi.
  • Kungezwe inketho ye- "–list-modules" ukubonisa uhlu lwamamojula afakiwe
  • Ngenguqulo yesithathu yenqubo elandelwayo yezinsizakalo, umyalo we-HSFETCH usetshenzisiwe, ngaphambili owawusekelwa kuphela kunguqulo yesibili.
  • Ama-bugs alungisiwe kukhodi yokuqalisa ye-Tor (bootstrap) nokusebenza kwenguqulo yesithathu ye-protocol yezinsizakalo ezifihliwe.

Umthombo: https://blog.torproject.org/


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.