#25574 new defect

Eliminate "silent-drop" side channels in Tor protocol — at Version 4

There are lots of ways to inject data into Tor streams, and this is a vector of attack for guard discovery and confirmation ("DropMark" attack):

I have a branch that tries to eliminate a pile of these from a while ago, but it has lots of false positives due to the common occurrence of invalid stream IDs in practice (see #25573).

I think we may want to do #25573 before trying to merge that branch.

#25573closedTrack half-closed stream IDsCore Tor/Tor

comment:1

I really want to ask for a proposal on this -- if only a formal list of the stuff you want to change here.

comment:2

comment:3

comment:4

Adding parenthetical to tie that term 'DropMark' to the paper (it might not otherwise be obvious by context).

