I'd rather that fewer people understand how to break tor, as opposed to more. There's a middle ground which may be better, but on the open-source/classified spectrum I'm a little right-leaning on this one. Thoughts?
I'd rather that fewer people understand how to break tor, as opposed to more. There's a middle ground which may be better, but on the open-source/classified spectrum I'm a little right-leaning on this one. Thoughts?
The entire reasoning behind using tor is for anonymity, and we don't know what this exploit is exactly or how serious it is.
If that's the case the exploit is intrinsically linked to the way tor works, and there may be no patching possible.
I'ma need someone to fact-check me because I'm semi-busy right now and I don't have the article on-hand.
Then you should be opposed to this! If the fbi shares the exploit, tor will patch it. As is, this vulnerability in tor puts its users at risk, both from the fbi and from anyone else who has found the exploit.
The FBI doesn't want the vulnerability to be fixed though, which is why they classified it.
If the exploit were in the protocol itself then that might not have been viable, but the facts of the case suggest it's an implementation level exploit, in which case the FBI choosing to hoard it actually does increase the chance of more people (even outside of the American intel community) gaining access to the exploit.
Releasing it would almost certainly lead to it being fixed very soon.
That is ridiculous. The more people who try to break Tor, succeed and tell the Tor Project how they did it, the safer Tor (and Firefox) become. The Tor Project relies on the security research community to find attacks on Tor so that they can be fixed. Same goes for all software in general.