Is Tor still safe to use? | Tor Project

A recent incident involving the de-anonymization of a user running an obsolete version of the Ricochet application highlights the critical importance of maintaining up-to-date privacy software. While specific protections like Vanguard were absent in the legacy code, the attack relied on timing analysis that is now mitigated in current Tor versions. This serves as a stark reminder that software longevity and community-maintained forks are essential for closing security gaps that emerge as threats evolve. The Tor Project emphasizes that the underlying network remains healthy and secure for the vast majority of users. The incident does not reflect a systemic failure but rather the vulnerabilities of discontinued applications lacking modern defenses. By keeping Tor Browser updated and ensuring the network has diverse, robust relay infrastructure, the community significantly reduces the risk of successful surveillance or de-anonymization attacks. This situation is relevant to open data because it underscores the necessity of accessible, transparent, and maintained open-source security tools. The incident illustrates how open collaboration allows for rapid identification and patching of vulnerabilities, ensuring that privacy-preserving technologies remain effective against sophisticated state-level actors. It reinforces the value of open data principles in cybersecurity, where visibility into code and network health metrics enables users to trust the integrity of their digital interactions.

Source: blog.torproject.org
Published on 2024-09-19