The Tor Project
Pentest Report on Tor Browser Applications and Tools
Pages
17
Time to read
28 mins
Publication
Language
English
Pages
17
Time to read
28 mins
Publication
Language
English
This technical report presents the findings from a security assessment conducted by Cure53 on various components of The Tor Project, specifically focusing on censorship circumvention tools, updates to the Tor browser for desktop and Android, and the OnionShare application. The assessment, conducted in January and February 2024, involved a penetration test and a source code audit, building upon previous analyses. The project was structured into four work packages, each targeting different aspects of the Tor ecosystem. Throughout the engagement, a total of twelve security-related findings were documented, with eight classified as vulnerabilities and four as general weaknesses. The report details identified vulnerabilities, including issues related to the Snowflake broker and the rdsys moat, and provides recommendations for mitigating these risks. The findings indicate a generally robust security posture for most components, although the OnionShare application exhibited several significant vulnerabilities that require attention. The report concludes with tailored recommendations for enhancing the security of the examined tools.