Deep packet inspection device purged of flaw that threatened TOR users

Cyberoam, a maker of appliances designed to secure sensitive networks, said it has issued an update to fix a flaw that could be used to intercept communications sent over the TOR anonymity network. Cyberoam issued the hotfix on Monday to a variety of its unified threat management tools. The devices, which are used to inspect individual packets entering or exiting an organization’s network, previously used the same cryptographic certificate. Researchers with the TOR network recently reported the flaw and said it caused a user to seek a fake certificate for thetorproject.org when one of the DPI (or deep packet inspection) devices was being used to monitor his connection. “Examination of a certificate chain generated by a Cyberoam DPI device shows that all such devices share the same CA certificate and hence the same private key,” TOR researcher Runa A. Sandvik wrote in a blog post published last Tuesday .

More:
Deep packet inspection device purged of flaw that threatened TOR users

You might also like

Deep packet inspection soon to be $1.5 billion business
Deep packet inspection (DPI) hardware continues to sell, with ABI Research now estimating that vendors...

Deep packet inspection engine goes open source
Deep packet inspection (DPI) hardware can identify an astonishing array of protocols passing across...

Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
Following a report last week that Iran is spying on domestic internet users with western-supplied technology,...

Deep Packet Inspection: netscapes of power
If you’re a p2pnet regular you’ll recognise the name Christopher Parsons. He’s working...

Tags: , , , , , , , , , ,

Monday, July 9th, 2012 Net News

Leave a Reply

Your email address will not be published. Required fields are marked *

HTML tags are not allowed.