Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is...
Moderate severity
Unreviewed
Published
May 24, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 24, 2023
Published to the GitHub Advisory Database
May 24, 2023
Last updated
Apr 4, 2024
Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.
References