[Return]

Report a post

Preview
>This release contains fixes for CVE-2023-36325. CVE-2023-36325 is a context-confusion bug which occurred in the bloom filter. An attacker crafts an I2NP message containing a unique messageID, and sends that messageID to a client. The message, after passing through the bloom filter, is not allowed to be re-used in a second message. The attacker then sends the same message directly to the router. The router passes the message to the bloom filter, and is dropped. This leaks the information that the messageID has been seen before, giving the attacker a strong reason to believe that the router is hosting the client
TLDR: there was an exploit that allowed attackers to deanonymize server hosts which caused most Darknet services to stop hosting on i2p which killed the whole project
https://geti2p.net/en/blog/post/2023/06/25/new_release_2.3.0
Post number No.143097
Board Off-Topic@Heyuri
Optional. Describe what's wrong with it.