过去几年,Tor 项目一直致力于扩展其移动隐私保护产品,包括开发 TorVPN 及其配套组件。这项工作旨在让更多人能够使用基于 Tor 的隐私保护,同时保持强大的安全保障。ftV免费翻墙网
作为这项工作的一部分,Cure53 于 2025 年 6 月对 TorVPN for Android 进行了渗透测试和源代码审计。ftV免费翻墙网
评估涵盖了 Android 应用程序和负责 DNS 解析和流量处理的底层 Onionmasq 网络层。ftV免费翻墙网
审计结果
审计工作主要涵盖两个方面:ftV免费翻墙网
主要发现
审计发现 Tor 的核心集成依然稳健,隧道建立和路由方面不存在根本性问题。大多数问题集中在两个方面:输入验证不完整以及 DNS 处理方面的缺陷,这些缺陷在某些罕见情况下可能导致拒绝服务攻击。ftV免费翻墙网
其他问题包括加密加固建议(例如证书绑定和随机性),以及典型的移动安全问题,例如明文配置存储和缺乏 root 检测。ftV免费翻墙网
下一步
所有发现的问题都已被跟踪,并将作为持续安全工作的一部分加以解决。此次审计有助于确定改进的优先顺序,包括验证、资源管理以及使用成熟的库来实现安全关键功能。ftV免费翻墙网
阅读完整审计报告
如需了解详细的调查结果和建议,请点击此处查看完整的审计报告。ftV免费翻墙网
Over the past several years, the Tor Project has been working to expand its mobile privacy offerings, including the development of TorVPN and its supporting components. This work is aimed at making Tor-based protections more accessible while maintaining strong security guarantees.ftV免费翻墙网
As part of this effort, in June 2025, Cure53 conducted a penetration test and source code audit of TorVPN for Android.ftV免费翻墙网
The assessment covered both the Android application and the underlying Onionmasq networking layer responsible for DNS resolution and traffic handling.ftV免费翻墙网
Audit findings
The audit covered two primary areas:ftV免费翻墙网
-
TorVPN for Android: the mobile application responsible for routing device traffic through the Tor networkftV免费翻墙网
-
Onionmasq / Tunnel Interface for Arti: the Ruse-based networking tunnel layer handling low-level network traffic forwarding, including TCP/UDP parsing, DNS resolution, and routing to the Tor network through Arti.ftV免费翻墙网
Key findings
The audit found that Tor’s core integration remains robust, with no fundamental issues in tunnel establishment or routing. Most findings instead cluster around two areas: incomplete input validation and weaknesses in DNS handling that could enable denial-of-service conditions in certain rare conditions.ftV免费翻墙网
Additional issues included cryptographic hardening suggestions (such as certificate pinning and randomness), and typical mobile security concerns like plaintext configuration storage and lack of root detection.ftV免费翻墙网
Next steps
All findings are being tracked and addressed as part of ongoing security work. This audit helps prioritize improvements around validation, resource management, and the use of established libraries for security-critical functionality.ftV免费翻墙网
Read the full audit report
For detailed findings and recommendations, please see the complete audit report hereftV免费翻墙网
https://blog.torproject.org/code-audit-tor-vpn/ftV免费翻墙网