惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
I
InfoQ
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
博客园_首页
罗磊的独立博客
V
V2EX
李成银的技术随笔
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
True Tiger Recordings
Vercel News
Vercel News
Cyberwarzone
Cyberwarzone
Cisco Talos Blog
Cisco Talos Blog
F
Fox-IT International blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
M
Microsoft Research Blog - Microsoft Research
Know Your Adversary
Know Your Adversary
爱范儿
爱范儿
The Register - Security
The Register - Security
G
Google Developers Blog
The Hacker News
The Hacker News
Malwarebytes
Malwarebytes
S
Securelist
博客园 - 三生石上(FineUI控件)
Jina AI
Jina AI
T
Threat Research - Cisco Blogs
T
The Exploit Database - CXSecurity.com
S
SegmentFault 最新的问题
博客园 - 叶小钗
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
博客园 - 聂微东
T
Threatpost
博客园 - 【当耐特】
D
Docker
P
Privacy & Cybersecurity Law Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
G
GRAHAM CLULEY
V
Visual Studio Blog
C
Cisco Blogs
IT之家
IT之家
S
Security Archives - TechRepublic
Latest news
Latest news
阮一峰的网络日志
阮一峰的网络日志

Latest from TechRadar

The Pope just warned AI could create ‘new forms of dehumanization’ — and his message feels aimed straight at Big Tech Ghost CMS flaw hijacked to target hundreds of websites with ClickFix attacks — here's how to stay safe 'It's something we've never done before': Logitech's newest flagship mouse and keyboard comes… What is the release date for The Four Seasons season 2 on Netflix? 007 First Light delivers a blockbuster Bond origin story packed with spycraft, stealth and explosive action set pieces Geekom A9 Max mini PC (2026) review: The latest update to the powerful AI mini PC is a desktop-class computer with workstation-level performance Adorama's Memorial Day sale is ending soon — don't miss these record-low prices on the Nikon Z6 III, Sony a7CR, Canon R5 Mark II, and much more Arkane devs say the studio almost made Thief 4 and a Blade Runner game before it made Dishonored — 'We were both so excited. Blade Runner and Thief, two of our favourite things of all time' 'Somehow worse than I could ever have imagined': the new Ferrari Luce EV is getting a brutal reception, but legendary Apple designer Jony Ive has defended his choices — and there's one key decision most people agree with AI-generated threats are hitting businesses harder than ever - do you know what to look out for? The best Nintendo Switch 2 controllers: the handheld hybrids top gamepads, all tested and reviewed by us Microsoft promised it would scale back on AI visibility, but Copilot is now back to its original and invasive sidebar design Apple is introducing useful accessibility features in tvOS 27 for Apple TV 4K that will appeal to everyone, including larger text and auto-generated subtitles — but some major streaming apps don't use Apple's own app tech that enables them Is this the Honey scandal all over again? Motorola phones caught adding affiliate codes to Amazon orders Next boss says 'dramatic' fall in entry-level roles could cause job market chaos — Lord Wolfson says fall highlights 'the crisis is in youth unemployment at the moment' Why health AI needs a new approach, not just smarter algorithms Sennheiser finally launches the successor to its ultra-popular 5-star Momentum wireless headphones, and adds in great new features including Dolby Atmos — Sony and Bose have some hot competition here How .BRANDs improve domain security and user trust – even in an AI world 'ChatGPT kind of sucked' — Former Assassin's Creed director says he used AI to help him learn to… Are cyber pros fooling themselves with skills development? What is the release date for Rivals season 2 episode 5 on Hulu and Disney+? I gamed with MSI's new 4K QD-OLED monitor and it was the eye-popping HDR experience I've been waiting for 'Downtime is inevitable; prolonged disruption is not': Unplanned downtime is now costing businesses billions… Sihoo Doro C300 Pro V2 review: A robust ergonomic office chair with more features than you probably know what to do with 9 fantastic fans to help you beat the heat — recommended by a former fan tester How to watch RCB vs Gujarat Titans: live stream 2026 IPL Qualifier from anywhere Lowest ever price for the 'brilliantly budget' Corsair gaming and office chair — now £128 at… ‘When things are moving fast, people make mistakes — and those mistakes cost’: Formula 1 fans are doing everything they can to watch motorsport, but it might cost them more than they'd expect What Sudoku reveals about the limits of LLMs AI agents are creating a major security blind spot in financial services New Apple TV sci-fi series Star City will be 'totally different' to For All Mankind season 5 despite having the same creative team — 'we wouldn't have made it if it was a companion piece' This air fryer with steam functionality at its lowest price makes me want to upgrade from my older model The M4 iPad Air is powerful, but I'd recommend this Apple tablet instead Forget stolen passwords — this is how hackers are actually breaking into US companies in 2026 Kansas City Public Schools is spending millions on MacBook Neos to replace 30,000 Windows PCs and Chromebooks and become… NYT Strands hints and answers for Tuesday, May 26 (game #814) NYT Connections hints and answers for Tuesday, May 26 (game #1080) Quordle hints and answers for Tuesday, May 26 (game #1583) 'Built for the boss': X-Chair's luxury office chair deals have landed for Memorial Day — and these… I’ve driven the smallest Kia EV yet and there’s a lot to love about the baby of the bunch 'Security of your network is essential to security of your robot': Industrial robots targeted by malware,… New 'scareware' attack hits 2.8 million victims, pretending to lock them out of your browser — here’s how you can stay safe I test ThinkPads for a living and these are the best 14-inch business laptop deals for professionals and power users in Lenovo's Memorial Day sale Best Buy's Memorial Day video editing laptop and PC deals end in a matter of hours — and they're packed with DDR5 memory, and RTX 5060, 5070, and 5080 graphics cards that are perfect for content creators FBI warns of Kali phishing scam hitting Microsoft OAuth tokens — warns 'Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures' How to watch the 2026 American Music Awards online — stream Teddy Swims, Keith Urban performances live from… Amazon’s Memorial Day Lego sale is packed with Star Wars, Botanicals, Art, and Creator set deals – but… You think your World Cup TV setup is good? This custom 9.4.4-channel Dolby Atmos home theater was designed for sports, with a unique smart 'Football Mode' and powerful sound that's probably louder than a real stadium crowd The Many Lives of Benjaman Kyle on HBO Max had Natalia Grace producer 'in tears' after man found naked behind Burger King with total amnesia couldn't remember past — 'I felt like I was never going to be normal again' Trend Micro users beware - dangerous Apex One zero-day exploited in the wild Save up to $600 on mini PCs from Dell, Geekom, GMKtec, and more in Amazon's Memorial Day sale — I've… IKEA living room trends for summer: playful colors and open storage for a welcoming space that's packed with personality 'This is a sales tactic': Experts warn ransomware hackers will often lower their prices - with some giving… What is the release date for Half Man episode 6 on HBO Max and BBC iPlayer? Samsung's 'absolutely stellar M.2 SSD for both professional users and gamers' is just $390 in the Amazon Memorial Day sale — that's a $250 discount on our 5-star 2TB internal SSD Amazon is slashing prices on its most popular and best-selling devices for Memorial Day — here are the 18 best… She handed a repair tech her iPhone and then the worst happened — here's how to protect your data and… Amazon's 24 best running shoes on sale for Memorial Day — up to 50% off Adidas, Brooks, Nike, Hoka, and more ‘It succeeds in painting an idyllic picture of vanlife’ — I loved my time in Outbound’s wilderness, but a few bumps in the road made me want to cut my trip short GitHub hit with another major attack — Megalodon hits over 5,000 repos with malware-laden commits Digital spring cleaning is now a frontline defense in the scam economy Save up to $350 on the best 3D printers in the Memorial Day sale — massive price cuts on Bambu Lab, Elegoo, Creality, and Anycubic 3D printers including the 'exceptionally good' Centauri Carbon 2 and our top budget pick for beginners The death of the deep dive — why Google’s new AI search wants to do your thinking for you The Dell Memorial Day sale is staggeringly good with up to $600 off laptops and $260 off my favorite business desktop PC… The 49 best Memorial Day tech deals worth adding to your cart — AirPods, Garmin, OLED TVs, cheap smart home,… These retailers have the best RTX 5060, RTX 5070, and RTX 5080 gaming laptop deals this Memorial Day — and yes,… GTA 6 is almost here — here are 7 features I’m desperately hoping for Apple, Samsung, and Google phones are all on sale for Memorial Day — these are the 12 best deals from Amazon,… Samsung's Memorial Day TV sale ends today — here are 15 deals worth buying, including up to $1,500 off top-rated 4K, QLED, and OLED TVs 'This technology turns every router into a potential means for surveillance': researchers warn you can be tracked and identified from Wi-Fi signals 12 of the best Memorial Day laptop deals — my top picks from Dell, Best Buy, Apple, HP, and Lenovo from $179 I tested the Honor 600 and was impressed by its ‘genuinely astounding’ AI features, even though they occasionally ‘nose-dive straight into the uncanny valley’ 'After one month, most partners have each found hundreds of critical- or high-severity vulnerabilities': Anthropic claims Mythos has found over ten thousand major security vulnerabilities across 'the most systemically important software in the world' Zendesk CLO Shana Simmons: Empathy is the new superpower for AI leaders 5 things Microsoft isn't fixing with Windows 11 that I'd love to see happen Why fiber is the real secret to scaling intelligence in artificial intelligence factories Most ransomware attacks are opportunistic. Here’s how you can stop attackers The new cyber gap is response latency Why self-running agents are creating the biggest security crisis of 2026 This little-known iPhone feature just saved a driver from a 330ft fall — and it could save your life too iOS 27 is tipped to get 3 big upgrades — here's what to expect at WWDC AI is making everyone web app builders - but leaving teams exposed What election polling teaches us about ML-based email security What is the release date for Dutton Ranch episode 4 on Paramount+? AI and education: Strengthening freedom of thought in the battle for truth How to watch Cheese Rolling 2026 live stream – it's *FREE* Surfshark has dropped an exclusive deal for TechRadar readers just in time for Memorial Day 2026 — here's how to claim your free Amazon gift card worth up to $30 The TerraMow V1000 robot lawn mower is the perfect wire-free lawnbot for newbies and technophobes From split-tunneling to post-quantum crypto: NymVPN just had its biggest two-month update yet, and a fresh redesign is already on the way Can you tell a bot from a human online? Surfshark's new experiment says nearly half of us cannot Richard Dawkins renamed Claude ‘Claudia’ and wondered if it was conscious — and that emotionally charged reaction says something profound about modern AI How to watch Rick and Morty season 9 online from anywhere NYT Strands hints and answers for Monday, May 25 (game #813) NYT Connections hints and answers for Monday, May 25 (game #1079) Quordle hints and answers for Monday, May 25 (game #1582) Your Android phone comes with two built-in tools for freeing up storage space — here's how to use them and keep your mobile running smoothly There's almost 50% off the 4.5-star-rated Motorola Razr Ultra at Best Buy Assassin's Creed Black Flag Resynced creative director says his top three favorite elements of the remake are the fight system, the new missions, and the new end game chapters — 'We have received a lot of positive reactions to the story' This is the world's first dual-sided monitor with recto verso displays — Philips sticks two full HD panels… I've turned my old Android phones into 5G routers, power banks, and more — here's how you can do the…
The Tor Project takes a major step toward launching its mobile VPN with successful Cure53 audit
Rene Millman · 2026-04-17 · via Latest from TechRadar

  • Security firm Cure53 performed a penetration test on TorVPN for Android and its Onionmasq networking layer in June 2025.
  • The assessment found no fundamental flaws in how the application routes traffic or establishes secure tunnels to the Tor network.
  • Developers are currently patching low-level DNS and input validation bugs that could potentially lead to denial-of-service in rare scenarios.

For millions of users worldwide, the Tor network is the gold standard for staying anonymous online. Now, the developers behind the project are moving closer to launching a dedicated mobile application, and a new independent code audit suggests the technical foundations are rock solid.

In recent years, the privacy organization has been working to expand its mobile offerings, including the ongoing development of TorVPN. The ultimate goal is to make Tor-based protections much more accessible to everyday smartphone users while maintaining the strict security guarantees the network is famous for.

As part of this ongoing mission, the Tor Project recently commissioned renowned cybersecurity firm Cure53 to rigorously test TorVPN for Android.

According to a post on the official Tor Project Forum, the penetration testing took place in June 2025, evaluating both the Android application and its underlying networking layer, known as Onionmasq.

While the mobile app isn't ready to challenge the overall best VPN providers on the market just yet, the results are incredibly promising. Cure53 reported that the software successfully maintains its core security requirements, paving the way for a safer, more private mobile browsing experience.

Under the hood of TorVPN

Unlike traditional consumer VPN services that route your traffic through a centralized server, the TorVPN Android application routes a user's device traffic through the decentralized Tor network. This makes it significantly harder for internet service providers or malicious actors to track your digital footprint.

Because this level of anonymity requires flawless execution, Cure53's assessment looked closely at how TorVPN establishes its connections. The security firm also tested Onionmasq, a Rust-based tunnel interface that handles everything from low-level network traffic forwarding and TCP/UDP parsing to DNS resolution and routing traffic to the Tor network via the Arti implementation.

Thankfully, the major takeaways are highly positive. Writing on the official forum, a Tor Project representative confirmed: "The audit found that Tor's core integration remains robust, with no fundamental issues in tunnel establishment or routing."

Ironing out the final bugs

While the core privacy features are functioning securely, Cure53 did flag a handful of technical concerns that need to be patched before a wider rollout.

The majority of these vulnerabilities centered on "incomplete input validation and weaknesses in DNS handling." According to the forum post outlining the audit results, these specific flaws could theoretically be exploited to create "denial-of-service conditions in certain rare conditions," which would temporarily crash or disrupt the application.

Testers also suggested implementing better cryptographic hardening, specifically pointing out certificate pinning and randomness as areas for improvement. Additionally, the audit noted some typical mobile security quirks, including "plaintext configuration storage and lack of root detection."

If you're eager to try the app to secure your smartphone, the good news is that the Tor Project team is already on the case. The organization stated that all findings are currently being tracked and actively addressed as part of its ongoing security work. By using this audit to prioritize resource management, tighten validation, and implement established security libraries, the final version of TorVPN for Android is shaping up to be a powerful, privacy-first tool.