Industry News

Alleged Backdoor Leaking Hashes in BitTorrent Sync; BitTorrent Says There’s no Backdoor

Popular sharing app BitTorrent Sync has been allegedly found to contain a backdoor that was leaking hashes, according to an analysis by Hackito Ergo Sum hackers.

BitTorrent Sync, which has been downloaded some 10 million times, is said to be 16 times faster than its competitors. The researchers at Hackito alleged that the apps’ backdoor was put in after the first release at NSA’s request.


Photo Credit: Hackito Ergo Sum

“This may be the result of NSL (National Security Letters, from US Government to businesses to pressure them in giving out the keys or introducing vulnerabilities to compromise previously secure systems) that could have been received by BitTorrent Inc and/or developers,” Hackito said.

A key finding was a “probable leak of all hashes to and access for BitTorrent Inc to all shared data” and a “leak about the private network addresses of clients that gives indication about where and what to attack.”

“Probable” multiple vulnerabilities were also found during the tests.

BitTorrent replied to the allegations through one of its employees, saying that, besides a few crashes, nothing bad was found during the Hackito tests.

“Wording of `Probable leak of all hashes to and access for BitTorrent Inc to all shared data.’ is very close to `I almost hacked microsoft today’,” a BitTorrent employee going by the moniker ‘kos13’ concluded.

A more detailed answer was posted on the BitTorrent Forum a few hours later.

“We’ve gone through the claims made on Hackito and after reviewing it in full, we do not feel there is any cause for concern,” said K.  Lissounov BitTorrent Sync General Manager.

BitTorrent said the folder hashes are not the folder key, which is secret and can’t be used for obtaining access to a folder, as their purpose is to “discover other peers with the same folder.” Also, hashes (160 bit number) “cannot be guessed” as it is “cryptographically impossible to guess the hash of a specific folder.”

Now the ‘leaking’ hashes appear to go to the peer discovery server which enables “peers to find each other” and is separate from the folder exchange system.

“Compromising the public infrastructure cannot impact the security of Sync,” even if Sync relies on public infrastructure due to its client-side implementation.

BitTorrent Sync’s cryptographic practices have also been reviewed by a third party security firm.

About the author

Lucian Ciolacu

Still the youngest Bitdefender News writer, Lucian is constantly after flash news in the security industry, especially when something is vulnerable or exploited. Besides digging for 'hacker' scoops and data leaks, he enjoys sports, such as football and tennis.
He has also combined an interest for social and political sciences, as a graduate of the Political Science Faculty, with a passion for guitar and computer games.


Click here to post a comment
  • Christian here from BitTorrent. These claims have been debunked:

    While I believe these guys had good intentions, they were still clear that their post was not a professional assessment of Sync’s security. Unfortunately, it is being interpreted as such.

    Sync has gone through rigorous third party review and has been deemed sound.

    • Hi Christian,
      The post has been updated. It now contains BitTorrent’s stance on the alleged backdoor and hash leaking problem.