2 ms·
Why? DNS lookups are routed through Tor just like HTTP/TCP traffic (in implementations that aren't broken).
by devit 11y ago
Why?
DNS lookups are routed through Tor just like HTTP/TCP traffic (in implementations that aren't broken).
- eponeponepon 11y agoAh, OK, I see. My understanding of Tor is far from complete, I should point out - it's not my area of expertise at all, and I'm just an interested observer! But surely the point still stands? Even if you only see the DNS lookup as it emerges from the endpoint, you still know that User XYZ uses Tor to access Service ABC, correct?
- devit 11y agoThe enemy sees that someone using Tor exit node E is accessing Microsoft using user id XYZ and they can infer that other traffic coming out of exit node E is also more likely than average to be from the owner of Microsoft account XYZ. Obviously, the enemy may know more about the owner of Microsoft account XYZ: for example, they may know the name you typed when registering it or, if you login to the same account from your home internet connection, they may know that it is the same person that had assigned IP I at time T and may thus know that it is the same person that the ISP who was assigned the IP address block containing IP I claimed presented ID stating he was Mr X to the ISP as part of subscribing to the ISP. This means that between accessing the Microsoft account XYZ and doing other things that you don't want to be associated to the owner of Microsoft account XYZ, you should use the "New Identity" button in Tor Browser, or use a separate machine or Tor Browser instance. Of course you cannot know which services reveal your user id to your enemies, so you should always do that regardless of whether the service is known to send it in plain text or not.