4 ms·
Smart detection for passive sniffing in the Tor-network
- tlrobinson 10y agoTor should really just detect and block (or warn + prompt the user to allow) unencrypted connections. If you're using Tor you probably also want end-to-end encryption.
- hueving 10y agoThat's the responsibility of a browser plugin. tor itself is a low-level packet relay so it's not really up to it to determine whether or not traffic is encrypted already.
- nxzero 10y agoNot really, lots of Tor servers will block various protocols for various reasons; core difference being that packet inspection would enforce network usage policy to a finer degree; lastly, anyone using Tor should assume the packers are actively being mined by the severs.
- flashman 10y agoI don't think so. Tor could make the address bar red when you're on a non-HTTPS connection, for instance, warning you that any information transmitted can be sniffed by the exit node.
- click170 10y agoIf someone just has tcpdump running this won't catch them unless they actually try to use the links or credentials they retrieved. I like this, but from the title I expected to be able to detect that tcpdump is running, akin to what you can do with malformed ARP packets to detect a NIC in promiscuous mode. Edit: in case anyone is wondering what I'm talking about - http://security.stackexchange.com/questions/3630/how-to-find-out-that-a-nic-is-in-promiscuous-mode-on-a-lan http://security.stackexchange.com/questions/3630/how-to-find...
- deleted 10y ago[deleted]