3 ms·
Would it be possible for Tor to detect sniffing by seeding the traffic with poison pills that ratted out anyone doing this in bulk?
by nxzero 10y ago
Would it be possible for Tor to detect sniffing by seeding the traffic with poison pills that ratted out anyone doing this in bulk?
- dogma1138 10y agoNot really you can always mirror the wan/uplink port and do the capture on another box so even some time based / performance analysis won't show anything.
- dkopi 10y agoPort mirroring means you can only be a passive eavesdropper. Attacks like SSL mitm wouldn't work because you actually have to intercept and modify the traffic
- dogma1138 10y agoSSL MITM still won't work unless you want it to be very noticeable or you have very substantial resources. Port mirroring is enough to capture SSL traffic and to break weak SSL keys or if you have compromised the key of the destination services (w/ some caveats like no forward secrecy etc.) And it doesn't prevents you from executing MITM attacks from upstream or just doing specific MITM attacks from within the TOR exit node later on. But overall there is nothing you can do to ensure that your TOR exit node, your VPN gateway or even your ISP isn't reading your traffic other than to use encrypted tunnels everywhere and even then you are for the most part only moving the problem upstream.
- unethical_ban 10y agoYou can't silently mitm SSL unless you are trusted by the client.
- DaKnOb 10y agoThis has been done in the past: researchers visited a uniquely generated URL from Tor and then recorded which Exit Nodes visited it again. You can find their work if you google it..
- brownbat 10y agohttps://chloe.re/2015/06/20/a-month-with-badonions/ https://chloe.re/2015/06/20/a-month-with-badonions/ "Chloe" visited unique web pages for a month last year, and also used unique credentials to log into a custom honeypot. Of the over 137,000 exit nodes tested, 15 attempted to use the credentials, 650 visited the unique websites. Less than half of a percent, but definitely happening regularly enough to be an issue.
- j3097736 10y agoYes, see http://www.cs.kau.se/philwint/spoiled_onions/ http://www.cs.kau.se/philwint/spoiled_onions/ and http://www.leviathansecurity.com/blog/the-case-of-the-modified-binaries http://www.leviathansecurity.com/blog/the-case-of-the-modifi...
- nxzero 10y agoMakes you wonder why Tor doesn't replicate this and send the nodes ghost traffic, poison pills, block the IPs, etc.
- paavokoya 10y agoSounds strenuous on an already slow network..
- makomk 10y agoLast I heard, there was basically one guy handling all reports of malicious exit nodes, and I couldn't even get him to do anything about the ones very obviously intercepting traffic to Bitcoin wallets and injecting code that stole people's money
- pjc50 10y agoPeople are communicating with bitcoin wallets without end-to-end encryption?
- nbraud 10y agoThere is automated tooling out there that is used to detect misbehaving exits, like ExitMap: https://gitweb.torproject.org/user/phw/exitmap.git/ https://gitweb.torproject.org/user/phw/exitmap.git/