4 ms·
HTTPS doesn't change the attack surface, it's just assumed to make it inaccessible. The exit node is still in the middle, and they absolutely can still listen.
by cookiecaper 7y ago
HTTPS doesn't change the attack surface, it's just assumed to make it inaccessible. The exit node is still in the middle, and they absolutely can still listen.
TLS will probably defeat script kiddies that are just after the "thrill" of voyeurism, but more advanced operators will make use of the attack surface you're offering them, even if they aren't ever able to decrypt the payloads (not necessarily a guarantee). There's lots of room to analyze and manipulate encrypted HTTPS traffic in interesting ways (SNI, non-secure cookies probably good starting points).
TLS depends on correct configuration on both the client and server-side to be effective (and an interested proxy could try to modify the handshake to downgrade the connection's security). Whole versions of SSL/TLS have been deprecated after fundamental flaws were discovered; things like Heartbleed, POODLE, and Debian's low-entropy key debacle were all real things that made TLS much less secure than expected. An exit node operator that knew about these flaws prior to disclosure could've been having a heyday while users just said "Welp if I use HTTPS Everywhere it'll be fine".
Even without bugs, when TLS is ostensibly working completely properly, the trust model is frequently hijacked. See the CACert wiki [0] for a list of several dozen well-known attacks on CAs, many of which allowed imposters -- on multiple occasions state-level actors -- to issue fake certificates for specific domains, which a malicious exit node could inject.
The incontrovertible point is that using exit nodes exposes some prime attack surface to literally anyone, and yes, that's still attack surface, even if you're 1000% sure that your encryption is so super-duper strong that literally no one will ever be able to break it.
The exposure is real, the risk is real even if not necessarily always immediate, and it needs to be considered along with the other factors. Any risk analysis that involves accessing clearnet resources via Tor exit nodes should contemplate this.
[0] http://wiki.cacert.org/Risk/History http://wiki.cacert.org/Risk/History
- LMYahooTFY 7y agoYou're clearly not a novice in this domain, but I'm having difficulty understanding your assessment without any sort of threat model. The risks you're detailing are likely insignificant for 99% of users right now. Using TOR doesn't imply a specific threat model, and that notion weakens tor security and anonymity as a whole.