3 ms·
Anonymity is not the same as privacy. Tor is more about anonymity than about privacy. That exit notes can sniff traffic has been known for a long time. Comprom
by demosthenes 16y ago
Anonymity is not the same as privacy. Tor is more about anonymity than about privacy.
That exit notes can sniff traffic has been known for a long time. Compromised exit nodes do not compromise anonymity as long as you don't give up personally identifiable information in traffic that gets routed via exit nodes.
More problematic is that compromised exit nodes could inject or run man in the middle attacks on your outbound traffic. These could then make you give up your real IP. This is why you shouldn't run exploitable protocols when exiting via Tor (ie. don't use javascript, flash, etc. if you want to remain anonymous).
- shii 16y agoIf you're engaging in sensitive escapades via Tor to conceal your true identity, shouldn't the intentions and identity of who you're tunneling all your traffic through be one of your top priorities? How do you know if that node with the pretty flag saying it's in Switzerland isn't logging all IPs, DNS requests, and packet headers straight to another Room 641A? I just dislike when people suggest things like Tor without having used it themselves and seen the glaring issues and essential deficiencies with the tool. Especially when there are such better and faster solutions available.
- demosthenes 16y agoBecause of Tor's design there's no need for trust at the exit node. Plus, you hop between exit nodes at 10 minute intervals, giving any one node at best a scrappy picture of your activities. You can also blacklist exit nodes that you consider suspicious. Even if an exit node's logs are compromised an adversary wouldn't know your identity if you haven't given it up in the compromised traffic. What better solutions are available? As far as I know Tor is still the most resilient option out there.