4 ms·
>through the use of Flash, Java, and add-ons that bypass the typical port proxy, but also, by HTML tags that call out to FTP bypassing the standard web ports.
by lambada 13y ago
>through the use of Flash, Java, and add-ons that bypass the typical port proxy, but also, by HTML tags that call out to FTP bypassing the standard web ports.
Which is why Tor Browser Bundle - the recommended way of using Tor, doesn't include Flash or Java, and is configured to route even FTP over Tor, when browsed with the built-in TBB. It also shoves up a dialog when you download something to Disk, about the dangers of opening it from outside the Browser.
>[stuff about exit node sniffing]
Which is why Tor Browser Bundle also uses HTTPS Everywhere. They also don't hide the fact that exit-server communication is unencrypted (unless HTTPS is used), and so sniffable. In fact, the Tor Project as a whole is very open about the threats that can break Anonymity - it's in the projects best interests to be after all.
EDIT: Clarified on exit-server communication, as language was imprecise.