3 ms·
Routing all of your traffic through Tor indiscriminately is a really, really bad idea - and not solely for the reason described in the article. When you use To
by csandreasen 12y ago
Routing all of your traffic through Tor indiscriminately is a really, really bad idea - and not solely for the reason described in the article. When you use Tor, you're accepting the risk that the exit node could be sniffing and/or manipulating your traffic as a tradeoff in order to hide your IP address from the remote server and anyone in between. For that reason, if you really need to use Tor then you need to be aware of every connection you make - everything should be over SSL with pinned or otherwise verified certificates.
I'd recommend against even enabling Tor globally for a single machine, unless that was a dedicated box that's only used for anonymous browsing. You don't want to get tripped up by that browser window you accidentally left minimized with some Javascript periodically reloading content, or perhaps some auto-update program running in the background that you didn't realize was leaking some unique identifier.
Routing all of your network's traffic through Tor is just begging for bad things to happen, nevermind the fact that it essentially negates any anonymity that Tor afforded you to begin with. If you absolutely must use Tor for something, the safest way to do so is to connect to Tor, make whatever connections you need to make (and only those connections), then immediately get off.
- thirsteh 12y agoIndeed: Client fingerprinting--when you're doing nothing unusual as well as when you're doing something "secret"--is just as deadly with Tor enabled, even if your true IP address isn't visible.
- deleted 12y ago[deleted]
- csandreasen 12y agoI'm more worried about the exit nodes themselves. If I were a well-funded intelligence agency and targeting, let's say, 'that guy who posts under the name "joeschmoe" (or some other identifier) that we only see coming out of Tor nodes', I'd set up a bunch of exit nodes, wait for you to connect through one and send back a browser exploit embedded in the web page. Or, more likely for most users, if I were an organized crime syndicate I'd set up an exit node with some fake data, just sslstrip one out of every 500 or so connections to some semi-popular website, and just steal the usernames/passwords/credit card info/etc. until the node got caught and was blacklisted, then disappear. I get the impression that malicious exit nodes work better when the operator doesn't care who gets hit. Targeting a specific user would probably be a lot harder. EDIT: I thought you made a decent point, and tried to give a thoughtful reply, but you apparently deleted your comment before I finished typing mine out. I don't know if you'd prefer to stay anonymous, so I've gone and edited your handle out of my response.