3 ms·
I'm more worried about the exit nodes themselves. If I were a well-funded intelligence agency and targeting, let's say, 'that guy who posts under the name "joe
by csandreasen 12y ago
I'm more worried about the exit nodes themselves. If I were a well-funded intelligence agency and targeting, let's say, 'that guy who posts under the name "joeschmoe" (or some other identifier) that we only see coming out of Tor nodes', I'd set up a bunch of exit nodes, wait for you to connect through one and send back a browser exploit embedded in the web page.
Or, more likely for most users, if I were an organized crime syndicate I'd set up an exit node with some fake data, just sslstrip one out of every 500 or so connections to some semi-popular website, and just steal the usernames/passwords/credit card info/etc. until the node got caught and was blacklisted, then disappear. I get the impression that malicious exit nodes work better when the operator doesn't care who gets hit. Targeting a specific user would probably be a lot harder.
EDIT: I thought you made a decent point, and tried to give a thoughtful reply, but you apparently deleted your comment before I finished typing mine out. I don't know if you'd prefer to stay anonymous, so I've gone and edited your handle out of my response.