Hacker builds tracking system to nab Tor pedophiles
blogs.zdnet.com
blogs.zdnet.com
And about that hacker from the article, I wonder if his system can be used to catch copyright infringers? People who download offensive texts? People who visit blacklisted sites, where the blacklist depends on the country? Human inventions are beautiful that way - you never know how other people will repurpose them. I hear the guy who invented dynamite didn't intend it to be used for killing, either.
Actually it's something of a legal grey area in most places. If that's all your caught with then you could well just get a slap on the wrists - but that's rarely the case.
I see where your coming from with the arguments; but it's, sadly, not in any way a victimless crime.
I want to see pedophiles in jail too, but if Tor is broken for this purpose, Tor will become useless for any purpose. Governments and others will catch on and take advantage of the same techniques to detect whatever other activity they happen to be interested in.
If you're a supporter of the sort of privacy Tor provides, this is a Bad Thing.
This only highlights something that individuals concerned about privacy should have known beforehand, namely that Tor is just a tool.
So you're essentially pro-thought-crime persecution. I will give you the benefit of the doubt and guess that you meant "I want to see child rapists in jail too, […]". A pedophile does not harm children just by being a pedophile or by being attracted to them, they only harm them when they abuse them.
I agree, however, with the rest of you post.
For what it's worth, I don't think things like child pornography that don't involve actual children should be illegal. Stories, cartoons and photoshop jobs don't involve any actual victims.
I think it would be nice if child pornography could be produced by computer simulations and pedophiles thus would be able to feed their addiction without causing harm. Being able to focus the available resources on treating actual child abusers would be nice.
Every government on earth wants to tear Tor open; he stands to make it big, if he can lie hard enough :-)
Or simply not wanting to be associated with something.
1. You need to run an exit node for unencrypted HTTP traffic to be able to inject html.
2. Tor warns you when you are potentially leaking DNS requests when you are using an old protocol like socks4 instead of sock4a. Anyone who is using Tor is presumably smart enough to activate this option on Firefox or whatever browser they happen to use,
3. The Java applet leaking DNS requests is a big hole which I believe is fixed by now. Even if it did work, it is entirely dependent on point 2 which is easily preventable.
Stuff like Tor is made for purposes that at least somebody considers nefarious. The relevance of this is that he apparently found a vulnerability.
For example: http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-...
A google search returns lots of results, although I'm unsure if any are 'in the wild' exploits.
[edit: from http://www.links.org/?p=205
"the Tor folks have known about this attack. It’s really hard to counter. It would be a lot more helpful for people to work on deeper browser integration to break the attack than to distribute attack code to demonstrate that a known, documented attack works."]