Thousands of Tor exit nodes attacked cryptocurrency users over the past year
therecord.media
therecord.media
Never felt so much relief to hear the world "crypto" as the delivery of the message had me confused and fearing bad things.
When I spoke to the person about it turns out they'd started mining on their own hardware as a hobby and were just curious what the perf diff would be on the work computer's
Agreed. There are even pretty strong disincentives from a legal standpoint.
Sounds like you kids need an anonymous decentralized cryptocurrency powering your tor nodes with rewards for doing so. But everyone here hates crypto so I’ll just be over here sipping my Monero tea.
That did work remarkably well, but unfortunately the author lost interest at some point and took the whole project down.
Either way, it can't be protected in the way filecoin/gridcoin are protected.
Of course a way to prove you are not malicious would be great but I don't see how you can prove that using technology.
The first reservation that comes to mind for me is concerns about crypto ledgers being more pseudonymous than anonymous. If I start using a cryptocurrency to tip exit node operators, that creates an immutable, publicly visible paper trail linking my presence on TOR back to me. Not exactly the kind of thing I'd be eager to sign up for if I'm trying to hide my tracks.
It also moves things toward a situation where digital privacy is reserved for people who can afford to pay for it, which strikes me as running directly counter to the principles the TOR project is supposed to be upholding.
(Also the EFF is literally a political organisation and has described itself as a civil rights organisation since its formation in 1990.)
I'm pretty sure that, if you asked a random EFF board member, they would tell you that digital rights are largely just the application of human rights principles to the digital domain.
Why is this bad? Branding yourself as a human rights project garners way more sympathy than having the implied branding of "we help cybercriminals cover their tracks". In an age where encryption and privacy is under constant attack, having the public be on your side is very important.
Reddit has tons of actors spreading disinfo especially about VPN's never trust the info from there without serious vetting.
What data exactly are you worried they would disclose? Everything they see would be encrypted, no?
Like you, I imagine plenty of governments run exit nodes just to see what's happening and keep the system working for their own uses.
edit: and, the reason it's an issue is not because these systems and networks don't have strong secure communication options available, but because if there is any potential security hole at all, some users will fall into it
Firefox has had `dom.security.https_only_mode` for a while and it's amazing.
User → HTTP connection → [INTERCEPTION] → HTTPS connection → website.
However, Tor onion services cannot be MITM'd by an exit node, because you don't use exit nodes and the connection is end-to-end encrypted (and authenticated -- the URL is also the public key of the hidden service so you'd need their key to spoof the service). So arguably .onion URLs are far harder to attack in this manner than TLS, and the HSTS preload list isn't needed at all to protect .onion URLs.
Tor Browser and TAILS try not to keep any trace of the websites you've visited.
That means no 'frequently visited sites' start page, no bookmarks, no address bar autocomplete from history, and no HSTS unless it's preloaded.
So if a tor user visits bitcoin-mixer.com there's a good chance they'll be typing the address in manually - and a good chance they'll omit the https:// at the start.
(Also, a great many bitcoin mixers, for some inexplicable reason, don't get themselves HSTS preloaded)
i think the only way to prevent that from working is if the websites outright reject http requests.