Can you trust Tor's exit nodes?
nakedsecurity.sophos.com
nakedsecurity.sophos.com
A false sense of security is worse than no security at all.
For example, when you use the (recommended) Tor Browser Bundle the start page contains a window containing the following headsup
"Tor is NOT all you need to browse anonymously! You may need to change some of your browsing habits to ensure your identity stays safe."
As well as a link to https://www.torproject.org/download/download.html.en#warning.
That same warning is also present on the main download page: https://www.torproject.org/download/download-easy.html.en
If there were one thing I could change about security discussions, it's that you can't talk about security in the abstract -- only security relative to some threat or foe.
I think a lot of the conversation would change if we could get people to start talking about security that way.
The less magical the internet seems, the easier it'll be for the public to get behind issues of internet security and privacy at the policy level.
https://people.torproject.org/~karsten/tor-brochure/tor-broc...
An ISP employee know whom either side of an connection are and can pick and chose targets in a very selective way. As gate keepers they can also be influenced by outsiders to target specific users and attack them. They are however likely to get caught if they do noticeable attacks and risks their job if its unsanctioned, and risk the companies reputation if it is sanctioned.
A Tor operator can not see whom is doing the connection, but they are slightly less likely to get caught if they do try to attack users. They are also only going to lose the nodes ip address reputation if they are caught attacking users.
Third is the backbone networks that unlike the ISP level has great incentives for government level attackers to collect whole nations/continents amount of data. The risk that they are found out is almost zero, and if they are they can still deny it.
All in all, I would summarize in such a way that ISP's has the greater risk of active attacks by both criminal actors and government level actors, backbone networks for passive attacks by government level actors, and tor nodes for passive attacks by criminal actors. In order to protect against all three you got to use end-to-end encryption as the primary security technique and adding tor helps then against meta data attacks.
I've since started using 'whole premises VPN' (all traffic is routed through an encrypted tunnel to a VPS) - I have more confidence in my VPS provider than I do in my residential ISPs. At least the VPS company probably won't use my connection data for marketing profiles..
> He concluded that people were using Tor in the mistaken belief that it was an end-to-end encryption tool.
No. Dan snooped on attackers hacking the email of the Australia, Japanese, Iranian, India and Russia embassies, the Iranian Foreign Ministry, the Indian Ministry of Defence and the Dalai Lama's liaison office.
Might want to change that.
Also, the Tor Project apparently hasn't responded to Chloe's report.[0] But I just saw a question about it on tor-talk.
Edit: The nickname of the first exit in her list is "Hackosaurusrex" ;)
[0] https://chloe.re/2015/06/17/tor-is-dead-centralization-is-wr...
The attack you say stands out is literally just implementing the most obvious thing that Tor explicitly doesn't defend against. It's just a demonstration that Tor's threat model is accurate, and not a weakness in Tor that people were unaware of.
The you had a knee jerk reaction to not use Tor for what it's good at when you realized it can't do everything is the all-or-nothing, it must be perfect mentality that is the enemy of good.
It's people like you, with your all-or-nothing extremism that undermine reasonable discussions about partial steps we could take.
It's totally possible to setup websites where you, as the user, don't have to worry about this at all. Even sslstriping can be mitigated if the operators of the website know what they're doing.
Passive monitoring? Use https.
Upgrades to https getting prevented? Submit your site to the hsts preload list[0]
It does not surprise me, bundling a list of all the sites wanting SSL-only with the browser can't possibly scale. I would expect that this is only possible for the most popular websites, that have enough clout to get included.
So for normal people, no, it sounds like it's not really possible to do this.
[0]: https://code.google.com/p/chromium/codesearch#chromium/src/n...
TOR doesn't provide encryption of your data. It just doesn't allow any listener to guess who is visiting what websites since they can't correlate the source to the destination.
The problem with the article approach is that it's only gonna attract small players. What you could do is signing up in a relevant website using high target's looking credentials. For example signing up in some http wikileak page using fake julian assange's credential.
What could be cool is to somehow leak your fake credential while logging into gmail (and I don't know how to do that since they use https only) and then check what IPs connected to that gmail from the gmail settings.
> "Tor is ... used to access anonymous, hidden services (the so-called Dark Web) but, more commonly, used as a way to access the regular internet anonymously and in a way that's resistant to surveillance."