Tor and HTTPS
31–40 of 135 posts
Re: Tor and HTTPS
#32What happens if NSA starts operating a number of Tor exit nodes and eavesdropping on the outgoing traffic? What prevents them from doing so?
Re: Tor and HTTPS
#33How legal is operating a Tor node? I'm thinking of putting up a machine (and a VPS) to just run a node. I just don't want to get into legal trouble for running a(n exit) node.
Running a regular node is fine as you're routing encrypted information for the Tor network - your unlikely to get any hassle although check your countries laws on crypto first. Running an exit node may be a different story. You could get false DMCA takedown notices or get charged with someone else's crime. Think of it this way; you're running an open proxy. Uses of Tor can send any traffic through your connection. Th…
Re: Tor and HTTPS
#34Maybe I'm misinformed, but I thought the big problem has less to do with data in transit than it does with the destinations (Google, Facebook, Microsoft, etc) working hand-in-hand with the NSA? What am I missing?
Re: Tor and HTTPS
#35When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?
By location they mean your IP (from which they can get your address, by asking the ISP). As long as they can't links the two captured packets, they just know that you're using Tor.
Re: Tor and HTTPS
#36What happens if NSA starts operating a number of Tor exit nodes and eavesdropping on the outgoing traffic? What prevents them from doing so?
Re: Tor and HTTPS
#37What happens if NSA starts operating a number of Tor exit nodes and eavesdropping on the outgoing traffic? What prevents them from doing so?
Nothing, but they would still not know where the traffic is coming from. The "Onion" defined in the Tor protocol is unwrapped layer by layer by each node. So the NSA has a choice where no option would help them too much: 1. Be the first node you access and be able to see your IP but not your traffic 2. Be the last node and be able to see your traffic but not your IP 3. Be a middle node and see neither
Re: Tor and HTTPS
#38Re: Tor and HTTPS
#39What happens if NSA starts operating a number of Tor exit nodes and eavesdropping on the outgoing traffic? What prevents them from doing so?
If the NSA was to create tons Tor nodes (enter, exit, and relay), the onion may be broken.
Tor is by no means perfect. It is only obfuscating.
It is easy to see how this is broken if you click the TOR button on this thing and then imagine the TOR nodes say NSA on them.
I think it is more fun to imagine security this way (extremely challenging and like you are protecting yourself from the perfect attacker, and the NSA is a good face to put on the perfect attacker). People don't realize how much trust they are putting in their hosting provider, cell carrier, etc.etc. It's insane.
Re: Tor and HTTPS
#40http://www.bivio.net/products/dpi/
http://arstechnica.com/tech-policy/2010/06/deep-packet-inspe...