Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If someone runs an entry node, they get to see the IP addresses of 1/N of Tor users, how much data the users send and receive, and when. But they don't get to see what data the users are sending and receiving, or even what exit node they're using. If someone runs an exit node, they get to see (and filter) what data 1/N of Tor users are sending and receiving, and when, but they don't get to see who those users are, or even what entry node they're using. And the data they see can still be encrypted; e.g. connections to Gmail will use TLS/SSL, so even the exit node doesn't get to steal your mail.

So that may be why.



FWIW, during the recent DigiNotar SSL shambles, there was evidence that some Tor exit nodes were using forged Google certificates to MITM "secure" connections to Googles services.

https://twitter.com/#!/moxie__/status/110863647693221888


Compiling a small list of Tor users and grabbing un-protected data could still be substantial though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: