Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Perhaps Tor operators can perform some act of vigilantism and expose criminals like the above without incriminating themselves through booting out and releasing the data of the pedophiles, terrorists and what have you.

If Tor allows the exit nodes to access that data, (1) it's not very secure, and (2) it won't be long before the ability to monitor that data will become an obligation to monitor it.



You may already know, but in case you don't:

Tor exit nodes get access to:

1) The network traffic that they've been asked to proxy.

2) The IP address of the previous hop in the Tor network that relayed that traffic to them.

IIRC, Tor currently runs a regular request through an entry node, a -er- middle node, and an exit node.


I didn't know that. Thank you.

I was under the impression that all traffic was encrypted. It sounds like that's up to the users; they can encrypt their traffic, but they aren't required to. Of course, failing to encrypt illegal traffic would be as boneheaded as sending a ransom note on a post card, with a correct return address.


> I was under the impression that all traffic was encrypted.

Welllll....

IIRC, traffic entering the Tor network and traffic between Tor nodes is encrypted with TLS. This means that the only place an adversary that doesn't have a compromised entry node can read your traffic is when the exit node makes any non-encrypted requests on your behalf.

To summarize: if you use TLS (or some other encrypted transport) over Tor, your communications will always be encrypted (obviously).

If you use an unencrypted transport over Tor, then the exit node[0] will be able to read your traffic, in exactly the same way that your ISP would be able to read that traffic if you chose to route it over your home Internet connection. :)

[0] But only the exit node!


Iirc, the middle node never has access to the data being sent.

I think only the last node might, and that is because they have to be able to send and receive it, and if the website you are connecting to doesn't support ssl or anything, then there's no way the exit node can send the information it needs to send , without having access to it.

But I think the entry and middle node have no information about the content (other than some bounds on its length)


Not just the traffic data, also when the traffic was sent or received, which can be a powerful tool in finding the point of origin.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: