|
|
Log in / Subscribe / Register

Spoiled onions and Tor exit relays

Spoiled onions and Tor exit relays

Posted Jan 30, 2014 10:47 UTC (Thu) by johill (subscriber, #25196)
In reply to: Spoiled onions and Tor exit relays by xav
Parent article: Spoiled onions and Tor exit relays

Wouldn't they still have detected that, since they likely connected to servers they controlled, so could compare the certificate exactly?


to post comments

Spoiled onions and Tor exit relays

Posted Jan 30, 2014 15:45 UTC (Thu) by raven667 (subscriber, #5198) [Link] (1 responses)

And they can only forge certs very very rarely, like what was done for Stuxnet, so this could only be used against pretty high-value targets. And certificate pinning could detect it, once detected the whole thing is kind of blown and you can't do it anymore.

Spoiled onions and Tor exit relays

Posted Jan 30, 2014 16:36 UTC (Thu) by njwhite (guest, #51848) [Link]

Exactly, and as the exit relay can't tell who it's relaying data for (at least without controlling a significant portion of the Tor network), it won't work. It's too high value a technique to use unless you're confident of your target.

I suppose if the exit monitored the traffic looking for e.g. a specific username being entered in plaintext on a certain site it could MITM, but even then you'd struggle, as IIRC tor switches circuits every 10 minutes anyway.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds