Re: How safe is Tor for logging into http (nont https) web sites

Re: How safe is Tor for logging into http (nont https) web sites

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: How safe is Tor for logging into http (nont https) web sites Joan Battaglia 10-26-2007
Posted by Joan Battaglia on October 26, 2007, 8:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Fri, 26 Oct 2007 03:35:03 -0500, VanguardLH wrote:
>
http://arstechnica.com/news.ars/post/20070910-security-expert-used-tor-to-collect-government-e-mail-passwords.html
> You get anonymity, not necessarily security, with P2P networks.

I read this article where, apparently
- government personnel used insecure passwords
- hackers (presumably not using Tor) guessed their passwords
- those hackers (now using Tor for anonymity) constantly read their email
- the security expert set up 5 rogue Tor servers to intercept passwords
- he wrongly concluded at first the governments were using Tor
- he complained to the governments who ignored it (they weren't using Tor)
- he published their government login and passwords to get their attention
- he then realized the hackers were the ones using Tor
- in the end - it was the same result - Tor exposes passwords

He concluded people need https to protect their password from Tor servers
But, did I hear you say even https exposes your password to the Tor server?

Similar ThreadsPosted
Re: How safe is Tor for logging into http (nont https) web sites October 27, 2007, 5:16 pm
Re: How safe is Tor for logging into http (nont https) web sites October 27, 2007, 5:24 pm
Re: How safe is Tor for logging into http (nont https) web sites October 28, 2007, 10:06 am
Snort logging May 4, 2005, 4:52 am
snort file logging name December 18, 2004, 5:31 am
A question about firewall logging March 29, 2006, 7:42 am
How to keep sites from reading cookies? November 24, 2004, 6:37 am
ActiveX drive-by download Sites December 29, 2004, 1:01 pm
Determining which sites are blocked at the office February 10, 2005, 10:41 am
Yahoo sites hit by availability problems July 8, 2007, 3:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy