republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Anonymnity: Introduction To The Tor Network
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
dslreportsmembers.freewebtools.com emailed me »
« Prevent spyware with ewido security suite  
AuthorAll Replies

jp10558
Premium
join:2005-06-24
Willseyville, NY

reply to novaflare
Re: Anonymnity: Introduction To The Tor Network

said by novaflare See Profile:

said by jp10558 See Profile:

said by Wildcatboy See Profile:

I think what novaflare See Profile has been trying to say and hasn't been successful in conveying it, is that each Tor server belongs to a totally unknown and most likely untrusted user. The fact that the communication is encrypted won't be enough to stop compromise of your data.

I too haven't had a chance to read the complete overview of Tor but it would be great if someone could clarify this for me:

Let's say I build a Tor server and I also run a proxy server on it that directs all requests for paypal.com, eBay.com, major banks, etc... to my own version of those web pages residing on my server. What in Tor system prevents me from redirecting you to may page? You as a user try to go to paypal, you see my version of it which by the way is quite convincing and you enter your username and password. You can't login and you say to yourself "Oops, Paypal must be down." and move on.

I have your password and the encryption didn't do anything. So can someone tell me how Tor prevents me from doing that and what safeguards are in place? This is a question that novaflare See Profile has been asking and I haven't seen an answer for it yet or perhaps I missed it.
Well, with paypal - it is SSL before you ever enter your password. So, paypal prevents it with or without tor. eBay is the same. So, unless you somehow get a verisign SSL cert claiming you are eBay or Paypal, I don't get the problem...

Every financial site I've seen is like this - and if you are in the habit of paying for things without it being secure, TOR isn't going to help - but I doubt it will hurt either.

So, yes, I suppose you could spoof yahoo e-mail, but who's using TOR to access their e-mail anyway? I mean, if you have to authenticate yourself to the end site, I don't see how it was worth all the anonymizing steps...

And if you mean to say you're spoofing google search, you're not getting private info that way...
when your entering info in to a moded cached page it does not matter how secure the real site is. SSL never plays a part. Hell why even bother presenting the user with a cert fake or real. Most will asume this is normal and just enter and submit away. Url will show correct anti fishing apps and meathods will be no good etc.
Ok, I don't know about IE, but in Opera, there's this big yellow bar that shows up in the address bar when the site is secure. It's not there if the site isn't SSL authenticated. If you have a spoof that pulls up that bar without a SSL Cert, I want to see it, so I can report the vulnerability to Opera.

At some point, you can't protect ignorant people. If these are the people falling for the nigerian scams etc... it doesn't matter if they have TOR or not. As I said before, there are numerous equivelent methods to phish them, and they are at equal risk without TOR.

Moreso, I'm guessing the people who even know about TOR, much less can manage to set it up, aren't technical neophytes, nor the best targets for phishing. IE, the people who don't use IE, and who know to look for SSL auth before inputting their CC#.

I'd also guess that these people would realise there is little point of using TOR to then tell the site who you are, where you live, and your CC# to order something on a legit site. There's little point using TOR to check yahoo e-mail, as I said before, if you are going to ID yourself to the end site, don't wast the time or overhead with TOR. It's pointless.

OTOH, if you aren't going to those sites for the reasons above, then the possible spoof sites aren't going to garner much information - One, you'll be seeing/spoofing the equivelent of google search, two, you'll only get 1-2 minutes of data before TOR yanks them to a different endpoint, so not enough to do much data anylsis on searches or whatever...
--
Opera 8.02(Build 7680); Windows XP Pro SP2;Athlon 64 3400+; 1GB PC3200 DDR; 1M/128k DSL; NOD32(Version 2.5.25); Sygate Pro 5.5(Build 2637);Proxomitron 4.5j Grypen 7/26/05(Opera mod),GPG ID:0x0A1C6EE3
Forums » Up and Running » Security » Securitydslreportsmembers.freewebtools.com emailed me »
« Prevent spyware with ewido security suite  


Tuesday, 16-Mar 22:34:32 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10.5 years online! © 1999-2010 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [81] What You Need To Know About The National Broadband Plan
· [77] The 'Electromagnetically Hypersensitive' Attack Smart Meters
· [68] 'Lawn Fridges' Attack UK Lawns
· [45] FCC Gives Final Sales Pitch For Broadband Plan
· [45] FCC Releases Copy Of The National Broadband Plan
· [34] Remember Zer01? They've Mysteriously Disappeared
· [33] Putting T-Mobile HSPA+ Through Its Paces
· [31] One Wireless Broadband Plan For All Your Devices
· [24] Verizon Pretends They've Not Been Blocking Broadband Mapping
· [16] A Closer Look At FiOS Installs In NYC
Most people now reading
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· WARNING: 2010 Census Cautions [Security]
· FiOS TV 2010 UPDATE: CHANNEL LINEUP CHANGES [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Dog]Not allowed to put your dog down? [General Questions]
· Scattered Web problems in Matawan, NJ [OptimumOnline]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Why so much hatred towards Bell? [TekSavvy]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· 2009-261 ADSL-CO proceedings [Canadian Broadband]