MustEat.org

Last updated: 03:39PM 09/11/07

The basic summary, is that various sections of the US Government IT staff had indicated to staff to make use of Tor to send confidential information. Unfortunately, they didn’t make use of end to end encryption, so when the data got shot out the other side, the plain text contents of highly sensitive information could be scooped up by the operator of the exit Tor node.

Even if the report is fake: This is a very real tactic.

Packet Sniffing Tor Exit points

Pulled from ZD Net: Zero Day

More at ISC Sans

FAQ at Tor

When you have access to that much raw data, it’s impressive what you can find when you look for it.

Tags:
weblog security Tor