OF THE
TIMES
Willing is not enough; we must do. Knowing is not enough; we must apply.
“The values of the EU are the values of the Talmud” - Ursula von der Leyen. Let’s see if Sweden challenges that for real + what the backlash will...
The core EU countries have constantly demonstrated that laws mean nothing to their government and Bruessels. Neither on national nor on...
In the complacent and effeminate West, it doesn't really make a difference. What will really wake up the average man is the realisation of (real)...
Right hand golfers slice right (anticlockwise) Lefties left clockwise.
[Fico] was the only EU leader to attend this year's Victory Day parade on Red Square on May 9. See above wrt to human stupidity...
To submit an article for publication, see our Submission Guidelines
Reader comments do not necessarily reflect the views of the volunteers, editors, and directors of SOTT.net or the Quantum Future Group.
Some icons on this site were created by: Afterglow, Aha-Soft, AntialiasFactory, artdesigner.lv, Artura, DailyOverview, Everaldo, GraphicsFuel, IconFactory, Iconka, IconShock, Icons-Land, i-love-icons, KDE-look.org, Klukeart, mugenb16, Map Icons Collection, PetshopBoxStudio, VisualPharm, wbeiruti, WebIconset
Powered by PikaJS 🐁 and In·Site
Original content © 2002-2026 by Sott.net/Signs of the Times. See: FAIR USE NOTICE

HTTPS is a better bet for security than no encryption, but Tor is not a better bet than nothing.
The biggest problem is that anyone can run a Tor node (and since Tor nodes are trusted with however much network capacity they state they have and, thus, how much traffic they get, anyone can choose how much traffic they get as a Tor node, especially if they're running multiple nodes), effectively choose how much Tor traffic they get, and then sniff traffic as it goes through, including running "Man in the Middle" (MitM) attacks against HTTPS (SSL/TLS encryption). These attacks aren't theoretical. They're also easy to perform if you have a lot of resources, like one of the alphabet soup agencies. With all the known flaws of Tor and the EFF (as far as I know) not having addressed them with new releases or new software altogether, for them to be recommending using it I have to wonder if they have serious blinders on or don't have their users' best interests at heart (my money's on the latter...).
Article on a security researcher sniffing data after running a few Tor exit nodes and what he got:
[Link]
Article about using BEAST (the Browser Exploit Against SSL/TLS Tool), which actually breaks SSL 3.0 and TLS 1.0 encrypted sessions, not just bypasses them (TLS 2.0 is secure, but not deployed or adopted anywhere yet)
[Link]
Article about sidestepping SSL (author is really using SSLstrip, not SLLstrip)
[Link]
How Tor can leak data to a malicious end router
[Link]
More evidence of Tor exit node performing man in the middle attacks:
[Link]
Source discussion of the above evidence:
[Link]