[Cryptography] MITM attacks on Tor exit nodes

Henry Baker hbaker1 at pipeline.com
Mon Jun 8 13:28:14 EDT 2015


I noticed my first MITM attack on a Tor circuit today, thanks to the recent upgrades of Tor & Firefox.

Basically, https://www.wired.com complained that the TLS had been "downgraded" to an obsolete cipher.  After asking Tor to establish a new Tor circuit for this site, the "problem" went away -- because the intermediate & exit nodes were different (and presumably un-MITM'd).

Chinese?  FBI?  Bueller?  Anyone?



More information about the cryptography mailing list