Hacker News new | ask | show | jobs
by kmlymi 4573 days ago
I think it's because he was the only one accessing TOR on a monitored network during the specific time.
2 comments

Almost certainly.

I'm at reasonably large (~15000 students on-campus), and a friend using TOR to do ... something ... got caught not because he was the only one using TOR at the time, but because he was the only one using TOR, ever -- it was just too obvious.

Reminds me of this XKCD: http://xkcd.com/1105/
How did they know the something was done by someone using TOR on their network?
There's a list of IPs that TOR networks run on, so they could just cross reference that.
tor exit nodes are easy to identify, if they had the co-operation of site.com then they'd not see the location, but they'd see the exit node.
I can understand they can the attack was done through Tor, what I don't understand is how they understood the attack originated on their own network through Tor.
It came from a TOR ip.
Good old Signal Intelligence.