|
|
|
|
|
by Someone1234
4249 days ago
|
|
I think Tor is great. But Tor is inherently insecure, and the easier you make it for "normal" users to utilise Tor the more users who will get caught out by Tor's inherent insecure nature. You're trading security for anonymity. That's should be Tor's unofficial tag-line. I don't even need to convince you of Tor's relative insecurity, there is a front page article right now all about it: https://news.ycombinator.com/item?id=8501557 |
|
The major users of Tor need to consider even their ISPs as an adversarial agent - that they are being actively monitored and MITMed. In this sense, these users are not trading security for anonymity.
For those who trust their telecommunications carriers (in the US even in the face of CALEA) - they are certainly introducing a MITM. It's also important to note that the linked article considers the 'security bug' to be owned by software updaters and software vendors that that do not sign binaries - the vulnerabilities are not specific to Tor, but it does provide one mechanism to exploit them.
This is all a good reminder, as the Tor team themselves regularly say, that secure operational browsing and software practices are crucial to anonymity and security even with Tor installed.