[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-dev] HTTPS Server Impersonation



On Mon, Sep 30, 2013 at 01:03:14AM -0700, Rohit wrote:
> This should satisfy most goals.
> - A passive attacker wouldn't be able to distinguish between HTTPS->HTTPS traffic and Tor->Bridge. (Both use TLS)

This seems false to me; it's not too hard to distinguish Tor-over-TLS
from HTTP-over-TLS, right?

   - Ian
_______________________________________________
tor-dev mailing list
tor-dev@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev