Re: Moxie Marlinspike

     On Thu, 19 Feb 2009 07:17:04 -0500 Erilenz <erilenz@xxxxxxxxx> wrote:
>There's nothing in there that we didn't already know was possible, and I realise
>it's not a Tor specific flaw. I just read this paragraph and thought I'd pass it
>on here:
>"Marlinspike also claimed that in a limited 24 hour test case running on the
>anonymous TOR network (and without actually keeping any personally identifiable
>information) he intercepted 114 yahoo logins â 50 gmail logins, 9 paypal, 9 
>inkedin and 3 facebook. So apparently the tool works - and works well."

     Thank you very much for pointing out yet another unscrupulous exit
operator.  I've just added

ExcludeExitNodes thoughtcrime,$1E6882D9AB86DA56C48BDE96698B8F8AF81FD707

to my torrc file.
>Lots of people simply don't know how to use Tor safely.

     Very true, but then, lots of people simply don't know how to use the
Internet safely.  Lots of people don't bother to buy and use a paper shredder
to dispose of sensitive USnail safely.
>I wonder if something could/should be built into TorButton to force a list of
>commonly used services to go entirely over https? Eg any request for
>Also, how feasible would it be to add a popup which says something along the
>lines of:
>"You are about to post unencrypted data over the Tor network. Are you sure you
>wish to proceed?"

     It's looks like a good idea, but what about pop-up blockers?  Maybe it
should be built into browsers, perhaps enabled as a configurable option turned
on by default.

