Re: same first hops

ok understood, so in actuality he would have to be observing 3 things:
1) The user' s computer (timing and size)
2) the first hop ((timing and size)
3) the last hop ((timing, size and anythign else)
He would have to be observing the user computer, as there would be no other way to correlate the first hop with the user, since the IP is hidden at the first hop, correct?
On Thu, Oct 9, 2008 at 6:41 AM, Gregory Maxwell <gmaxwell@xxxxxxxxx> wrote:
Sorry, I accidentally hit send.

Consider: Nothing prevents you from running multiple tor nodes. A well
funded party might run dozens or hundreds.  If the attacker controls
both the entry and the exit that you are using he can look at the
unencrypted traffic leaving the exit and correlate it with the timing
and sizes of the data on the the entrances he controls.  He could also
do things like intercept your TCP connections leaving the exit and
stuff them with megabytes of junk data and then watch for the traffic
spike on any of the entrances he controls.

If you think about it for a bit you'll realize why changing entrances
all the time would maximize your exposure to this attack. Eventually
you would land on the bad guy's entrance and he could track you down.