Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If Appelbaum actually works on Tor then just BadExit'ing his nodes is obviously not enough. Even a clean compile (for the paranoid: do you trust your compiler?) from a fully audited (do you have the resources?) source code is not enough. In order to use Tor you gotta trust the other nodes, including the code that runs there.


I doubt Jacob is hacking his own code, he'd have way too much to lose and I do believe he actually loves the project. If he were to do anything it'd be handing interesting traffic off various exit nodes he and friends control to Wikileaks. That'd be about all I or anyone else could allegedly claim.


Ok, but (if I understand how Tor works) then the fact that he works on Tor has nothing to do with his control of exit nodes. Anybody can run an exit node, whether or not they work on Tor.


Especially since bad actors (including governments) have been running exit nodes and sniffing the traffic — Wikileaks got its start by doing it, and the Chinese got access to a bunch of embassy webmail accounts that way.

Tor exit nodes are already extraordinarily untrustworthy, one run by anyone associated with Wikileaks might as well be a chinese room with Hitler inside!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: