Defeat Exit Node Sniffing?

Gregory Maxwell gmaxwell at gmail.com
Mon Mar 3 02:18:51 UTC 2008


On Sun, Mar 2, 2008 at 6:34 PM, Michael_google gmail_Gersten
<keybounce at gmail.com> wrote:
[snip]
>  Here's a simple idea. Just as search engines added a "robots.txt"
>  file, how about a web server providing a "torexit.txt" file, which is
>  simply the list of tor exit nodes that the server considers "close" to
>  itself?
[snip]

The 'right' way to do this would be to signal it in DNS.  By signaling
it in DNS you'd avoid another round trip, etc.    The problem with
doing it in DNS is that DNS isn't widely authenticated.   ... which is
ashame since it could be.. dnssec exists for that purpose.



More information about the tor-talk mailing list