[tor-talk] Differences between real exit traffic and exit-generated traffic ?

John Case case at SDF.ORG
Fri Dec 30 07:42:20 UTC 2011

Let's say I have an exit node handling average traffic and number of 
connections (whatever that is).  Let's also say that port 22 is included 
in my exit policy.

Now let's say that I, as the administrator, log onto the exit node and:

ssh user at host.com

I understand that a global observer with traffic analysis blah blah blah.

But what about someone just watching the exit node ?  Is there anything at 
all about my ssh connection generate from within the exit node that would 
distinguish it from "real" exiting Tor traffic ?

