And just to clarify for people, this is no worse than ANYPLACE you log in using unencrypted credentials - any wireless cafe, airport hotspot, wherever. All these places can potentially grab unencrypted data.
The difference here is that TOR is often used to anonymize traffic, so people use it thinking they are secure. But since these are routers, people can set up their own nodes (which is encouraged), including the dark side of society, and they now have access to all the data passing through.
Just remember that you are vulnerable. Heck logging into CP your password is unencrypted and could be picked up by a packet sniffer. But will a hacker really care about your CP login? Probably not, but there are probably other sites that don't have security set up correctly, that is the real crux of the issue the analyst was trying to bring to light.
(Banks do it correctly - if you notice when you log on to a bank site the URL starts https: )
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
|