andrew s
unread,Apr 9, 2013, 8:25:57 PM4/9/13You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Zak Hipp wrote on Tue, 09 Apr 2013 19:40:15 +0100:
> Thank you for the reply.
Thank YOU for trying to help!
I asked because I had figured someone _must_ have run into this, and I
very much appreciate your advice and efforts.
In summary, here's the compromised scenario for the uninformed:
- User starts Tor Browser Bundle (TBB) and gets IP address #1.
- User visits political web as user A with IP address #1.
- User converses with others on political web page as user A.
- User then presses the TBB "Start Private Browsing" button.
- This gives user1 a blank page & wipes out cookies.
- But, this does NOT change the IP address from IP address #1.
- Therefore, user presses the TBB "New Identity" button.
- Now the user's IP address traces back to IP address #2.
- User again visits the aforementioned political web page.
- User converses with others on political web page as user B.
... coming up is where the mistake is made ...
- When conversing is done, user presses TBB "Stop Private Browsing".
- ... BAMM! ... TBB brings user back to user A at the web forum!
... The problem is that IP address #2 is also conveyed to the forum!
... The forum can easily connect user A & user B by the same IP!
The user's identity has been compromised without him even realizing it.