Delivery-Date: Wed, 04 May 2016 08:45:23 -0400
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.1 required=5.0 tests=BAYES_00,DKIM_ADSP_CUSTOM_MED,
	DKIM_SIGNED,FREEMAIL_FROM,RCVD_IN_DNSWL_MED,T_DKIM_INVALID,T_RP_MATCHES_RCVD
	autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id 470531E02FF;
	Wed,  4 May 2016 08:45:22 -0400 (EDT)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id 6835D3AA28;
	Wed,  4 May 2016 12:45:18 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 85A5D3A9E5
 for <tor-talk@lists.torproject.org>; Wed,  4 May 2016 12:45:15 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id D-wyrEk2J3LI for <tor-talk@lists.torproject.org>;
 Wed,  4 May 2016 12:45:15 +0000 (UTC)
Received: from mail-yw0-x22f.google.com (mail-yw0-x22f.google.com
 [IPv6:2607:f8b0:4002:c05::22f])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (Client CN "smtp.gmail.com",
 Issuer "Google Internet Authority G2" (not verified))
 by eugeni.torproject.org (Postfix) with ESMTPS id 5C75F3A9C5
 for <tor-talk@lists.torproject.org>; Wed,  4 May 2016 12:45:15 +0000 (UTC)
Received: by mail-yw0-x22f.google.com with SMTP id g133so76620974ywb.2
 for <tor-talk@lists.torproject.org>; Wed, 04 May 2016 05:45:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to;
 bh=m+gx7SdyuCkJJQd+aE8wJfZP9AVMSqu9OAGefxKka/0=;
 b=h3J6IOT5tOS0Y/dBljccLx2G3mIaqueXG/1s8LOnpITsVklO4wjmlg0HIPTmw/NSkO
 uVRzy7+5fVjLO5sKbJzhBjjAnqvKlJZbUM7/1RnZSllbgfq1ID5PuTmZm2JhCbxpdahI
 mipCVzfVSMtGr5WiFktkxmFsZ1Ib9qgBBZAbj7d8Wno727GC/xPnBkku9bOvRYzzMASI
 b8G9r0n1Zskx0h+BpZ6cly3Ns8kkLYZSMo1QaVSYhzAT9wKtlgrbPLt2jrDld4DJV0C8
 GAZpinu8RCbYdNTz7XEspLcPpB/QpmQ6JP1LVmecXVKJRleW/QqIKU8juNfNH0zfwVmY
 fR+Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:mime-version:in-reply-to:references:date
 :message-id:subject:from:to;
 bh=m+gx7SdyuCkJJQd+aE8wJfZP9AVMSqu9OAGefxKka/0=;
 b=BrRtoS+FaRwtwTUtbMJD15HiSnHqSL1LsPJ8gaxNhSwjdMo8ZIUh0LEI3W4FbBpXa3
 Nt6xjOrkXNG3cIJpZOlAKfH8Bk7EmsI4otH5mTc7u//Tu+NRSTxckBNtKSQ217W4Ae9w
 JfM4S4VeGC/Hop4QI/zMOK5DqLqOVMQXs7bOF9KPHS3+7NfUnBWwjn9jvwvD3krBcptH
 o7PWyj2yQOZy1MDY7wP0JMIr7XLN2M8DJgR73Hq9h6gqDXubzXcKrDBm5NO+FHbVyQvI
 YKqJDKhJfbnNaYopSx4gGvEFJSPUZ4tBIGG/eHWi4q38DdO5DUwkIehJaH3+6z3ObdM6
 c4yw==
X-Gm-Message-State: AOPr4FU7yGL5CD0/v/HxWTp7YOTN5nxPQRkadatR+9wtQmsZfVIMKqvgg6Z42rPKJNXP11nD0hzFzWogxERc7A==
MIME-Version: 1.0
X-Received: by 10.37.13.197 with SMTP id 188mr1099596ybn.163.1462365913071;
 Wed, 04 May 2016 05:45:13 -0700 (PDT)
Received: by 10.13.243.195 with HTTP; Wed, 4 May 2016 05:45:12 -0700 (PDT)
In-Reply-To: <CAJ8LpWpTNxBvPqRut=ELX-XC2V60p8v0u5S7p+iRnE0Lu10M2A@mail.gmail.com>
References: <CAJ8LpWp_yr5KDSHKg0z72FL-s82QYNVaS9Ob5efzftViTqnA=Q@mail.gmail.com>
 <5729E33D.3080706@mailbox.org>
 <CAJ8LpWpTNxBvPqRut=ELX-XC2V60p8v0u5S7p+iRnE0Lu10M2A@mail.gmail.com>
Date: Wed, 4 May 2016 08:45:12 -0400
Message-ID: <CAB7TAM=a=oiuMHH78Q84RnR+vmRmVeOZb_EtWF5BGZzofZ+YyQ@mail.gmail.com>
From: Allen <allenpmd@gmail.com>
To: tor-talk@lists.torproject.org
X-Content-Filtered-By: Mailman/MimeDel 2.1.15
Subject: Re: [tor-talk] MITM attack: How to see Tor Messenger's exit node?
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

> Are there any other explanations than MITM?

A software bug.  But given that your desired opsec is to be resistant to
MitM attacks, you should always perform the required authentication steps
regardless.  Note that in any reasonable software, you shouldn't have to
compare fingerprints every conversation--instead you should only have to do
this once and the software should then store some kind of credentials so it
can perform automated authentication.  If "Tor Messager" makes you check
fingerprints every time you start a fresh conversation, you might want to
look for another solution.
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

