Somewhere in Russia, a spy is running a data collection network, using Tor for anonymity. And he's particularly interested in what users do on Facebook.
That's the conclusion of two researchers who used custom software to test Tor exit nodes for malicious behavior, in a four-month study published recently.
Philipp Winter and Stefan Lindskog of Karlstad University in Sweden identified 25 nodes that were embedded in web traffic, without encryption or monitored sites. Some of the faulty nodes likely resulted from configuration errors or ISP issues. However, 19 of the nodes were caught using the same fake crypto certificate to perform man-in-the-middle attacks on users, decrypting and then re-encrypting the traffic.

