This is part 2 of my RSA Conference 2006 wrap-up. Bruce Schneier: There are far too many legitimate users compared to attackers. Nitesh Dhanjani discussed penetration testing techniques and tools. He emphasized how he only uses open source tools for his work, because they are so easily customized to meet his requirements. He described problems with the Google Firefox anti-phishing toolbar, namely that it sends all GET requests in clear text to Google — even those referenced via HTTPS. He also discussed how to use Tor to anonymously attack Web servers.”]
Source: https://taosecurity.blogspot.com/2006/02/rsa-conference-2006-wrap-up-part-2.html