this is the only node that I found patching binaries
This suggests the exit relay itself is doing the patching. Isn't it more likely that some MITM between the exit relay and origin server is responsible?
As he states, the way he found that node wasn't comprehensive. We shouldn't take that statement to mean there are no other exit nodes patching binaries. He just stopped after he proved it wasn't only a theoretical exploit.
Comments
This suggests the exit relay itself is doing the patching. Isn't it more likely that some MITM between the exit relay and origin server is responsible?
I don't see why would it be more likely. The exit node explanation is simpler.
As he states, the way he found that node wasn't comprehensive. We shouldn't take that statement to mean there are no other exit nodes patching binaries. He just stopped after he proved it wasn't only a theoretical exploit.
That's entirely possible and wouldn't be the first time that an exit relay's upstream or data center is responsible for MitM attacks.