7 ms·
Tor Browser User Manual
- tomtommer 10y agoIs this "news" really worthy of HN?
- sun_n_surf 10y agoLol, it's a trap. I get an untrusted certificate.
- noja 10y agoI don't, I get a valid DigiCert cert.
- akerro 10y agoYup, same here https://i.imgur.com/PsYzYmV.png https://i.imgur.com/PsYzYmV.png
- mnx 10y agoI get a valid cert, with the S/N: 05:CA:2A:A9:A5:D6:ED:44:C7:2D:88:1A:18:B0:E7:DC
- aq3cn 10y agoHow do I view the link?
- witty_username 10y ago> https://webcache.googleusercontent.com/search?q=cache%3Ahttps%3A%2F%2Fblog.torproject.org%2Fblog%2Fannouncing-tor-browser-user-manual https://webcache.googleusercontent.com/search?q=cache%3Ahttp... Tip: in Google search you can type cache:<URL> to see Google's cached version of a page.
- overlordalex 10y agoIt's because they're using a stricter form of https, which fails if your company messes with the certs (I'm guessing proxy problems). This is what it looks like for me: > Certificate Error There are issues with the site's certificate chain (net::ERR_CERT_AUTHORITY_INVALID). Issued To Common Name (CN) blog.torproject.org Organisation (O) <Not Part Of Certificate> Organisational Unit (OU) <Not Part Of Certificate> Issued By Common Name (CN) $my_company Web Gateway Organisation (O) $my_company Organisational Unit (OU) $my_company_infrastructure_unit
- noja 10y agoHow do you generate a stricter cert like this?
- tucif 10y agoUsing HSTS (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/St...) From the RFC 6797 : (https://tools.ietf.org/html/rfc6797#page-27 https://tools.ietf.org/html/rfc6797#page-27) 11.3. Using HSTS in Conjunction with Self-Signed Public-Key Certificates If all four of the following conditions are true... o a web site/organization/enterprise is generating its own secure transport public-key certificates for web sites, and o that organization's root certification authority (CA) certificate is not typically embedded by default in browser and/or operating system CA certificate stores, and o HSTS Policy is enabled on a host identifying itself using a certificate signed by the organization's CA (i.e., a "self-signed certificate"), and o this certificate does not match a usable TLS certificate association (as defined by Section 4 of the TLSA protocol specification [RFC6698]), ...then secure connections to that site will fail, per the HSTS design. This is to protect against various active attacks, as discussed above. However, if said organization wishes to employ its own CA, and self- signed certificates, in concert with HSTS, it can do so by deploying its root CA certificate to its users' browsers or operating system CA root certificate stores. It can also, in addition or instead, distribute to its users' browsers the end-entity certificate(s) for specific hosts. There are various ways in which this can be accomplished (details are out of scope for this specification). Once its root CA certificate is installed in the browsers, it may employ HSTS Policy on its site(s).
- Wheaties466 10y agowhich company is your organization using for web filtering?
- SticksAndBreaks 10y ago[UK-Edition] Install Instructions: Click the Executable. Wait for the Police to arrive.
- secfirstmd 10y agoBlatant Plug For loads more digital and physical security manuals and advice (from using TOR to dealing with physical surveillance) that work offline on your phone, we launched an open source app called Umbrella to make it a bit easier. -https://play.google.com/store/apps/details?id=org.secfirst.umbrella https://play.google.com/store/apps/details?id=org.secfirst.u... -https://www.amazon.com/Security-First-Umbrella-made-easy/dp/B01AKN9M1Y https://www.amazon.com/Security-First-Umbrella-made-easy/dp/... -https://secfirst.org/fdroid/repo https://secfirst.org/fdroid/repo -Code and Content - https://github.com/securityfirst/ https://github.com/securityfirst/ -Code audit - https://secfirst.org/blog.html https://secfirst.org/blog.html -More info - https://secfirst.org https://secfirst.org Ends blatant plug :)
- 01Michael10 10y agoHow many more posts are you going to plug this app on? How about you make this the last one...
- secfirstmd 10y agoPoint taken!
- ComodoHacker 10y agoAnd please fix your main page.
- secfirstmd 10y agoThanks for the heads up!
- noja 10y agoI don't mind your plug, but two of those links are broken.
- secfirstmd 10y ago
- idkwatm888 10y agoIf anyone here is interested in running a Tor relay or Tor exit node that is pro-active to prevent abuse from crimeware/malware/ransomware, Check out https://github.com/torworld/ https://github.com/torworld/ or http://TorWorld.org http://TorWorld.org