3 ms·
This is why we need SSL certs for .onions. DigiCert was doing this, but they told me it is on hold. Maybe when V3 hidden services are out? With an SSL cert, yo
by the_stc 9y ago
This is why we need SSL certs for .onions. DigiCert was doing this, but they told me it is on hold. Maybe when V3 hidden services are out?
With an SSL cert, you get a cert for your .onion PLUS your clearnet domain. Then users can access the .onion and see your real enterprise's name.
This should be doable even for extrajurisdictional companies like mine. The key is that your clearnet site should be a TCP-level proxy to the hidden service. That way the SSL keys are never on an easily-discoverable system so only IP addresses can be logged, not any contents. Slight plug: Here's the tech design for our system: https://medium.com/@PinkApp/pink-app-trading-latency-for-anonymity-and-other-techniques-815ee21c6da4 https://medium.com/@PinkApp/pink-app-trading-latency-for-ano... (ignore the clickbait title). This should work just fine for .onions too, even with the clearnet entry point. For a DarkNet Market, most small buyers are probably safe visiting over clearnet.
- jerheinze 9y agoSSL certs for .onions exist for years now, here are two examples: https://www.facebookcorewwwi.onion https://www.facebookcorewwwi.onion and https://protonirockerxow.onion https://protonirockerxow.onion Also v3 onion services are available now with Tor 0.3.2.x-alpha.
- the_stc 9y agoBut DigiCert says they are no longer issuing them. Probably because the .onion is an 80-bit truncation of a SHA1 hash so it doesn't meet baseline reqs?
- jerheinze 9y agoAh, so yeah that's probably why they were waiting for v3 onion services which are 56 characters long now (which are available now as mentioned above).
- schoen 9y agoI don't know what DigiCert's motivation was for suspending issuance of .onion certificates, but the CA/Browser Forum had given a special dispensation (by ballot) for issuance of EV certs despite the criticism about cryptographic strength mismatch. This dispensation didn't extend to DV, but it's never been revoked, so DigiCert would still apparently be able to continue its EV issuance if it wanted to! (But it looks like they've even let the facebookcorewwwi.onion certificate expire.) I've recently become an observer at the CA/Browser Forum and plan to bring up the subject of DV certificates for next-generation onion services imminently, just as soon as I'm done with my relaxing vacation!
- wybiral 9y agoWhat's the purpose of running a hidden service if you're clearly identifying yourself? Couldn't Tor users still visit your "clearnet" domain privately (it is just an onion-routing proxy, after all)?
- the_stc 9y agoThe point is to remain user-friendly while hiding the actual webservers, databases, and anything else that LE might want to take. An onion-routing proxy is easily setup and torn down and moved around quickly, making it a harder target for persistent surveillance.
- runeks 9y agoHow are .onion service providers supposed to communicate out to their users whether or not their site uses a certificate? And, presuming they are able to do this, why not just use that communication channel to communicate the correct .onion URL to the user in the first place (thus removing the need for a certificate authority)? EDIT: Perhaps it would make sense to create a separate URL type for Tor services whose keys are signed by a certificate authority? So the URL would become e.g. secure.smspriv6fynj23u6.onion, and the Tor browser would reject sites prefixed with “secure.“ that don’t have their key signed by a certificate authority. This way, an attacker must register with a certificate authority in order to phish a “secure.“ Tor site.
- wybiral 9y ago> Perhaps it would make sense to create a separate URL type for Tor services whose keys are signed by a certificate authority? The onion IS a proof of key. If you use the whole onion address (which is a hash of the public key) then Tor requires that the hidden service be able to prove they own the private key. It's like a builtin CA. The problem to me is that knowing someone has a key isn't as interesting as knowing that the person is a trusted source. And being anonymous takes some of the responsibility away. It makes more sense to me that someone just use an HTTPS clearnet site and users who want to protect their own IP address can access it from Tor (it works just fine). Protecting the site owners identity and then wanting to prove their identity to stop phishing attempts seems at odds to me.
- Buge 9y agoAre you talking only about EV certs? Because DV certs don't really display your enterprise name, at least not in an easily accessible location for users to see.