3 ms·
I guess that all of the private keys for the onion services will be gone too. Even if they aren't, they can't be used anymore anyway as they should be assumed t
by jamieweb 8y ago
I guess that all of the private keys for the onion services will be gone too. Even if they aren't, they can't be used anymore anyway as they should be assumed to be compromised.
I hashed for a month to get a vanity one, others have done longer. Did this hosting service allow custom private key uploads?
- kodablah 8y agoAlso, if private keys were obtained, it's trivial to republish to the same onion address with any changes you want. This is that one scenario where an EV cert that can be revoked has value if you're a non-anonymous hoster. There are other alternative-factor identity verification techniques (e.g. DNS, Alt-Svc HTTP header) but the querying aspect reduces anonymity.
- jamieweb 8y agoWith the DNS and Alt-Src, are you saying that the Onion site identity can be verified by visiting the non-onion version of the site, and then relying on the header/DNS record to take the session onto Tor? Then when the onion service private key is breached, the site operator just changes the header and DNS record to a new, non-breached one? As you say though, querying these does reduce anonymity.
- kodablah 8y agoYup (well, automatically with Alt-Svc when using the Tor browser, some kind of manual TXT record I would guess with DNS, I don't know of anything standardized)
- danieltillett 8y agoIs it wise to have a vanity private key in this circumstance?
- brokenmachine 8y agoI presume OP didn't mean he hashed until the key was his social security number and name.
- danieltillett 8y agoNo but I assume he chose something that was of meaning to them. You really don't want to turn something that should be anonymous into something that could be traced back to you.
- jamieweb 8y agoYes, the first characters are just my name. The hidden service is for my public blog, so it's deliberately non-anonymous.