6 ms·
What’s the advantage of accessing an onion service (as opposed to accessing a normal https website over tor)?
by surround 6y ago
What’s the advantage of accessing an onion service (as opposed to accessing a normal https website over tor)?
- ve55 6y agoThe website cannot identify who they are, what ISP they use, or where they live. Similarly, middleboxes such as their ISP cannot find out what websites they are browsing, which is still easily possible even with TLS via many methods (DNS, SNI, IP correlation, many others)
- surround 6y agoWhat I mean is, how is a .onion website over tor better than an https website over tor? I edited my comment to clarify.
- threentaway 6y agoThe traffic never leaves the Tor network. This has a few advantages: * You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end * The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic * It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion endpoint
- surround 6y agoIf certificate authorities are a concern, then why do some onion services use https?
- danielheath 6y agoIf I had to guess, it’d be because TOR users are not a solid block with identical opinions.
- zaarn 6y agoTor public keys don't prove identity (ie, that is cloudflare.com) while such a certificate over, for example, Alt-Svc headers does. Pure .onion certs exist as well and give extra reinsurance that you're on the correct website.
- deleted 6y ago[deleted]
- boring_twenties 6y agoIn theory no one can spoof a Tor hidden service. The service name itself encodes the public key, and only the corresponding private key can authenticate. Much better than https, where you have many dozens of "trusted" authorities, any one of which can compromise you. And also it precludes any attacks a malicious exit node could run on your https traffic, like the other comment says
- t0astbread 6y agoI am not an expert but as far as I understand it's harder to do correlation attacks when you're able to monitor network traffic when communication stays inside the Tor network. Additionally, you're replacing (or extending) CAs with Tor's public key cryptography for authentication and encryption. Computerphile did an interesting video series on this!
- moonchild 6y ago> replacing (or extending) CAs with Tor's public key cryptography Which is good because CAs are useless; they're complete overhead. Back when EV certificates meant something, they were marginally useful, but at this point, we might as well just switch to a TXT record that validates domain ownership. (Obviously, that doesn't protect against DNS MITM attacks, but that's a separate issue.)
- t0astbread 6y agoOh you mean storing some data to cryptographically verify that a particular server is associated with a domain? If I'm not mistaken, that's what .onion addresses are. I wonder if anyone has tried putting .onion addresses into DNS and have clients treat them like address records...
- superkuh 6y agoThe domain is actually owned by the person running the website rather than leased on the whim of some corporation all too eager to bow to external pressures.
- 0xggus 6y agoLocation hiding An onion service's IP address is protected. Onion services are an overlay network on top of TCP/IP, so in some sense IP addresses are not even meaningful to onion services: they are not even used in the protocol. End-to-end authentication When a user visits a particular onion, they know that the content they are seeing can only come from that particular onion. No impersonation is possible, which is generally not the case. Usually, reaching a website does not mean that a man-in-the-middle did not reroute to some other location (e.g. DNS attacks). End-to-end encryption Onion service traffic is encrypted from the client to the onion host. This is like getting strong SSL/HTTPS for free. From here: https://community.torproject.org/onion-services/overview/ https://community.torproject.org/onion-services/overview/ And there's another good reason for the Tor network: if you run an onion service, the traffic will use only Tor non-exit nodes in the circuit, giving a relief to the exit nodes.
- jack46644g 6y agoCost savings. Running web apps behind a dynamically allocated ISP.