3 ms·
What I mean is, how is a .onion website over tor better than an https website over tor? I edited my comment to clarify.
by surround 6y ago
What I mean is, how is a .onion website over tor better than an https website over tor? I edited my comment to clarify.
- threentaway 6y agoThe traffic never leaves the Tor network. This has a few advantages: * You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end * The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic * It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion endpoint
- surround 6y agoIf certificate authorities are a concern, then why do some onion services use https?
- danielheath 6y agoIf I had to guess, it’d be because TOR users are not a solid block with identical opinions.
- zaarn 6y agoTor public keys don't prove identity (ie, that is cloudflare.com) while such a certificate over, for example, Alt-Svc headers does. Pure .onion certs exist as well and give extra reinsurance that you're on the correct website.
- deleted 6y ago[deleted]
- boring_twenties 6y agoIn theory no one can spoof a Tor hidden service. The service name itself encodes the public key, and only the corresponding private key can authenticate. Much better than https, where you have many dozens of "trusted" authorities, any one of which can compromise you. And also it precludes any attacks a malicious exit node could run on your https traffic, like the other comment says