3 ms·
You're correct, but I recall a Tor dev saying at one point that HTTPS for .onion wasn't completely useless, I think in that more secure settings (CSP, etc.) app
by milkey_mouse 6y ago
You're correct, but I recall a Tor dev saying at one point that HTTPS for .onion wasn't completely useless, I think in that more secure settings (CSP, etc.) apply to pages loaded with HTTPS.
- jeremiahlee 6y agoThe Tor Project discussed the advantage a little in this blog post ("Part four: what do we think about an https cert for a .onion address?"): https://blog.torproject.org/facebook-hidden-services-and-https-certs https://blog.torproject.org/facebook-hidden-services-and-htt...