6 ms·
Twitter's onion service is serving an invalid TLS certificate since 3/6/2023
- gaganyaan 3y agoNot surprising. That seems like something he wouldn't care about up until it could somehow be used to own the libs or whatever. There's probably nobody left that even knows about the onion service.
- waihtis 3y ago[flagged]
- WallyFunk 3y agoI don't understand the premise of Twitter having an .onion hidden service. They're anti-anonymity, at least from my experience, where they extorted my phone number from me so I could continue to use their service. Mixing PII with Tor defeats the purpose of anonymity. You're immediately outed by providing a phone number or even en e-mail.
- parineum 3y agoAccessing Twitter from countries that don't have any way to force Twitter to divulge information is the purpose.
- atkailash 3y agoI think it’s intended to circumvent government blocks in times of unrest to ensure communication
- Forbo 3y agoJust a heads-up, it looks like your account might have been shadowbanned? You last few comments were all dead, as well as this one when I first saw it. Looks like someone else may have already vouched for it though.
- bboygravity 3y agoThis goes for every single website on clearnet though? If not phone number, they have your IP and location, timezone, likely waking hours, private chats, search queries, who you communicate with and when etc. If not collected by the webmaster then it is automatically collected by whatever government the server sits in (+ whatever governments that government trades data with). The times of anonymity on the internet/clearnet are long gone.
- astrange 3y ago> If not collected by the webmaster then it is automatically collected by whatever government the server sits in (+ whatever governments that government trades data with). It certainly is not, that's what we did all that HTTPS perfect forward secrecy for.
- bastawhiz 3y agoNonsense. The threat model that onion routing protects against is a middle man intercepting the traffic, not from Twitter knowing who you are. It still offers value.
- godelski 3y agoIt's not too hard to get a temporary voip phone number if required to sign up for a service, but when I signed up this wasn't needed. Just don't use your phone. You can also get dummy, private, or temporary email addresses. Yeah, the scraping makes things harder, but it's perfectly doable to get these services completely anonymously. I mean hell, NYT, WP, CNN, Reuters, etc all have Signal and most have Secure drop, which is via Tor, to connect to them. Interestingly it looks like Fox is the only major platform not have any method I could find from a single search.
- mattsan 3y agoI can hear the people in charge on the onion service that were fired laughing
- ocdtrekkie 3y agoThis is the sort of thing that if it even exists at a large company is a pet project of one enthusiast, and obviously that enthusiast was laid off. I doubt a single person at Twitter today cares if their onion service works.
- sassy_quat 3y ago[dead]
- ThePowerOfFuet 3y agoWhy are they even using TLS? Onion services bring their own security.
- dewey 3y agoThat was a bigger discussion when Facebook did it back in the days and there's really no clear reason for and against it. In the end it mostly boils down to "regular people were educated that https is needed, so it's better to just keep doing that instead of explaining Tor to them". Which is a fair point I think. https://blog.torproject.org/facebook-hidden-services-and-https-certs/ https://blog.torproject.org/facebook-hidden-services-and-htt...
- sva_ 3y agoIf there is no reason for it, then that is a reason against it. Regular people probably don't use Tor.
- duskwuff 3y agoThere's an annoying practical reason to use HTTPS on Tor: some browser features are gated on the page being served from an HTTPS origin. Some of them (like geolocation and payment requests) are likely to be irrelevant to most Tor users, but others (like HTTP2 and Web Crypto) are more generally relevant. https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts/features_restricted_to_secure_contexts https://developer.mozilla.org/en-US/docs/Web/Security/Secure...
- derefr 3y agoMind you, most of these TLS-origin-requiring features are only accessible through Javascript APIs — and so won't be used by any "zero trust" Tor hidden services (which must assume the client's Javascript is disabled) anyway.
- deleted 3y ago[deleted]
- stathibus 3y agoTwitter should not care about having an onion service. Great example of a distraction that the Musk downsizing properly removed.
- kakwa_ 3y agoMaybe, but then, why the onion service is still up? This feels more like uncontrolled infrastructure rot/lack of maintenance rather than a conscious decision to cut unnecessary parts of it.
- avs733 3y agoDid they properly remove it or does no one there even know it was/is happening. They didn’t shut it down, the seem to have left the lights on with nobody home. Bigger picture - given the role news making and sharing in real time has always played in Twitter, it seems logical that services which may not provide obvious returns but which build a platform that journalists find useful would help do that.
- stathibus 3y agoI agree, it seems like they left it to rot instead of shutting it down. But again it is irrelevant to the business so who cares?
- rmwaite 3y agoMy understanding is the onion service was launched to provide access for people in places where Twitter is blocked. How is this "irrelevant to the business"?
- takoid 3y ago[dead]
- silas 3y agoAlso noticed that the Status page linked from the logged out https://twitter.com https://twitter.com page has been expired since Aug 29. Not especially interesting, but probably an indication that some of the non-core stuff is getting overlooked.
- abraham 3y agoThe API page is still up https://api.twitterstat.us/ https://api.twitterstat.us/
- devilkin 3y agoI guess they'd care if they could monetize it.
- jimrandomh 3y agoGiven that Twitter is the target of a lot of manipulation attempts, some of which come from intelligence agencies, having a .onion service seems like an actively bad thing. This seems like the sort of thing that a spy who snuck through the hiring process would build. Leaving it unmaintained seems worse than taking it down (especially since that implies a lack of monitoring that would invite abuse), but it definitely ought to go down.
- cedws 3y agoI mean, it's not like Twitter can't see where the traffic is coming from. If you start seeing thousands of users tweeting the same thing over Tor, it's a pretty obvious campaign.
- weare138 3y agoAnd what about users in countries with hostile governments? Your online posts get you killed in places like Saudi Arabia. The state will literally execute you. If there's a conspiracy here that's why Twitter's 'secure' TOR access is less secure now.