4 ms·
The Tor service model is equivalent to if every site used a self-signed certificate, which doesn't scale. The more feasible CA-free architecture is to have the
by dadrian 2y ago
The Tor service model is equivalent to if every site used a self-signed certificate, which doesn't scale.
The more feasible CA-free architecture is to have the browser operator perform domain validation and counter-sign every sites key, but that has other downsides and is arguably even less distributed.
- jeroenhd 2y agoThe Tor system does scale, as Tor itself proves. Tor just lacks domain names all together and reuses public keys for site identification instead. Is the tor node you're accessing the real Facebook or just a phishing page intercepting your credentials? Better check if the 60 character domain name matches the one your friend told you about! I don't think putting any more power in browser vendors is the right move. I'd rather see a DNSSEC overhaul to make DANE work.