3 ms·
No - each name is checked before issuance. .onion is an interesting one though since there isn't WHOIS info. The only check there is to download Tor and check
by AmustheGreat 12y ago
No - each name is checked before issuance. .onion is an interesting one though since there isn't WHOIS info. The only check there is to download Tor and check that FB controls the service.
- feld 12y agoAnd there's been another article now showing that someone else was able to successfully obtain a certificate for that same .onion address.
- wowaname 12y agoOr to give the CA a copy of the private key to establish ownership of the onion. This would be more trustworthy IMO since there would be no chance of phishing lookalikes or something akin to the "onion cloner" MITM attack. EDIT: Or simply redirecting myownfacebook420.onion to facebook.com, because that can VERY easily be done. Just add a HiddenServicePort 80 facebook.com:80 to the torrc.
- nintendo1889 12y agoThen the CA also has a copy of the private key and a malicious person could use that key.
- wowaname 12y agoHey, CAs shouldn't be trusted in the first place.
- iancarroll 12y agoThat's frankly a horrible idea. What you should do is simply have them generate a CSR using the key - CSRs are signed by the key.
- wowaname 12y agoYou can drop the Hacker-News trademark "fuck your comment" so I could actually agree with you without first telling you you're rude.