who has done https aka #SSL over onion #asknostr

(saw a few somewhere - guess many technical ways to do it - dns expensive + attack prone)

wss aka secure websocket may also possibility over 🧄

Reply to this note

Please Login to reply.

Discussion

I think these are self signed certs, but honestly, ssl on a Tor Service (.onion site) is not useful afaik. The traffic is end to end encrypted already.

nope u missed big part last leg cleartxt - hence using any cert to encrypt is big think

who issue cert is not important - dummy self sign whatever so long sniffer cannot be content is good enough

Only if you are visiting a normal website. For .onion site, it is e2e encrypted.

Actually says it here too: https://tb-manual.torproject.org/onion-services/

NOPE IT WORNG EXIT NODE TO FINAL SITE = CLEARTXT

even in end to end onion there is possiblity with split traffic vs exit tor to clearnet site without ssl