logoalt Hacker News

londons_exploretoday at 6:21 PM3 repliesview on HN

But isn't it unnecessary to use https, since tor itself encrypts and verifies the identity of the endpoint?


Replies

charcircuittoday at 6:33 PM

For example HTTP/2 and HTTP/3 require HTTPS. While technically HTTPS is redundant, .onion sites should avoid requiring browsers to add special casing for them due to their low popularity compared to regular web sites.

gizmo686today at 7:18 PM

It would give you a certificate chain which may authenticate the onion service as being operated as who it purports to. Of course, depending on context, a certificate that is useful for that purpose might itself be too much if an information leak

show 1 reply
rnhmjojtoday at 6:24 PM

Yes, but browsers moan if you connect to a website without https, no matter if it's on localhost or an onion service.

show 1 reply