Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 11 hours ago

New blogpost:

"decoded.legal's .onion site no longer has TLS / https"

I've just turned off the TLS cert and config for dlegal66uj5u2dvcbrev7vv6fjtwnd4moqu7j6jnd42rmbypv3coigyd.onion.

This does not affect decoded.legal's clearweb site.

https://neilzone.co.uk/2026/02/decodedlegals-onion-site-no-longer-has-tls--https/

#Tor #encryption #blog

  • Copy link
  • Flag this post
  • Block
barsteward
barsteward
@barsteward@infosec.exchange  ·  activity timestamp 11 hours ago

@neil From a technical perspective, someone running a tor exit node could spoof the destination website, so a TLS certificate allows detection of this. Having said that, I can’t imagine there’s significant demand for a tor site in the first place.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 11 hours ago

@barsteward

> someone running a tor exit node could spoof the destination website

.onion traffic doesn't go through an exit node?

  • Copy link
  • Flag this comment
  • Block
barsteward
barsteward
@barsteward@infosec.exchange  ·  activity timestamp 11 hours ago

@neil You’re correct; my bad choice of description there - but doesn’t the same apply to the final node (whether or not it exits the tor network)?

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 11 hours ago

@barsteward Not as far as I know, but then, were it true, it would be a significant weakness in Tor / .onion services, which I should have thought would be widely publicised...

  • Copy link
  • Flag this comment
  • Block
barsteward
barsteward
@barsteward@infosec.exchange  ·  activity timestamp 10 hours ago

@neil Maybe I need to check my understanding of tor routing!

  • Copy link
  • Flag this comment
  • Block
RevK :verified_r:
RevK :verified_r:
@revk@toot.me.uk  ·  activity timestamp 11 hours ago

@barsteward @neil Isn't the "final node" Neil's?

  • Copy link
  • Flag this comment
  • Block
barsteward
barsteward
@barsteward@infosec.exchange  ·  activity timestamp 10 hours ago

@revk @neil I meant the final one which makes the request to the destination address, so the penultimate one I guess.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 11 hours ago

My blog is also available as a .onion service, and this particular post is available at

http://6x27vvtf5vic2slpfe3yr7p2w37vbum2w5edt7ghw477mwxnnazjl2yd.onion/2026/02/decodedlegals-onion-site-no-longer-has-tls--https/

:)

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About · Code of conduct · Privacy ·
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Code of Conduct