Hacker News new | past | comments | ask | show | jobs | submit login

If you stay within the Tor network and don't exit, you dont really need the cert for encryption-- the traffic is encrypted end-to-end and decrypted on the hosting server already. Most onion sites are http. For these sites, proving identity to get a trusted cert is the barrier. If let's encrypt had an onion service, that could solve some of this.

Edit: clarified




I meant for clearnet sites. There is essentially no benefit for an onion site to use https. Maybe if you want an extra layer of security potentially using different ciphers than the rest of the tor network. I suppose EV certs to prevent fake sites, although i think its debatable how well that works and its inherently not practical in many usecases.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: