TLS Certificate Validation Methods for Onion Services
By
keepamovin
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
This technical document examines various approaches and proposals for integrating TLS/HTTPS certificate validation specifically for Onion Services (Tor hidden services). It covers both traditional Certificate Authority (CA) models and alternative certification methods that don't require built-in certificate chains or financial transactions. The document serves as a comprehensive guide for implementing secure certificate validation in the Tor network ecosystem.
Key quotes
· 4 pulledThis document tracks existing procedures or proposals for integrating and validating TLS/HTTPS certificates for Onion Services
While some depends on Certificate Authorities (CA) model, others rely on alternative certification and validation procedures
does not require built-in certificate chains in the client software or reliance on financial transactions
Whenever you browse the internet regularly, the connection between your computer and a service
You might also wanna read
Security Vulnerability: Data Exfiltration via DNS Resolution with allowLocalBinding Enabled
The article demonstrates a security vulnerability where DNS resolution can be exploited for data exfiltration when the 'allowLocalBinding' s
North Korean Chollima Group Targets PHP Developers via Malicious Packagist Package
A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor
Attacker publishes 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A single npm user published 14 malicious packages over four hours, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-
Extending Wazuh Detection with Clickdetect, OpenSearch PPL, and Sigma Rules
This blog post by "souzo" introduces clickdetect, a repository/tool designed to extend Wazuh's detection capabilities by integrating with Op
infosecwriteups.com·3d ago