Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Why is it better to provide a hidden service Web site with HTTP rather than HTTPS access?

hidden http HTTPS service web site
0
Posted

Why is it better to provide a hidden service Web site with HTTP rather than HTTPS access?

0

Put simply, HTTPS access puts the connecting client at higher risk, because it bypasses any first-stage filtering proxy.. Generally, a person using a Tor client will access HTTP via a first-stage proxy such as Privoxy, which has the ability to filter both the browser’s request and the server’s response. However, for HTTPS access to function correctly, the connection must be direct from the browser to the server, to protect the encrypted SSL connection under the hood. Without the proxy forging the SSL encryption keys (causing the browser to pop up an invalid certificate warning box), there is then no way to filter things from the HTTPS connection before the server or browser sees it — potentially allowing the browser to send identifiable user information to the server, or the server to send an exploit for a browser bug back to the client. For more information, see Privoxy’s FAQ entry (4.15) on the subject. http://www.privoxy.org/faq/misc.html#AEN895 Since hidden service connections are

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123