The implications with regard to SSL certificates are interesting, though, and I'm curious how long it'll take for SSL providers to start supporting that. :)
The implications with regard to SSL certificates are interesting, though, and I'm curious how long it'll take for SSL providers to start supporting that. :)
[0]: https://blog.digicert.com/anonymous-facebook-via-tor/
[1]: https://blog.digicert.com/the-current-state-of-onion-certifi...
Perhaps a better question is: are there any benefits other than just providing an additional layer of encryption that a potential attacker would have to defeat -- there's already end-to-end encryption when using hidden services (even if there isn't any encryption at the application layer)?
ETA: I just remembered that hidden services use 1024-bit RSA keys and there's been some arguments lately that that may not be enough bits. For some sites, using (at least) a 2048-bit key may be necessary.
Another concern is that major browsers might obsolete HTTP scheme, so their UI will warn user about insecure connection. I'm not sure whether browsers will be able to distinct between onion sites and regular sites in that aspect.
Yeah, but those are companies that might as well have non-hidden websites, or be serving .onion mirrors of their regular domains.
The main "use case" for .onion domains are people for whom EV certificates would defeat the whole point.
Which is an excellent usecase for a cert to make sure that you actually are connected to the mirror. They could even have a cert that works for both domains, linking those together.
If it's not a hidden service then you can't really use an .onion address anyhow.
In those instances, an SSL certificate would provide encryption all the way from the "Tor client", through the Tor network, the rendevous point, Tor endpoint, and to the actual application server. Without additional encryption in use at the application layer, the link from the Tor (hidden service) endpoint and the actual server would not be encrypted and, thus, vulnerable.
To (perhaps) explain better, this would be similar to how Cloudflare offers SSL for all sites and while the path from the end user to Cloudflare is (can be) encrypted, the link from Cloudflare back to the origin server isn't necessarily encrypted. Alternatively, think of the link from an SSL terminating device to the backend web servers. Again, in most cases, this is a non-issue but there certainly are some instances in which it would apply (and this is probably more likely the bigger a site (hidden service) is).