How Tor Works
alexkyte.me
alexkyte.me
Edit: I've also had some posts about Tor that did not fall exactly under this series format but should be helpful: http://jordan-wright.com/blog/tags/tor/
Also, a few months back I annotated the original Tor whitepaper here http://fermatslibrary.com/s/tor-the-second-generation-onion-...
The first thing you see in Tor Browser is a tab explaining that you got properly connected to Tor, but that Tor in itself is not a complete solution to online privacy and suggests you follow a link to an informative document written by the Tor Project.
It's all documented here: https://hackaday.io/project/12985-multisite-homeofficehacker...
It makes me think if HN should perhaps make a stand and either display some sort of lock icon next to secure links or make it harder for insecure links to show in the front page. Where is the right place to discuss this?
EDIT: previously incorrectly stated 'url' instead of 'domain'.
/* insert ascii goatse here */
A more frequent one is injection of ads or tracking scripts, or 'web accelerators' that recompress images. Certain ISPs have been known to do these.
The only thing that's not hidden are the domain names in the certificate that the server presents.
The rest of the URL is encrypted, along with all data and headers.
Regarding security, using HTTPS (along with the right measures on externally-hosted content) guarantees (to some extend) that what the users gets is what you meant to publish: an hostile network cannot replace the content with misinformation and cannot inject JS -- to exploit the client or not (as was done with the “Great Cannon” [0] which took down Github).
Privacy-wise, a number of countries routinely spy on their communication infrastructure, and revealing “I visited this website” is far more problematic than “I visited this Tor-related post on this website, and left this comment”.
The last reason for systematic HTTPS is “political”: if we go towards a situation where HTTPS is systematically employed, HTTP-only website will be subjected to increasing amounts of social pressure as adoption rates grow: deploying HTTPS (and preferably best-practices) on your “text-only” website pushes other websites (that might “need” it more) to deploy it too.