Could you explain what you mean by that?
Could you explain what you mean by that?
The Tor hidden services actually being used (as evidenced by the .onion address given above being relatively short) are what's called "v2" hidden services. You will see other people saying, oh, this is all fixed, Tor hidden services are much safer now. And maybe v3 really is better, although their documentation sure has a lot of TODO / FIXME lines for a "finished" protocol version. But that doesn't matter so long as in reality it's v2 hidden services people are using, so that's the subject of my critique.
The first scary thing is a v2 hidden service's uniqueness depends upon 80-bits from a SHA-1 hash. Technically although SHA-1 is broken that's not a hole in this part on its own, but for comparison HTTPS is using SHA-256. 80-bits is also worryingly small. I clearly can't guess my way to an 80-bit second pre-image using what I know today, but if a further crumbling of SHA-1 gives me a boost maybe it's possible.
Next is the public key crypto used, this is 1024-bit RSA. I think you might technically be allowed to still do this in HTTPS, but I haven't seen it for years, everybody is either 2048 or 4096 bits, or they've moved to an elliptic curve that's stronger.
Now, I should be clear all this seemed pretty good when Tor was invented, and the new stuff in Hidden Services v3 is pretty good today. But cryptographic recommendations don't age very well, and Tor sat on this problem for far too long, if the above .onion name was a v3 name and I was seeing widespread reliance on v3 hidden services I'd have shut up.