Depending on the nature of the leak, perhaps it'd be best to get it into a safe public store that won't be disappeared (e.g. the blockchain) in an encrypted fashion, and then release the key to select parties.
Depending on the nature of the leak, perhaps it'd be best to get it into a safe public store that won't be disappeared (e.g. the blockchain) in an encrypted fashion, and then release the key to select parties.
* Scandal and investigation when they do, potentially leading to removal of trust from an associated CA.
* Easier and easier to detect (recently mandatory disclosure of all publicly-trusted certs https://groups.google.com/a/chromium.org/forum/#!topic/ct-po... and you can sign up to get alerts when a certificate is logged for a particular domain name).
* Onion sites also derive cryptographic security from the onion name itself. (I'm working on getting them to be allowed to have DV certs, but even without certs, the onion rendezvous protocol confirms that you've reached a party that controls a key specified in the name itself.)
(Someone else mentioned HPKP, which I've also touted in the past as improving HTTPS security, but it seems HPKP enforcement is going away, so we can't necessarily tout it for this purpose anymore...)
Is it possible to derive a fully secure HTTPS-or-equivalent connection purely from the site's curve25519 key? It seems like that would make DV (and CAs in general) completely redundant. (And if not, is there a explanation of why not?)
https://cabforum.org/pipermail/public/2017-November/012451.h...
See the section "Why do people want certificates for onion names?".
It's correct that both v2 and v3 onions provide end-to-end encryption based on the onion service key. In v3 onions that encryption uses more modern cryptographic primitives than in v2 onions, so the incremental cryptographic benefit would be much larger in v2, where unfortunately for historical reasons the CA industry is reluctant to allow DV certs.
Just put it up as a torrent and share the magnet link.
What would get the most buzz? FreedomChain?
Don't do this; it has all the same problems of just giving the data to select parties directly.
Instead use http://www.gwern.net/Self-decrypting-files and post that to the blockchain. This ensures that anyone can access the data without depending on a trusted third party, but the data will already be irrevocably committed by the time anyone realizes that they want to censor it. Then publish the decryption key for convenience; if that get censored, it's merely mildly annoying.
I don't know whether Chrome provides appropriate extension APIs to allow an extension to do this, but I have a number of colleagues who work on browser extension development whom I could ask.