How does one store links like this? You'd need a bookmark file, which would sort of give the game away, I'd have thought. How do you make sure you notice when you visit a URL with the same readable prefix?
How does one store links like this? You'd need a bookmark file, which would sort of give the game away, I'd have thought. How do you make sure you notice when you visit a URL with the same readable prefix?
Figure 10 shows that most users (52%) use bookmarks, followed by locally-saved text files (37%), and referral to trusted web pages (35%).
Also, lots of people find themselves unable to determine an onion service's legitimacy (Figure 12), which is why phishing attacks are successful. We document one such attack in Section 5.1 of another research paper: https://nymity.ch/sybilhunting/pdf/sybilhunting-sec16.pdf
One possible solution would be to issue a TLS certificates for both the clear-web and .onion domain (for services which are offering .onion services to provide better anonymity for users not their servers).
Unfortunately, the CAB forum has decided to not allow this -- only EV certificates can be issued for .onion services so you can't use LetsEncrypt for this.
HN discussed (https://news.ycombinator.com/item?id=14038013) about the issue and the post (https://blog.torproject.org/cooking-onions-names-your-onions) outlines some of the ways in which you can mitigate right now.
Cloudflare is using the 'alt-svc' header (https://blog.cloudflare.com/cloudflare-onion-service/).. The CIA is not, I'd have loved it.
curl -I https://www.cia.gov/index.html HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/html ETag: "<>" Last-Modified: Tue, 28 May 2019 15:05:25 GMT Content-Length: <> ID: <> SESSION: <> Date: Thu, 30 May 2019 12:36<> GMT Connection: keep-alive Set-Cookie: _session_=<>; path=/; domain=cia.gov; secure; HttpOnly ID: <> SESSION: <>
It should be noted that alt-svc is an HTTP header returned which means you have first made an HTTP request before the onion request which affects anonymity. It's not a big deal over Tor because that HTTP call is on an exit node, but still should be noted.
Once you have confirmed a domain is correct, you should save it yourself, and only access that saved link.
Using any forums/wikis/search to find onion links (may) leave you with stolen credentials or a hacked machine.
It's cumbersome for sure, but the beauty is it's self-authenticating. Don't forget to turn off JS. :)
[1] https://trac.torproject.org/projects/tor/wiki/doc/HiddenServ...
Cloudflare offers their DNS-over-https service at an onion address. In their documentation, they say:
"
Protip: if you ever forget the dns4torblahblahblah.onion address, you can simply use cURL:
curl -sI https://tor.cloudflare-dns.com | grep alt-svc
alt-svc: h2="dns4torpnlfs2ifuz2s2yf3fc7rdmsbhm6rw75euj35pac6ap25zgqad.onion:443"; ma=315360000; persist=1
"
It's a clever way, and standards-compliant, to distribute alternate onion addresses for existing services.
What I don't know is if Tor Browser Bundle has support for this natively, where if you visit tor.cloudflare-dns.com and it'll look for the alt-svc record and redirect you automatically to the onion address.
If it does, then you can just bookmark the regular URL knowing that you'll be redirected.
What can you do when there is no central DNS to trust. I suddenly felt that I couldn't trust anything at all. I started to question those around me and spiraled into existential philosophical crisis of truth testing even my own senses.
I eventually found a real solution, but I'm on mobile and don't feel like typing the whole thing out.
If it's not on you, they can't beat it out of you.
Of course, they might decide to beat you anyway. Which raises the question of whether it's strong crypto or rule of law that matters more. I'm not sure which way I come dwn on that myself, though could argue for bits of both.