Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The last hop off the relay is unencrypted breaking the security model.

Isn't that only true of using Tor to access regular websites, not hidden services?



Yes, thank you, I think I had the wrong idea, I probably didn’t know. I looked it up and: so long as the tor service and the web server are on the same machine, and operated by the same people - i think that’s true. But they don’t need to be on the same machine, or managed by the same person.

Some more info: https://community.torproject.org/onion-services/advanced/htt...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: