Follow

@schestowitz still throws an unnecessary fit when an SSL cert on an site is self-signed. Then after several clicks to reassure TB that it's not an issue, it still in the end falls over with "secure connection failed.. [try again]". WTF, devs should know SSL to an onion site is redundant.

@schestowitz And when clicking on the cert details of an onion site, says "Information you submit could be viewed by others (like passwords,..)" Tor Browser is lying.

@resist1984 @schestowitz Yes, for Onion-sites TLS/SSL is mostly redundant. However if you are connecting to a site on the web without HTTP over TOR (e.g. duckduckgo.com), you'd still have to trust the Exit-Node to not be malicious.

Tor devs probably preferred consistent behavior :)

@rarepublic @schestowitz it doesn't make sense to give consistent treatment to inconsistent circumstances.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!