#Tor v3 addresses are a shambles.

You can't write them down in 10 seconds, if you can't even remember them.

It seems Tor's v2 address have been depricated, and Tor defaults to v3 now — bad news for UX?

#HSv3 #HSv2

@realcaseyrollins
#Tor's v2 addresses (ie. the 16-character addresses) for #HiddenServices are being replaced by v3 addresses that are approx 50 characters.

We read a ticket on #Gitlab detailing plans to completely remove support for #HSv2 addresses.

In our view this kills Tor . It means people won't be able to spontaneously write their address to give to others, they'll need to access a device to remember it or have the address on their person.

Seriously questioning #TorProject, right now.

@dsfgs @realcaseyrollins

there was always a need for an alternative way to visualise a .onion

even the 16-char addresses are subject to people not remembering/paying attention to if they're exactly correct.

I speak more of the users of an address, than the person who runs a given site.

@msaunders
There is an easy way to tell #TorBrowser to add colour to parts of the address based on additional information in the publicKey with HTML header tags, this would give the #hiddenService operator control over the way the address is presented in the browser.

This stuff is not rocketScience.

#TorProject are dropping the ball. Plans to ditch v2 is a step too far.
@realcaseyrollins

@dsfgs @realcaseyrollins @msaunders It's very disturbing how early @torproject is killing v2. They're over-reacting to exaggerated risks. Many /stable/ platforms don't advance versions this quickly & Project is creating instability. I have a separate machine w/Tails just to handle v3 on the side until I can undertake the massive migration task.

@torproject @msaunders @realcaseyrollins @dsfgs And it's a big hassle to just get the URL copy/pasted over or to read and trascribe the long-ass thing

@dsfgs @realcaseyrollins @msaunders @torproject Suppose I don't need anonymity as a host, and suppose impersonation isn't in my threat model? Maybe I have an onion address to serve Tor users in a way that doesn't burden the exit nodes, or because I simply don't want the cost of a domain name? I should be able to serve Tor users with v2 address.

Follow

@torproject @msaunders @realcaseyrollins @dsfgs Think about users of the physical security app , where users have to transcribe the onion address from their phone to their desktop. Onion v3 will be hell for those users.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!