|
|
|
|
|
by unsignedint
3888 days ago
|
|
Yes, within a Tor, if you access certain hidden service, you are pulling data from the node that has the corresponding private key. I guess the threat model is when there's some MITM between a user agent and Tor, perhaps via some type of malware. (Because your browser can't tell if you are really accessing hidden service or not.) At this least verifying against certificate coming from a hidden service server would verify that it is coming from the host intended. |
|