Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Lee
On 11/14/14, Jacob Appelbaum wrote: > On 11/15/14, Lee wrote: >>> c) Get .onion IANA reserved >> >> It doesn't look like that's going to happen. >> >> https://datatracker.ietf.org/doc/draft-grothoff-iesg-special-use-p2p-names/ >> is expired & I haven't been able to find anything indicating it's >

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Jacob Appelbaum
On 11/15/14, Griffin Boyce wrote: > Fair. What are your thoughts about possible trade-offs with anonymity when > using a CA-signed cert? > I have many. It won't impact client anonymity from where I stand and it will ease usability for certain use cases. All in all, I welcome the CA cartels signi

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Griffin Boyce
Fair. What are your thoughts about possible trade-offs with anonymity when using a CA-signed cert? On November 14, 2014 9:38:02 PM EST, Jacob Appelbaum wrote: >On 11/15/14, Griffin Boyce wrote: >> Lee wrote: c) Get .onion IANA reserved >>> >>> It doesn't look like that's going to happen.

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Jacob Appelbaum
On 11/15/14, Griffin Boyce wrote: > Lee wrote: >>> c) Get .onion IANA reserved >> >> It doesn't look like that's going to happen. > >Yeah. Though the biggest use-case for cert+onion is when trying to > match a clearnet service to a hidden service -- such as Facebook or > Erowid. > That is fal

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Jacob Appelbaum
On 11/15/14, Lee wrote: >> c) Get .onion IANA reserved > > It doesn't look like that's going to happen. > > https://datatracker.ietf.org/doc/draft-grothoff-iesg-special-use-p2p-names/ > is expired & I haven't been able to find anything indicating it's > still being considered. It's still somethin

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Griffin Boyce
Lee wrote: c) Get .onion IANA reserved It doesn't look like that's going to happen. Yeah. Though the biggest use-case for cert+onion is when trying to match a clearnet service to a hidden service -- such as Facebook or Erowid. ~Griffin ___ tor

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Lee
> c) Get .onion IANA reserved It doesn't look like that's going to happen. https://datatracker.ietf.org/doc/draft-grothoff-iesg-special-use-p2p-names/ is expired & I haven't been able to find anything indicating it's still being considered. See the "existing requests/RFC 6761 process:" section h

Re: [tor-dev] User experience issue

2014-11-14 Thread Adam Shostack
On Fri, Nov 14, 2014 at 12:50:20AM +, Runa A. Sandvik wrote: | On Fri, Nov 14, 2014 at 12:43 AM, Adam Shostack wrote: | > Hi, | | Hi Adam, | | > I just had the fun experience of trying to walk someone who's not very | > technical and not familiar with Tor through downloading and installing |

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Adam Shostack
Hi Tom, thanks for the great summary. I want to comment on one element of your writeup, the hidden service on box A, webserver on box B. My weak belief is that this is no different than the "SSL added and removed here" issue which impacts many 'secure sites.' Imposing a requirement that a person

Re: [tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Jeremy Rowley
Great summary Tom, >From my perspective, getting .onion reserved is a pretty high priority. Once >reserved, we can really eliminate it as an internal name and get onion listed >as part of the PSL. I'm happy to help with this part of the project if I can. >Syrup-tan had an idea on irc: Have a

[tor-dev] Of CA-signed certs and .onion URIs

2014-11-14 Thread Tom Ritter
There's been a spirited debate on irc, so I thought I would try and capture my thoughts in long form. I think it's important to look at the long-term goals rather than how to get there, so that's where I'm going to start, and then at each item maybe talk a little bit about how to get there. So I t