[tor-onions] Announcing Onion-Website with x-onion response-header?

Martijn Grooten martijn at lapsedordinary.net
Sat Feb 6 14:34:55 UTC 2016


On Thu, Feb 04, 2016 at 03:36:44PM +0000, Alec Muffett wrote:
> Perhaps only issuing the header to people who access from an exit node, might
> reduce that cost?

Even so, and especially then, this sound like an easy way for someone
operating a rogue exit node to get persistent MitM on non-HTTPS sites.

Martijn.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: Digital signature
URL: <http://lists.torproject.org/pipermail/tor-onions/attachments/20160206/67c96a4d/attachment.sig>


More information about the tor-onions mailing list