[tor-talk] hidden service with only one authorized client

Allen allenpmd at gmail.com
Sat Mar 28 22:39:07 UTC 2015


As far as I can tell from testing and from deconstructing the spec at
https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt , if I have a
hidden service with only one authorized client, there is no functional
difference between using basic auth (rend-spec section 2.1) and stealth auth
(rend-spec section 2.2).  By that I mean, the security and privacy would
effectively be the same in both cases.  Is my reading correct?  If not, what
is the functional difference?  Thanks.



More information about the tor-talk mailing list