Skip to content
Snippets Groups Projects
Closed Consider enforcing HTTPS by default in Tor Browser
  • View options
  • Consider enforcing HTTPS by default in Tor Browser

  • View options
  • Closed Issue created by Arthur Edelstein

    Hostile exit nodes can perform ssl strip attacks to steal passwords or other sensitive data. See for example: https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac

    A possible solution is to prohibit insecure connections through exit nodes. There are a couple of possible implementations:

    HTTPS support is much more pervasive on the web than in the past. I have been dogfooding HTTPS-Only Mode and it's remarkably rare to run into its error page.

    Edited by Arthur Edelstein

    Linked items ... 0

  • Activity

    • All activity
    • Comments only
    • History only
    • Newest first
    • Oldest first
    Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading