aeris22’s avataraeris22’s Twitter Archive—№ 26,032

  1. …in reply to @DieRoteLisbeth
    @AliceDust If somebody give you aeriszyr4wbpvuo2.onion, you can’t be sure it’s really mine. Perhaps aerisxgrtqmbwcbp.onion is.
    1. …in reply to @aeris22
      @AliceDust But if you connect to aeriszyr4wbpvuo2.onion and you see imirhil.fr inside the valid cert, confirmation it’s the legit one.
      1. …in reply to @aeris22
        @AliceDust (In my case, cert is not valid because no affordable/free CA offer .onion signing with plain-net domain inside too)
        1. …in reply to @aeris22
          @AliceDust But you can confirm this is the same cert as my plain-net cert, so even if .onion is not the legit, traffic remains safe.
          1. …in reply to @aeris22
            @AliceDust Because only me can decrypt content protected with this certificate. Even if everybody can generate fake .onion […]
            1. …in reply to @aeris22
              @AliceDust […] and proxify my content (kind of MitM).