-
@AliceDust If somebody give you aeriszyr4wbpvuo2.onion, you can’t be sure it’s really mine. Perhaps aerisxgrtqmbwcbp.onion is.
-
@AliceDust But if you connect to aeriszyr4wbpvuo2.onion and you see imirhil.fr inside the valid cert, confirmation it’s the legit one.
-
@AliceDust (In my case, cert is not valid because no affordable/free CA offer .onion signing with plain-net domain inside too)
-
@AliceDust But you can confirm this is the same cert as my plain-net cert, so even if .onion is not the legit, traffic remains safe.
-
@AliceDust Because only me can decrypt content protected with this certificate. Even if everybody can generate fake .onion […]
-
@AliceDust […] and proxify my content (kind of MitM).
aeris22’s Twitter Archive—№ 26,033