[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-dev] SOOC (Same Origin Onion Certificates) discussion tomorrow
- To: tor-dev@xxxxxxxxxxxxxxxxxxxx
- Subject: [tor-dev] SOOC (Same Origin Onion Certificates) discussion tomorrow
- From: Richard Pospesel <richard@xxxxxxxxxxxxxx>
- Date: Mon, 9 Mar 2020 15:10:01 -0500
- Autocrypt: addr=richard@xxxxxxxxxxxxxx; prefer-encrypt=mutual; keydata= xsFNBFnAGv8BEACeqywkP5Bb917JJKOEMObLpvHKIHXhbNTA1K0lh6bvX/prYaCnxtLpR9OO W1s1FUvox0BSh7um15dj3gMrkHUmMtIOlKd+K8kgjI6z145wjZ+Xt/pB92i3ROUvUJRz3ION dzMQmGnsuPDDmz+1VnrHyKE1dr2qXYyejTPeJAJM2eO78dlWoUhi2am17+Hna6HjRMktFFb1 NSEr//I0NR1BbsXOVvn0Pt3dYyHcWiBt2k4ew7sfgFMVtNW5qvfyYB78hGt6xFNp0C8acrQT 0k0unlo8vr7Vdh1oOc6b/tsV0ebjUqhU4LIvHKUzsY5K1kaqjx/lmMCRvF9BX4gGfd0LqLuC UOwsNywP74n0ZG3tPx+tLEZxKt1Yd4pEs9hXKGLtmch7PATnAlW73s8Acb7il7qQQsGHtACb f/BPjXQS2yz8O5+KLhQ+UNTzI1w9N9fVpAyMfbFHdl4yTmZr5bjet23jOpfFRxOIGFbbyNE8 q010u+iN28t7pNS17VcqUxq4u+ED1txB+HciTA1RfNHCI/2Y+r8GOPT+1uk6TMkNEr0FyjJU yHJDyitzwHubq46KnKdAAG1Q0/+e99CmGCGQXrj3YvoB4+EhGQjeuTvGBzoVNSIYFHBsGHxi Yvz4BMksbg/eoSY6PBPnI6corSO0a8RbSvqUY5KLXdUkWbJxjQARAQABzSlSaWNoYXJkIFBv c3Blc2VsIDxyaWNoYXJkQHRvcnByb2plY3Qub3JnPsLBfQQTAQgAJwUCWcGl/gIbIwUJCWYB gAULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRDeRzYDY/NLLDWXD/9UN1Pdevf8Pbhcadr6 SJTvdYH6y+dkMaLLR2Pd3l645Bn1cY9Be5Azw86jwFnaP+hH2rPrEG9jGyU/xpIPRLiA0Tl2 9QLopD6KIb2mc6SCosEVa8WNV9eJ5YvRM66QmNQHJT0eZkk4th/EUZkqy66NohtilSIIMc5o 0a4xMCmB61URDoReQckzAfujSTfeMhJkfyW5uYg9xvH2/deM1JPq+J/xBOdiMRZswM1E+KVN eIRnD3vvtpZ7i+UW82ExAxhm1ubcX3vwcGd7bKYR+jg7QcBienwUNrXDVlfZ3tvH/clkyZZa E2nQeyeBzFYGm+mxhDoA6Ivv0XfDOCHg9kcYaQBdskbBN8PlezaW+CmBmdeWR3ED5Y/vX6ud rlwJ4lJ3XZFrL/zRbIuJgWlUe6kEqy7RyUNhnhS/4svRlI8fsU8NBQj5QCsxSI6FkQxrchAO VhmV8xhyIg54+/e3jKYPhBWvS9Y/B4SzFvGbya7+U//ucDRTGyNGcwQA2l9TJYYFOqZb6Ws+ 0/pa54smTFwChqysVPRXA6S2L0GIZppSQATLkhLj6trqbDihfU53za255w8GWRShZz8Os3g3 QaUmQI8aHTO2Beea4QJ1fpJLkpgaJ5U6Gmleo0OANChLkkF3xeQfKsXYS+bcmH5jpgO2z9l6 gV8DhBYK29eqVaArws7BTQRZwBr/ARAA17GeN7sK1XkshfK22jh8cOli70Xv+4nkFucodxy1 FtAHbthJ61Cce/9F+8tZgV+Ect186z3ANs997Wm/BvcfiiKIDsT0sWpV6SdHIgeTM3FJIsFu 2lZyDSN9J4B4XMBw5jshwcSqf74qYrIlq0c6QD1JDAcB9Oa5FRm4i5SoJZUh/181pr8C1kuo ajaEE5PhVz2+GU2FoSl9AV6WzzuR9DQponC0kyulPWq3TO2sFto64XSQ6imd2ZM1f5r6zmTn RzsxL3mJmzAKy7TwkkqhWTi71brSbA69O9hJyLKAXEhCIfw0tVjE/IzAD/T3h9FeXcfRlvq6 U9GM3dCNbLMIAJSXpOvvio4ZD1p2tZYrajF9roqf4vXNuCvx7mP3TFO4saYe2h8egeim8v9D m40qr58FaPYl8e4z7EFpW07mvUKMXe9yshEBdOcWIk4MbLPij2yk0rfIXjFHCaJnezL5Ayad gD1mtkY/r1WQm6Z8hMDulbCmQ4913AUg9efXeX5LjMrou1SptPNooD1z8bQtciXMHCV7AjSU Hnm+dPdYA1n7HIPNWTZ7KLz9+26vLtZEalBm8cjMJddWEiH1nncVggC8EKuxvRa9mOrYJ2qZ eXmlGK7LLEDxc5j/fCUv64naduIo25IxCpf8CdjnOx5SNYCKmNT9Jt66hjt8s67KpS0AEQEA AcLBZQQYAQgADwUCWcAa/wIbDAUJCWYBgAAKCRDeRzYDY/NLLOuJD/9nfyJebL4WXazUeoit 38Dsb28BXSpbJBVBTwjETU9my1dlET51U0Yf/N3AWssHxMjyKsbPW0P0aftBy64i1iqBwjs1 plFGzArlaIwYrYkF+YulbWscLjQGMr9gwoSAAicIq0LbJITy2Fr/xhv0JccwPiU1WXy4k4wS Fu93fqL5xwTHgkZvw/K86ujoczQksxtdDCU2GIvQdKHAMBkSsW9KhlhBUNXM99BPibSMkKmF 6TuiKLoZ23oT5W4IIcyi/0U0Le/yGWFXJtyBGFT3Ul6ulDehjzd8ixXyWW/5bngPx7E/EUGq pp6iarNsj02FJeSIMy8KM32ZmGpaBWIU62To0uW4INiNihn6FFz4O/GgPGG9iWot/+MpTIfO 76TxIQ/Gwza13XISH1jlBiXE9P9VMqfczggxz+YAVNbeHmdBpnjJRyVtSmEoD5am/zhD6qHw gcoEFIrIumY71CRpqGnQ+Ll7gUVvb3zPGhP4oQZqwkoUWaU/KU2Nut42u6hzxcHFhAPjgp1Y dzFQt/jpihRcNz6vn0UtmY6/i0h68ybIVHxbarndyI7uKnUqqetDqjNPjK9w3l6kjRn/Nilg bwzAEYjMx37I848+vEtc97VpiXKGKYNLosLec6HWntpdRac0toTunwLljHxvlrKu7r06rZgW FitEw4xp3JUlTbtWvw==
- Delivered-to: archiver@xxxxxxxx
- Delivery-date: Mon, 09 Mar 2020 16:10:38 -0400
- List-archive: <http://lists.torproject.org/pipermail/tor-dev/>
- List-help: <mailto:tor-dev-request@lists.torproject.org?subject=help>
- List-id: discussion regarding Tor development <tor-dev.lists.torproject.org>
- List-post: <mailto:tor-dev@lists.torproject.org>
- List-subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev>, <mailto:tor-dev-request@lists.torproject.org?subject=subscribe>
- List-unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-dev>, <mailto:tor-dev-request@lists.torproject.org?subject=unsubscribe>
- Reply-to: tor-dev@xxxxxxxxxxxxxxxxxxxx
- Sender: "tor-dev" <tor-dev-bounces@xxxxxxxxxxxxxxxxxxxx>
Hi Everyone,
The current UX situation around HTTPS-enabled onionsites is not the
best: Tor Browser shows security warning splash screens and icons in
scenarios that do not warrant them. On top of that, the only way for
your onion site to not show these warnings is by getting an EV cert
which is only practical if you have the $$$.
alecmuffet's SOOC proposal (
https://github.com/alecmuffett/onion-dv-certificate-proposal/blob/master/text/draft-muffett-same-origin-onion-certificates.txt
) does seem to fix these UX problems for us. Though the proposal is
still incomplete, we can make forward progress with a prototype
implementation as the certificate specification is fully fleshed out.
We'll be talking about this tomorrow during the Sponsor 27 meeting
tomorrow on Tuesday 10th May @ 1500UTC in #tor-meeting. Please feel free
to come by if you wish to discuss.
best,
-Richard
Attachment:
signature.asc
Description: OpenPGP digital signature
_______________________________________________
tor-dev mailing list
tor-dev@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev