Remix.run Logo
keepamovin 5 days ago

A bit circular. How do you know the domain? Trust.

I like this “onion pinning” possibility:

There is value in exposing the existence of an onion site via CT Logs. If someone navigates to the plain web version of a site, and is presented with a certificate containing a Subject Alternative Name (SAN) for both the plain web and the onion site that provides a strong cryptographic guarantee that they are the same site. Effectively this would replace the Onion-Location header with something more authenticated.