Title: Recommend making sites available over Tor Onion (Hidden) Services · Issue #93 · GSA/https · GitHub
Open Graph Title: Recommend making sites available over Tor Onion (Hidden) Services · Issue #93 · GSA/https
X Title: Recommend making sites available over Tor Onion (Hidden) Services · Issue #93 · GSA/https
Description: As you yourself state: IP addresses and destination domain names are not encrypted during communication. Even encrypted traffic can reveal some information indirectly, such as time spent on site, or the size of requested resources or sub...
Open Graph Description: As you yourself state: IP addresses and destination domain names are not encrypted during communication. Even encrypted traffic can reveal some information indirectly, such as time spent on site, o...
X Description: As you yourself state: IP addresses and destination domain names are not encrypted during communication. Even encrypted traffic can reveal some information indirectly, such as time spent on site, o...
Opengraph URL: https://github.com/GSA/https/issues/93
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Recommend making sites available over Tor Onion (Hidden) Services","articleBody":"As [you yourself state](https://https.cio.gov/#what-https-doesn't-do):\n\n\u003e IP addresses and destination domain names are not encrypted during communication. Even encrypted traffic can reveal some information indirectly, such as time spent on site, or the size of requested resources or submitted information.\n\n[Tor](https://www.torproject.org/) enables users to browse sites anonymously, to keep secret the fact that they're browsing (as examples) [health care](https://www.healthcare.gov/), [the GAO](http://www.gao.gov/), [OSHA Whistleblowers](http://www.whistleblowers.gov/), or [the SEC](https://www.sec.gov/whistleblower). Clearly browsing any one of these sites may be a telling act to (e.g.) an employer that should be treated as sensitive.\n\nMaking these sites available over Onion Services provides even stronger protection for users than merely using Tor, as their traffic is end-to-end authenticated and never leaves the Tor Network. (Onion services are also, more commonly, called 'Hidden Services' but in this case, the identity of the server is not intended to be hidden.) [Facebook](https://www.facebook.com/notes/protect-the-graph/making-connections-to-facebook-more-secure/1526085754298237) recently made a Onion Service available for example.\n\nIt would be a wonderful gesture, on top of this already excellent proposal, to recommend that agencies consider if the mere act of browsing their site may be sensitive information and make themselves accessible via a Tor Onion Service.\n","author":{"url":"https://github.com/tomrittervg","@type":"Person","name":"tomrittervg"},"datePublished":"2015-03-28T00:19:42.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":3},"url":"https://github.com/93/https/issues/93"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:1528cc4e-6c5f-2d21-842b-5e08417506d7 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 8482:249DA2:B3DB36:F390DF:6971CA1D |
| html-safe-nonce | a173bc0959c4c287b66c6be1d807b1078c9c779492705271a793623c79652e89 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4NDgyOjI0OURBMjpCM0RCMzY6RjM5MERGOjY5NzFDQTFEIiwidmlzaXRvcl9pZCI6Ijc0NTUzMDkzNDc5MzcxODMwMiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 724a3f8ebf7d9aaf5aa4880f57d41c47fc5b4f41b8aafd620931ae8781af4fdf |
| hovercard-subject-tag | issue:64876627 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/GSA/https/93/issue_layout |
| twitter:image | https://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/93 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/93 |
| og:image:alt | As you yourself state: IP addresses and destination domain names are not encrypted during communication. Even encrypted traffic can reveal some information indirectly, such as time spent on site, o... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | tomrittervg |
| hostname | github.com |
| expected-hostname | github.com |
| None | ac615aa66802dad9a938c6abe95edf09ee43c0c7f508315b64b08612858ef32e |
| turbo-cache-control | no-preview |
| go-import | github.com/GSA/https git https://github.com/GSA/https.git |
| octolytics-dimension-user_id | 643070 |
| octolytics-dimension-user_login | GSA |
| octolytics-dimension-repository_id | 28724827 |
| octolytics-dimension-repository_nwo | GSA/https |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 28724827 |
| octolytics-dimension-repository_network_root_nwo | GSA/https |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 6b618569a5f93e0b31f97f620112341421ef5f69 |
| ui-target | canary-2 |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width