Tor and HTTPS protect different paths
Summary
The EFF graphic explains which observers see which data with Tor, HTTPS, both or neither layer of protection. Tor routes traffic through several relays. HTTPS authenticates the target server via certificates.
Ideas
- Tor hides the origin address from the target server.
- HTTPS encrypts content between browser and target server.
- The Tor exit node sees unencrypted HTTP traffic.
- Depending on the setup, DNS and destination information remain partly visible.
Insights
- Anonymity and confidentiality of content are separate security properties.
- Layers of protection must be chosen against the respective observer.
- An encrypted connection can still reveal metadata.
Facts
- Tor and HTTPS can be used together.
Recommendations
- Use HTTPS within Tor as well.
- Never send identifying data just because the connection is anonymous.
References
Links to the original source and the Web Archive open in a new tab.