Live data from Hacker News

Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

twitter3e4tixl4xyajtrzo62zg5vztmjuricljdp2c5kshju4avyoid.onion

31–40 of 52 posts

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#31

I don't understand the premise of Twitter having an .onion hidden service. They're anti-anonymity, at least from my experience, where they extorted my phone number from me so I could continue to use their service. Mixing PII with Tor defeats the purpose of anonymity. You're immediately outed by providing a phone number or even en e-mail.

Nonsense. The threat model that onion routing protects against is a middle man intercepting the traffic, not from Twitter knowing who you are. It still offers value.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#32

Twitter should not care about having an onion service. Great example of a distraction that the Musk downsizing properly removed.

It broke because there's no one left at the company who knows how to keep it online.

That's unlikely. Even though Elon gutted the team at Twitter, the previous devs were good and certainly documented things. Besides, renewing a cert and applying it to an onion service isn't very hard, so the current team could fix it if it was a priority.

Its much more likely that it just isn't something they want to spend time on.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#33

Twitter should not care about having an onion service. Great example of a distraction that the Musk downsizing properly removed.

Serving a valid tls cert takes virtually no effort. It's far more likely that Musk's downsizing killed off infra that was doing this job correctly and inexpensively for many years. If Musk actually cared about free speech like he says he does, onion services would be a priority. But obviously that's just hot air. You can't have it both ways.

> infra that was doing this job correctly

Twitter's Onion handling hasn't been reasonably functional for years, so in this particular case it's not that.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#34

Earlier quoted context omitted.

Serving a valid tls cert takes virtually no effort. It's far more likely that Musk's downsizing killed off infra that was doing this job correctly and inexpensively for many years. If Musk actually cared about free speech like he says he does, onion services would be a priority. But obviously that's just hot air. You can't have it both ways.

> infra that was doing this job correctly Twitter's Onion handling hasn't been reasonably functional for years, so in this particular case it's not that.

The infrastructure that issues and replaces certs isn't the same infra that performs onion handling.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#35

Twitter should not care about having an onion service. Great example of a distraction that the Musk downsizing properly removed.

Maybe, but then, why the onion service is still up?

This feels more like uncontrolled infrastructure rot/lack of maintenance rather than a conscious decision to cut unnecessary parts of it.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#36
post #22

Also noticed that the Status page linked from the logged out https://twitter.com page has been expired since Aug 29. Not especially interesting, but probably an indication that some of the non-core stuff is getting overlooked.

The API page is still up

https://api.twitterstat.us/

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#37

I don't understand the premise of Twitter having an .onion hidden service. They're anti-anonymity, at least from my experience, where they extorted my phone number from me so I could continue to use their service. Mixing PII with Tor defeats the purpose of anonymity. You're immediately outed by providing a phone number or even en e-mail.

It's not too hard to get a temporary voip phone number if required to sign up for a service, but when I signed up this wasn't needed. Just don't use your phone. You can also get dummy, private, or temporary email addresses. Yeah, the scraping makes things harder, but it's perfectly doable to get these services completely anonymously. I mean hell, NYT, WP, CNN, Reuters, etc all have Signal and most have Secure drop, which is via Tor, to connect to them. Interestingly it looks like Fox is the only major platform not have any method I could find from a single search.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#38

I don't understand the premise of Twitter having an .onion hidden service. They're anti-anonymity, at least from my experience, where they extorted my phone number from me so I could continue to use their service. Mixing PII with Tor defeats the purpose of anonymity. You're immediately outed by providing a phone number or even en e-mail.

This goes for every single website on clearnet though? If not phone number, they have your IP and location, timezone, likely waking hours, private chats, search queries, who you communicate with and when etc. If not collected by the webmaster then it is automatically collected by whatever government the server sits in (+ whatever governments that government trades data with). The times of anonymity on the internet/cl…

> If not collected by the webmaster then it is automatically collected by whatever government the server sits in (+ whatever governments that government trades data with).

It certainly is not, that's what we did all that HTTPS perfect forward secrecy for.

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#39
post #21
post #15

Earlier quoted context omitted.

That was a bigger discussion when Facebook did it back in the days and there's really no clear reason for and against it. In the end it mostly boils down to "regular people were educated that https is needed, so it's better to just keep doing that instead of explaining Tor to them". Which is a fair point I think. https://blog.torproject.org/facebook-hidden-services-and-htt...

If there is no reason for it, then that is a reason against it. Regular people probably don't use Tor.

There's an annoying practical reason to use HTTPS on Tor: some browser features are gated on the page being served from an HTTPS origin. Some of them (like geolocation and payment requests) are likely to be irrelevant to most Tor users, but others (like HTTP2 and Web Crypto) are more generally relevant.

https://developer.mozilla.org/en-US/docs/Web/Security/Secure...

Re: Twitter's onion service is serving an invalid TLS certificate since 3/6/2023

#40

Twitter should not care about having an onion service. Great example of a distraction that the Musk downsizing properly removed.

If you think running an onion service is distracting, wait until you see how distracting trying to become an "everything" app is.
Post reply on HN