Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends on the content of your traffic.

If “deanonymize” strictly means perform a timing attack using info you have from the beginning and end of the circuit, then by definition you’re correct.

But if you visit an identifying set of websites and/or ignore TLS errors or … they can still deanonymize you.



What role do TLS errors play in de-anonymizing onion traffic?


My comment is strictly about exit nodes which are not used as part of connecting to onion services.

Ignoring TLS errors might mean you’re ignoring the fact your exit relay is MitM attacking you.


Thanks, I just wanted to be sure I wasn’t missing something.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: