Sauteed Onions: Transparent Associations from Domain Names to Onion Addresses
2022 (English)In: WPES'22: Proceedings of the 21st Workshop on Privacy in the Electronic Society, Association for Computing Machinery (ACM), 2022, Vol. November 2022, p. 35-40Conference paper, Published paper (Refereed)
Abstract [en]
Onion addresses offer valuable features such as lookup and routing security, self-authenticated connections, and censorship resistance. Therefore, many websites are also available as onionsites in Tor. The way registered domains and onion addresses are associated is however a weak link. We introduce sauteed onions, transparent associations from domain names to onion addresses. Our approach relies on TLS certificates to establish onion associations. It is much like today's onion location which relies on Certificate Authorities (CAs) due to its HTTPS requirement, but has the added benefit of becoming public for everyone to see in Certificate Transparency (CT) logs. We propose and prototype two uses of sauteed onions: certificate-based onion location and search engines that use CT logs as the underlying database. The achieved goals are consistency of available onion associations, which mitigates attacks where users are partitioned depending on which onion addresses they are given, forward censorship-resistance after a TLS site has been configured once, and improved third-party discovery of onion associations, which requires less trust while easily scaling to all onionsites that opt-in.
Place, publisher, year, edition, pages
Association for Computing Machinery (ACM), 2022. Vol. November 2022, p. 35-40
Keywords [en]
certificate transparency, onion services, tls certificates, web pki, HTTP, Network security, Search engines, Seebeck effect, Certificate authority, Certificate-based, Domain names, Lookups, Onion service, Routing security, Tls certificate, Weakest links, Transparency
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
URN: urn:nbn:se:kau:diva-92773DOI: 10.1145/3559613.3563208Scopus ID: 2-s2.0-85143256217ISBN: 978-1-4503-9873-2 OAI: oai:DiVA.org:kau-92773DiVA, id: diva2:1722436
Conference
21st Workshop on Privacy in the Electronic Society, Los Angeles, USA, November 7-11, 2022.
Funder
Swedish Foundation for Strategic Research2022-12-292022-12-292023-04-18Bibliographically approved
In thesis