[tor-talk] Improved HS key management

2013-12-28 Thread Gregory Maxwell
One of the current unfortunate properties of hidden services is that the identity of the hidden service is its public key (or the equivalent hash, in the current setup), and this key must always be available for signing on an online host (usually the HS itself, though potentially on a bastion host)

Re: [tor-talk] Improved HS key management

2013-12-28 Thread grarpamp
On Sat, Dec 28, 2013 at 6:46 AM, Gregory Maxwell wrote: > One of the current unfortunate properties of hidden services is that > the identity of the hidden service is its public key (or the > This is pretty bad for prudent key management— the key is very high > value because its difficult to chan

Re: [tor-talk] Improved HS key management

2013-12-28 Thread Gregory Maxwell
On Sat, Dec 28, 2013 at 1:15 PM, grarpamp wrote: > On Sat, Dec 28, 2013 at 6:46 AM, Gregory Maxwell wrote: >> One of the current unfortunate properties of hidden services is that >> the identity of the hidden service is its public key (or the > >> This is pretty bad for prudent key management— th

Re: [tor-talk] Improved HS key management

2013-12-28 Thread Qingping Hou
On 12/28/2013 06:46 AM, Gregory Maxwell wrote: > One of the current unfortunate properties of hidden services is that > the identity of the hidden service is its public key (or the > equivalent hash, in the current setup), and this key must always be > available for signing on an online host (usual

Re: [tor-talk] Improved HS key management

2013-12-29 Thread Nick Mathewson
On Sat, Dec 28, 2013 at 4:15 PM, grarpamp wrote: > On Sat, Dec 28, 2013 at 6:46 AM, Gregory Maxwell wrote: >> One of the current unfortunate properties of hidden services is that >> the identity of the hidden service is its public key (or the > >> This is pretty bad for prudent key management— th

Re: [tor-talk] Improved HS key management

2014-01-29 Thread George Kadianakis
Qingping Hou writes: > On 12/28/2013 06:46 AM, Gregory Maxwell wrote: >> One of the current unfortunate properties of hidden services is that >> the identity of the hidden service is its public key (or the >> equivalent hash, in the current setup), and this key must always be >> available for sig