Oddbean new post about | logout
 I think these are self signed certs, but honestly, ssl on a Tor Service (.onion site) is not useful afaik. The traffic is end to end encrypted already. 
 nope u missed big part last leg cleartxt - hence using any cert to encrypt is big think
who issue cert is not important - dummy self sign whatever so long sniffer cannot be content is good enough 
 Only if you are visiting a normal website. For .onion site, it is e2e encrypted.

Actually says it here too: https://tb-manual.torproject.org/onion-services/ 
 NOPE IT WORNG EXIT NODE TO FINAL SITE = CLEARTXT 
 even in end to end onion there is possiblity with split traffic vs exit tor to clearnet site without ssl 
 MiM still a possibility