Reddit Onion Site: Unexplained Certificate error

When I tried to open the Reddit Onion site https://www.reddittorjg6rue252oqsxryoxengawnmo46qy4kyii5wtqnwfj4ooad.onion/ using version 13.52 on Sept-1-2024 I get Warning potential security risk ahead.

I do not believe Tor uses certificates and it does not display any certificate information and since the time on my workstation is correct what is the cause of this error ?

I tried to place this on r/tor and it was removed

1 Like

Although not required for onion services (since data is already encrypted), using certificates is possible for a little extra security. You are seeing that error because the certificate they were using has expired, which you can see from the details.

More info:
https://forum.torproject.org/t/reddit-onion-service-launch/5305/8?u=capole

1 Like

The tor browser does not display certificate information as I have shown with my image so how are you able to determine it is a certificate error and where did you get that error message? Can you show the certificate ?

1 Like

Just click on Advanced... and the browser will tell you what the error with the certificate is. And if you click on View certificate, you’ll be able to see the details. It was issued 30 Aug 2023 and was valid until 29 Aug 2024.

1 Like

I get this error when visiting the site

2 Likes

It’s because they have published the Onion with “https” it’s normal behavior.

A series of conditions must be met so that the alert does not appear.

Anyway, there’s no need to worry.

Source:

No, that’s incorrect. It is not normal for this message to appear, and the Reddit onion has operated for years without this error. Ignoring the error and continuing to the site is not just insecure practice, it’s impractical because none of the stylesheets or images will load since they’re on different subdomains whose certificates have also expired.

The problem is that Reddit has let the certificate, which used to be valid, expire on August 28th. The question is, will the certificate ever be renewed, or are they content leaving the site unusable, effectively shutting down the onion service?

Thanks. I did find it.
I was expecting the tor browser to show the onion certificate information which it does not. It is strange that Reddit got a certificate for a onion site especially since they do not allow connections via Tor for at least a year.

This problem is fixed, Reddit renewed the certificate of the onion site, now valid till 04 Sep 2025.

1 Like

I see they updated the onion certificate and it is now valid. But the question still is why ? From posts from Reddit they are preventing logins using Tor, is this not the case ?

Now when I try to log into reddit site I get the following.

I suspect this is a communications issue between noscript but since noscript cannot be removed I cannot test.

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.