{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T03:50:01Z","timestamp":1772164201148,"version":"3.50.1"},"reference-count":70,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2021,1,29]],"date-time":"2021-01-29T00:00:00Z","timestamp":1611878400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>The security of the web improved greatly throughout the last couple of years. A large majority of the web is now served encrypted as part of HTTPS, and web browsers accordingly moved from positive to negative security indicators that warn the user if a connection is insecure. A secure connection requires that the server presents a valid certificate that binds the domain name in question to a public key. A certificate used to be valid if signed by a trusted Certificate Authority (CA), but web browsers like Google Chrome and Apple\u2019s Safari have additionally started to mandate Certificate Transparency (CT) logging to overcome the weakest-link security of the CA ecosystem. Tor and the Firefox-based Tor Browser have yet to enforce CT.<\/jats:p>\n               <jats:p>In this paper, we present privacy-preserving and incrementally-deployable designs that add support for CT in Tor. Our designs go beyond the currently deployed CT enforcements that are based on blind trust: if a user that uses Tor Browser is man-in-the-middled over HTTPS, we probabilistically detect and disclose cryptographic evidence of CA and\/or CT log misbehavior. The first design increment allows Tor to play a vital role in the overall goal of CT: detect mis-issued certificates and hold CAs accountable. We achieve this by randomly cross-logging a subset of certificates into other CT logs. The final increments hold misbehaving CT logs accountable, initially assuming that some logs are benign and then without any such assumption. Given that the current CT deployment lacks strong mechanisms to verify if log operators play by the rules, exposing misbehavior is important for the web in general and not just Tor. The full design turns Tor into a system for maintaining a probabilistically-verified view of the CT log ecosystem available from Tor\u2019s consensus. Each increment leading up to it preserves privacy due to and how we use Tor.<\/jats:p>","DOI":"10.2478\/popets-2021-0024","type":"journal-article","created":{"date-parts":[[2021,4,6]],"date-time":"2021-04-06T21:02:43Z","timestamp":1617742963000},"page":"194-213","source":"Crossref","is-referenced-by-count":6,"title":["Privacy-Preserving &amp; Incrementally-Deployable Support for Certificate Transparency in Tor"],"prefix":"10.56553","volume":"2021","author":[{"given":"Rasmus","family":"Dahlberg","sequence":"first","affiliation":[{"name":"Karlstad University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tobias","family":"Pulls","sequence":"additional","affiliation":[{"name":"Karlstad University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tom","family":"Ritter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Syverson","sequence":"additional","affiliation":[{"name":"U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,1,29]]},"reference":[{"key":"2022050407480952198_j_popets-2021-0024_ref_001_w2aab3b7c22b1b6b1ab1ab1Aa","doi-asserted-by":"crossref","unstructured":"[1] J. Aas, R. Barnes, B. Case, Z. Durumeric, P. Eckersley, A. Flores-L\u00f3pez, J. A. Halderman, J. Hoffman-Andrews, J. Kasten, E. Rescorla, S. D. Schoen, and B. Warren. Let\u2019s Encrypt: An automated certificate authority to encrypt the entire web. In CCS, 2019.10.1145\/3319535.3363192","DOI":"10.1145\/3319535.3363192"},{"key":"2022050407480952198_j_popets-2021-0024_ref_002_w2aab3b7c22b1b6b1ab1ab2Aa","doi-asserted-by":"crossref","unstructured":"[2] M. Alicherry and A. D. Keromytis. DoubleCheck: Multi-path verification against man-in-the-middle attacks. In ISCC, 2009.10.1109\/ISCC.2009.5202224","DOI":"10.1109\/ISCC.2009.5202224"},{"key":"2022050407480952198_j_popets-2021-0024_ref_003_w2aab3b7c22b1b6b1ab1ab3Aa","unstructured":"[3] Apple Inc. Apple\u2019s certificate transparency log program, January 2019. https:\/\/support.apple.com\/en-om\/HT209255, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_004_w2aab3b7c22b1b6b1ab1ab4Aa","unstructured":"[4] Bugzilla. Implement certificate transparency support (RFC 6962), 2020. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1281469, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_005_w2aab3b7c22b1b6b1ab1ab5Aa","unstructured":"[5] Catalin Cimpanu. Exploit vendor drops Tor Browser zero-day on Twitter, 2018. https:\/\/web.archive.org\/web\/20200529194530\/https:\/\/www.zdnet.com\/article\/exploit-vendor-drops-tor-browser-zero-day-on-twitter\/, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_006_w2aab3b7c22b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] M. Chase and S. Meiklejohn. Transparency overlays and applications. In CCS, 2016.10.1145\/2976749.2978404","DOI":"10.1145\/2976749.2978404"},{"key":"2022050407480952198_j_popets-2021-0024_ref_007_w2aab3b7c22b1b6b1ab1ab7Aa","unstructured":"[7] B. Chor, O. Goldreich, E. Kushilevitz, and M. Sudan. Private information retrieval. In FOCS, 1995."},{"key":"2022050407480952198_j_popets-2021-0024_ref_008_w2aab3b7c22b1b6b1ab1ab8Aa","doi-asserted-by":"crossref","unstructured":"[8] L. Chuat, P. Szalachowski, A. Perrig, B. Laurie, and E. Messeri. Efficient gossip protocols for verifying the consistency of certificate logs. In CNS, 2015.10.1109\/CNS.2015.7346853","DOI":"10.1109\/CNS.2015.7346853"},{"key":"2022050407480952198_j_popets-2021-0024_ref_009_w2aab3b7c22b1b6b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"[9] J. Clark and P. C. van Oorschot. SoK: SSL and HTTPS: revisiting past challenges and evaluating certificate trust model enhancements. In IEEE S&P, 2013.10.1109\/SP.2013.41","DOI":"10.1109\/SP.2013.41"},{"key":"2022050407480952198_j_popets-2021-0024_ref_010_w2aab3b7c22b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] M. Conti, S. Crane, T. Frassetto, A. Homescu, G. Koppen, P. Larsen, C. Liebchen, M. Perry, and A. Sadeghi. Selfrando: Securing the Tor Browser against de-anonymization exploits. PoPETs, 2016(4), 2016.10.1515\/popets-2016-0050","DOI":"10.1515\/popets-2016-0050"},{"key":"2022050407480952198_j_popets-2021-0024_ref_011_w2aab3b7c22b1b6b1ab1ac11Aa","unstructured":"[11] CT policy mailing list (n.d.). Certificate transparency policy. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!forum\/ct-policy, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_012_w2aab3b7c22b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] R. Dahlberg and T. Pulls. Verifiable light-weight monitoring for certificate transparency logs. In NordSec, 2018.10.1007\/978-3-030-03638-6_11","DOI":"10.1007\/978-3-030-03638-6_11"},{"key":"2022050407480952198_j_popets-2021-0024_ref_013_w2aab3b7c22b1b6b1ab1ac13Aa","unstructured":"[13] R. Dahlberg, T. Pulls, T. Ritter, and P. Syverson. SFO distribution artificat, December 2020. https:\/\/github.com\/rgdd\/ctor\/tree\/master\/artifact, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_014_w2aab3b7c22b1b6b1ab1ac14Aa","unstructured":"[14] R. Dahlberg, T. Pulls, J. Vestin, T. H\u00f8iland-J\u00f8rgensen, and A. Kassler. Aggregation-based certificate transparency gossip. In SECURWARE, 2019."},{"key":"2022050407480952198_j_popets-2021-0024_ref_015_w2aab3b7c22b1b6b1ab1ac15Aa","unstructured":"[15] G. Danezis and P. Syverson. Bridging and fingerprinting: Epistemic attacks on route selection. In PETS, 2008."},{"key":"2022050407480952198_j_popets-2021-0024_ref_016_w2aab3b7c22b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] R. Dingledine, N. Mathewson, and P. F. Syverson. Tor: The second-generation onion router. In USENIX Security, 2004.10.21236\/ADA465464","DOI":"10.21236\/ADA465464"},{"key":"2022050407480952198_j_popets-2021-0024_ref_017_w2aab3b7c22b1b6b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"[17] B. Dowling, F. G\u00fcnther, U. Herath, and D. Stebila. Secure logging schemes and certificate transparency. In ESORICS, 2016.10.1007\/978-3-319-45741-3_8","DOI":"10.1007\/978-3-319-45741-3_8"},{"key":"2022050407480952198_j_popets-2021-0024_ref_018_w2aab3b7c22b1b6b1ab1ac18Aa","doi-asserted-by":"crossref","unstructured":"[18] Z. Durumeric, J. Kasten, M. Bailey, and J. A. Halderman. Analysis of the HTTPS certificate ecosystem. In IMC, 2013.10.1145\/2504730.2504755","DOI":"10.1145\/2504730.2504755"},{"key":"2022050407480952198_j_popets-2021-0024_ref_019_w2aab3b7c22b1b6b1ab1ac19Aa","unstructured":"[19] P. Eckersley. A Syrian man-in-the-middle attack against Facebook, 2011. https:\/\/www.eff.org\/deeplinks\/2011\/05\/syrian-man-middle-against-facebook, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_020_w2aab3b7c22b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] S. Eskandarian, E. Messeri, J. Bonneau, and D. Boneh. Certificate transparency with privacy. PoPETs, 2017(4), 2017.10.1515\/popets-2017-0052","DOI":"10.1515\/popets-2017-0052"},{"key":"2022050407480952198_j_popets-2021-0024_ref_021_w2aab3b7c22b1b6b1ab1ac21Aa","unstructured":"[21] N. S. Evans, R. Dingledine, and C. Grothoff. A practical congestion attack on Tor using long paths. In USENIX Security, 2009."},{"key":"2022050407480952198_j_popets-2021-0024_ref_022_w2aab3b7c22b1b6b1ab1ac22Aa","unstructured":"[22] firstwatch at sigaint.org. [tor-talk] javascript exploit, 2016. https:\/\/web.archive.org\/web\/20200529194407\/https:\/\/lists.torproject.org\/pipermail\/tor-talk\/2016-November\/042639.html, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_023_w2aab3b7c22b1b6b1ab1ac23Aa","unstructured":"[23] Google LLC. Minimal gossip, May 2018. https:\/\/github.com\/google\/trillian-examples\/blob\/master\/gossip\/minimal\/README.md, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_024_w2aab3b7c22b1b6b1ab1ac24Aa","unstructured":"[24] Google LLC. Chromium certificate transparency policy, October 2020. https:\/\/github.com\/chromium\/ct-policy\/blob\/master\/README.md, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_025_w2aab3b7c22b1b6b1ab1ac25Aa","unstructured":"[25] Google LLC. Trillian log signer, June 2020. https:\/\/github.com\/google\/trillian\/blob\/master\/cmd\/trillian_log_signer\/main.go, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_026_w2aab3b7c22b1b6b1ab1ac26Aa","unstructured":"[26] Google LLC. (n.d.). HTTPS encryption on the web. https:\/\/transparencyreport.google.com\/https\/overview?hl=en, accessed 2020-05-19."},{"key":"2022050407480952198_j_popets-2021-0024_ref_027_w2aab3b7c22b1b6b1ab1ac27Aa","doi-asserted-by":"crossref","unstructured":"[27] B. Greschbach, T. Pulls, L. M. Roberts, P. Winter, and N. Feamster. The effect of DNS on Tor\u2019s anonymity. In NDSS, 2017.10.14722\/ndss.2017.23311","DOI":"10.14722\/ndss.2017.23311"},{"key":"2022050407480952198_j_popets-2021-0024_ref_028_w2aab3b7c22b1b6b1ab1ac28Aa","unstructured":"[28] K. Hill. How did the FBI break Tor?, 2014. https:\/\/www.forbes.com\/sites\/kashmirhill\/2014\/11\/07\/howdid-law-enforcement-break-tor\/#6cf2ed594bf7, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_029_w2aab3b7c22b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] D. Kales, O. Omolola, and S. Ramacher. Revisiting user privacy for certificate transparency. In IEEE EuroS&P, 2019.10.1109\/EuroSP.2019.00039","DOI":"10.1109\/EuroSP.2019.00039"},{"key":"2022050407480952198_j_popets-2021-0024_ref_030_w2aab3b7c22b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] D. Kesdogan, J. Egner, and R. B\u00fcschkes. Stop-and-Go MIXes: Providing probabilistic anonymity in an open system. In IH, 1998.10.1007\/3-540-49380-8_7","DOI":"10.1007\/3-540-49380-8_7"},{"key":"2022050407480952198_j_popets-2021-0024_ref_031_w2aab3b7c22b1b6b1ab1ac31Aa","unstructured":"[31] N. Korzhitskii and N. Carlsson. Characterizing the root landscape of certificate transparency logs. In IFIP Networking, 2020."},{"key":"2022050407480952198_j_popets-2021-0024_ref_032_w2aab3b7c22b1b6b1ab1ac32Aa","unstructured":"[32] A. Langley. Enhancing digital certificate security, 2013. https:\/\/security.googleblog.com\/2013\/01\/enhancing-digital-certificate-security.html, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_033_w2aab3b7c22b1b6b1ab1ac33Aa","unstructured":"[33] A. Langley. No, don\u2019t enable revocation checking, 2014. https:\/\/www.imperialviolet.org\/2014\/04\/19\/revchecking.html, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_034_w2aab3b7c22b1b6b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"[34] B. Laurie. Certificate transparency. Commun. ACM, 57(10), 2014.10.1145\/2659897","DOI":"10.1145\/2659897"},{"key":"2022050407480952198_j_popets-2021-0024_ref_035_w2aab3b7c22b1b6b1ab1ac35Aa","unstructured":"[35] B. Laurie. Certificate transparency over DNS, March 2016. https:\/\/github.com\/google\/certificate-transparency-rfcs\/blob\/master\/dns\/draft-ct-over-dns.md, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_036_w2aab3b7c22b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"[36] B. Laurie, A. Langley, and E. Kasper. Certificate transparency. RFC 6962, IETF, 2013.10.17487\/rfc6962","DOI":"10.17487\/rfc6962"},{"key":"2022050407480952198_j_popets-2021-0024_ref_037_w2aab3b7c22b1b6b1ab1ac37Aa","unstructured":"[37] B. Laurie, A. Langley, E. Kasper, E. Messeri, and R. Stradling. Certificate transparency version 2.0. Internet-draft draft-ietf-trans-rfc6962-bis-34, IETF, 2019."},{"key":"2022050407480952198_j_popets-2021-0024_ref_038_w2aab3b7c22b1b6b1ab1ac38Aa","doi-asserted-by":"crossref","unstructured":"[38] B. Li, J. Lin, F. Li, Q. Wang, Q. Li, J. Jing, and C. Wang. Certificate transparency in the wild: Exploring the reliability of monitors. In CCS, 2019.10.1145\/3319535.3345653","DOI":"10.1145\/3319535.3345653"},{"key":"2022050407480952198_j_popets-2021-0024_ref_039_w2aab3b7c22b1b6b1ab1ac39Aa","doi-asserted-by":"crossref","unstructured":"[39] W. Lueks and I. Goldberg. Sublinear scaling for multi-client private information retrieval. In FC, 2015.10.1007\/978-3-662-47854-7_10","DOI":"10.1007\/978-3-662-47854-7_10"},{"key":"2022050407480952198_j_popets-2021-0024_ref_040_w2aab3b7c22b1b6b1ab1ac40Aa","doi-asserted-by":"crossref","unstructured":"[40] A. Mani, T. Wilson-Brown, R. Jansen, A. Johnson, and M. Sherr. Understanding Tor usage with privacy-preserving measurement. In IMC, 2018.10.1145\/3278532.3278549","DOI":"10.1145\/3278532.3278549"},{"key":"2022050407480952198_j_popets-2021-0024_ref_041_w2aab3b7c22b1b6b1ab1ac41Aa","unstructured":"[41] B. McMillion. Un-incorporated SCTs from GDCA1, 2018. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/ct-policy\/Emh3ZaU0jqI, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_042_w2aab3b7c22b1b6b1ab1ac42Aa","unstructured":"[42] S. Meiklejohn, P. Kalinnikov, C. S. Lin, M. Hutchinson, G. Belvin, M. Raykova, and A. Cutter. Think global, act local: Gossip and client audits in verifiable data structures, 2020. https:\/\/arxiv.org\/pdf\/2011.04551.pdf, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_043_w2aab3b7c22b1b6b1ab1ac43Aa","unstructured":"[43] Mozilla. Mozilla research grants 2019H1, 2019. https:\/\/web.archive.org\/web\/20200528174708\/https:\/\/mozilla-research.forms.fm\/mozilla-research-grants-2019h1\/forms\/6510, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_044_w2aab3b7c22b1b6b1ab1ac44Aa","unstructured":"[44] Mozilla (n.d.). SSL ratios. https:\/\/docs.telemetry.mozilla.org\/datasets\/other\/ssl\/reference.html, accessed 2020-05-19."},{"key":"2022050407480952198_j_popets-2021-0024_ref_045_w2aab3b7c22b1b6b1ab1ac45Aa","unstructured":"[45] L. Nordberg. Tor consensus transparency, June 2014. https:\/\/github.com\/torproject\/torspec\/blob\/master\/proposals\/267-tor-consensus-transparency.txt, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_046_w2aab3b7c22b1b6b1ab1ac46Aa","unstructured":"[46] L. Nordberg, D. K. Gillmor, and T. Ritter. Gossiping in CT. Internet-draft draft-ietf-trans-gossip-05, IETF, 2018."},{"key":"2022050407480952198_j_popets-2021-0024_ref_047_w2aab3b7c22b1b6b1ab1ac47Aa","unstructured":"[47] P. H. O\u2019Neill. Telegram traffic from around the world took a detour through Iran, 2018. https:\/\/www.cyberscoop.com\/telegram-iran-bgp-hijacking\/, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_048_w2aab3b7c22b1b6b1ab1ac48Aa","unstructured":"[48] M. Perry, E. Clark, S. Murdoch, and G. Koppen. The design and implementation of the Tor Browser [DRAFT], June 2018."},{"key":"2022050407480952198_j_popets-2021-0024_ref_049_w2aab3b7c22b1b6b1ab1ac49Aa","unstructured":"[49] J. Prins. DigiNotar certificate authority breach \u201coperation black tulip\u201d. Interim report, Fox-IT, 2011."},{"key":"2022050407480952198_j_popets-2021-0024_ref_050_w2aab3b7c22b1b6b1ab1ac50Aa","unstructured":"[50] J. Rowley. CT2 log compromised via Salt vulnerability, 2020. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/ct-policy\/aKNbZuJzwfM, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_051_w2aab3b7c22b1b6b1ab1ac51Aa","unstructured":"[51] A. Siddiqui. What happened? The Amazon Route 53 BGP hijack to take over Ethereum cryptocurrency wallets, 2018. https:\/\/www.internetsociety.org\/blog\/2018\/04\/amazons-route-53-bgp-hijack\/, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_052_w2aab3b7c22b1b6b1ab1ac52Aa","unstructured":"[52] R. Sleevi. Upcoming CT log removal: Izenpe, 2016. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/ct-policy\/qOorKuhL1vA, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_053_w2aab3b7c22b1b6b1ab1ac53Aa","unstructured":"[53] R. Sleevi. Upcoming log removal: Venafi CT log server, 2017. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!topic\/ct-policy\/KMAcNT3asTQ, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_054_w2aab3b7c22b1b6b1ab1ac54Aa","unstructured":"[54] R. Sleevi and E. Messeri. Certificate transparency in Chrome: Monitoring CT logs consistency, March 2017. https:\/\/docs.google.com\/document\/d\/1FP5J5Sfsg0OR9P4YT0q1dM02iavhi8ix1mZlZe_zls\/edit?pref=2&pli=1, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_055_w2aab3b7c22b1b6b1ab1ac55Aa","doi-asserted-by":"crossref","unstructured":"[55] E. Stark, R. Sleevi, R. Muminovic, D. O\u2019Brien, E. Messeri, A. P. Felt, B. McMillion, and P. Tabriz. Does certificate transparency break the web? Measuring adoption and error rate. In IEEE S&P, 2019.10.1109\/SP.2019.00027","DOI":"10.1109\/SP.2019.00027"},{"key":"2022050407480952198_j_popets-2021-0024_ref_056_w2aab3b7c22b1b6b1ab1ac56Aa","unstructured":"[56] E. Stark and C. Thompson. Opt-in SCT auditing, September 2020. https:\/\/docs.google.com\/document\/d\/1G1Jy8LJgSqJB673GnTYIG4b7XRw2ZLtvvSlrqFcl4A\/edit, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_057_w2aab3b7c22b1b6b1ab1ac57Aa","unstructured":"[57] J. Stewart. BGP hijacking for cryptocurrency profit, 2014. https:\/\/www.secureworks.com\/research\/bgp-hijacking-forcryptocurrency-profit, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_058_w2aab3b7c22b1b6b1ab1ac58Aa","doi-asserted-by":"crossref","unstructured":"[58] E. Syta, I. Tamas, D. Visher, D. I. Wolinsky, P. Jovanovic, L. Gasser, N. Gailly, I. Khoffi, and B. Ford. Keeping authorities \u201chonest or bust\u201d with decentralized witness cosigning. In IEEE S&P, 2016.10.1109\/SP.2016.38","DOI":"10.1109\/SP.2016.38"},{"key":"2022050407480952198_j_popets-2021-0024_ref_059_w2aab3b7c22b1b6b1ab1ac59Aa","doi-asserted-by":"crossref","unstructured":"[59] A. Tomescu and S. Devadas. Catena: Efficient nonequivocation via Bitcoin. In IEEE S&P, 2017.10.1109\/SP.2017.19","DOI":"10.1109\/SP.2017.19"},{"key":"2022050407480952198_j_popets-2021-0024_ref_060_w2aab3b7c22b1b6b1ab1ac60Aa","unstructured":"[60] Tor Project. Getting up to speed on Tor\u2019s past, present, and future. https:\/\/2019.www.torproject.org\/docs\/documentation.html.en, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_061_w2aab3b7c22b1b6b1ab1ac61Aa","unstructured":"[61] Tor project. Advertised and consumed bandwidth by relay flag, 2020. https:\/\/metrics.torproject.org\/bandwidth-flags.html, accessed 2020-05-30."},{"key":"2022050407480952198_j_popets-2021-0024_ref_062_w2aab3b7c22b1b6b1ab1ac62Aa","unstructured":"[62] Tor project. Relays by relay flag, 2020. https:\/\/metrics.torproject.org\/relayflags.html, accessed 2020-05-29."},{"key":"2022050407480952198_j_popets-2021-0024_ref_063_w2aab3b7c22b1b6b1ab1ac63Aa","unstructured":"[63] Tor Project (n.d.). Functions to queue create cells for processing. https:\/\/src-ref.docs.torproject.org\/tor\/onion__queue_8c_source.html, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_064_w2aab3b7c22b1b6b1ab1ac64Aa","unstructured":"[64] Tor project (n.d.). Relay requirements. https:\/\/community.torproject.org\/relay\/relays-requirements\/, accessed 2020-05-29."},{"key":"2022050407480952198_j_popets-2021-0024_ref_065_w2aab3b7c22b1b6b1ab1ac65Aa","unstructured":"[65] U.S. Dept. of Justice. More than 400. onion addresses, including dozens of \u2018dark market\u2019 sites, targeted as part of global enforcement action on Tor network, 2014. https:\/\/www.fbi.gov\/news\/pressrel\/press-releases\/more-than-400-.onion-addresses-including-dozens-of-dark-market-sites-targeted-as-part-of-global-enforcement-action-on-tor-network, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_066_w2aab3b7c22b1b6b1ab1ac66Aa","unstructured":"[66] Wikipedia contributors. BGP hijacking\u2014Wikipedia, the free encyclopedia, 2020. https:\/\/en.wikipedia.org\/w\/index.php?title=BGP_hijacking&oldid=964360841, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_067_w2aab3b7c22b1b6b1ab1ac67Aa","unstructured":"[67] C. Wilson. CT days 2020. https:\/\/groups.google.com\/a\/chromium.org\/g\/ct-policy\/c\/JWVVhZTL5RM, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_068_w2aab3b7c22b1b6b1ab1ac68Aa","doi-asserted-by":"crossref","unstructured":"[68] P. Winter, R. K\u00f6wer, M. Mulazzani, M. Huber, S. Schrittwieser, S. Lindskog, and E. R. Weippl. Spoiled onions: Exposing malicious Tor exit relays. In PETS, 2014.10.1007\/978-3-319-08506-7_16","DOI":"10.1007\/978-3-319-08506-7_16"},{"key":"2022050407480952198_j_popets-2021-0024_ref_069_w2aab3b7c22b1b6b1ab1ac69Aa","unstructured":"[69] Zerodium. Tor Browser zero-day exploit bounty (expired), 2017. https:\/\/web.archive.org\/web\/20200528175225\/https:\/\/zerodium.com\/tor.html, accessed 2020-12-15."},{"key":"2022050407480952198_j_popets-2021-0024_ref_070_w2aab3b7c22b1b6b1ab1ac70Aa","unstructured":"[70] Zerodium. Our exploit acquisition program, 2020. https:\/\/web.archive.org\/web\/20200521151311\/https:\/\/zerodium.com\/program.html, accessed 2020-05-21."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:24Z","timestamp":1658334684000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0024.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,29]]},"references-count":70,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2021,1,29]]},"published-print":{"date-parts":[[2021,4,1]]}},"alternative-id":["10.2478\/popets-2021-0024"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0024","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,29]]}}}