exit node sniffing
exit node sniffing is when whoever runs the last relay of your circuit reads the unencrypted part of your traffic - the reason plain http over tor is a bad idea.
traffic leaving a tor exit relay toward a plain http site arrives decrypted at the exit. a malicious or curious exit operator can log destinations, inject content into pages, and capture anything sent in cleartext - login forms, session cookies, message boards without tls. this is not hypothetical: researchers have repeatedly run exits that harvested credentials to demonstrate the risk, and the demonstration results were ugly every time.
https collapses most of the attack: with transport encryption, the exit sees only the domain (via sni) and encrypted blobs. certificate warnings over tor deserve genuine respect - they may indicate exactly this kind of interception rather than an innocent misconfiguration.
onion services sidestep the exit entirely. traffic to a .onion address never leaves the tor network, so there is no exit hop positioned to observe it, and the self-authenticating address provides end-to-end cryptographic assurance without any certificate authority.
practical rules fall out cleanly: never submit credentials over plain http on tor, prefer onion addresses over clearnet mirrors when they exist, and take broken-padlock warnings seriously instead of clicking through them.