<- Back
Comments (97)
- p4bl0My personal website has been hosted on Tor for years. It's easy to do from your home even behind a NAT because it's an outgoing connection from your point of view (which also makes it a great way to expose local services even when you are behind a NAT and don't not have a static IP), and by design your personal IP is hidden from your visitors.I wrote about it in 2600 almost ten years ago (already?!). A copy of my article can be found here: https://pablorauzy.fr/outreach/2600/how-to-run-a-tor-hidden-...If you have an Onion copy of your website, don't forget the Onion-Location http header which will automatically redirect Tor Browser users to the onion version of the website even if they visit it at the clear web address.If it interests people, I also have a follow up article about I2P: https://pablorauzy.fr/outreach/2600/how-to-run-an-i2p-hidden...
- ivanmontillamWhat I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).- Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.- Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.If you can ship your website to the browser in a single connection, you've won.I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.--[0]: https://news.ycombinator.com/item?id=49872320EDIT: Formatting of bullet points.
- basilikumYou probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it: https://community.torproject.org/onion-services/advanced/oni...
- mzajcBesides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:> HiddenServicePort 80 127.13.37.1:8080> listen 127.13.37.1:8080;This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
- kittikittiThe "thousands of volunteer-run servers" on Tor is mainly the CIA and FBI.
- dherlsWhat is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?
- coldbluesI recommend that people give I2P and Yggdrasil a try as well, especially Yggdrasil. It makes no compromises on speed and latency, but it has no anonymity.
- comrade1234Besides accessing your page are random people able to use your server as an exit node? Am I thinking the right thing... I met someone in Switzerland that was hosting anonymous exit nodes to some anonymous network and he said that it was a pain having to explain what was happening to the police.
- jan_m_savageabsolutely love how OP's site is designed. It's clean and minimal, fast and user-friendly, but also stylish.
- hoistwayAdds a whole new layer of paranoia, but for some things, it's probably the only way to genuinely stay off the grid.
- dalvrosaThanks for sharing! Happy to get feedback :)
- sermah> so that no single party can link who you are to what you are doingsome single parties called government agencies pretty much can. it’s just much harder to do, so you’re safe from random people
- charcircuitA few more tips.1. If you want to improve page load speed you need to buy a HTTPS certificate so you are not limited to HTTP/1.1. Multiplexing in HTTP/2 is important for getting sites to load fast.2. You can set the HiddenServiceExportCircuitID configuration to pass the circuit id to your web server for telemetry or anti abuse purposes. Otherwise your logs will say that all users are coming from the same IP.https://blog.cloudflare.com/cloudflare-onion-service
- anonundefined
- nonasking_No DNS, no CA, no exposed IP. Just a ridiculously long string of characters and a bit of determination.
- shevy-javaI like the idea of TOR, but whenever I used it, I hit a speed penalty.This, in turn, handicaps me searching for information. If they could fix this problem then I would be more likely to make use of TOR. We really need to think long-term about a future web that isn't ruined by Google etc... while also not being locked down such as via age-gating.
- superkuhThe one thing I learned from hosting superkuhbitj6tul.onion (from a home computer) for ham radio and science stuff for about a decade was that EVERYTHING ON A .ONION IS EPHEMERAL. When the tor project correctly decided that for high security torv2 no longer was anonymous enough they unilaterally wiped out every torv2 .onion site that existed. Every link that was made between these sites came to an end in 2021 when they released a tor client without support for torv2 onions and tore the web to pieces.Know this: the "dark web" is not for people who just want to own your domain name. It's for SECURITY and that use case is going to drive all their decisions. And if it wipes out every community in the entire tor dark web? So be it. And they'll do it again. Don't build your communities on the sand that is the dark web. You won't like the result.
- 6510Imagine if normal people could install a single normal application and just run a website from a folder. CLI makes it more difficult than hosting a normal website. Typing commands you don't understand doesn't seem all that of a great idea.
- hn9zmdcaouNice thing is you skip port forwarding entirely, which matters a lot if your ISP has you behind CGNAT. Curious how people handle uptime though, since a hidden service going down isn't something you notice until someone tells you.
- han1My open source project (https://github.com/du82/nonograph) spawns a Tor hidden service with Onion-Location advertising by default, and on the Docker container its always on and self-healing
- tobin1994[dead]
- GnosiWorksthe thing that surprised me running an onion service was reachability, not setup. a fresh or restarted service can take a while before clients find it, so anything that has to work on first try needs a fallback. and if some of your users are where tor is blocked, plain tor isn't enough, you need bridges like obfs4 or snowflake
- hndhyc0bdtRan a small onion site for a couple years and the nice part is you never touch a public IP or a cert. Downside is onion v3 addresses are impossible to share verbally and the latency makes anything chatty feel broken. Static pages only, honestly.