Rendered at 07:40:35 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ivanmontillam 6 hours ago [-]
What I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:
- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).
- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).
- Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.
- Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.
As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.
If you can ship your website to the browser in a single connection, you've won.
I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.
Also DDoS becomes a problem, and the ways it's done are pretty specific to Tor. Double captchas are necessary when you're getting DDoSed, due to performance reasons. Oh, and captchas are also pretty specific to Tor as well.
There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).
>avoid JS for them
Using any JS defies the point and makes your site instantly suspicious.
dalvrosa 41 minutes ago [-]
How are captchas done?
boredatoms 6 hours ago [-]
Are these simply good ideas regardless of tor?
nephanth 17 minutes ago [-]
Depends on which ones. Embedding assets as base64 makes little sense nowadays with http pipelining.
Relyinging the least possible on js, and using CSS for animations sounds like good engineering to me
ivanmontillam 5 hours ago [-]
With CDNs of today, they are not so much relevant for the clearnet.
Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:
> HiddenServicePort 80 127.13.37.1:8080
> listen 127.13.37.1:8080;
This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
AFAIK TCP outperforms Unix sockets for some odd reason, but it's irrelevant anyway because you aren't getting that much bandwidth through Tor.
sermah 46 minutes ago [-]
> so that no single party can link who you are to what you are doing
some single parties called government agencies pretty much can. it’s just much harder to do, so you’re safe from random people
dherls 8 hours ago [-]
What is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?
dalvrosa 8 hours ago [-]
Fair point. Very small things like RSS, canonical link or og:url or microformats use absolute URL
To make sure once in the .onion, you never leave the .onion
xena 2 hours ago [-]
Website impersonation/fronting is a big problem in onionland, this at least makes fronters need to take more effort.
comrade1234 8 hours ago [-]
Besides accessing your page are random people able to use your server as an exit node? Am I thinking the right thing... I met someone in Switzerland that was hosting anonymous exit nodes to some anonymous network and he said that it was a pain having to explain what was happening to the police.
creatonez 7 hours ago [-]
Exit node are an entirely optional part of the Tor network. If you run a relay or a hidden service you are not forced to participate in the exit node side of things. It's also not recommended to combine these roles because it could have security implications for your hidden service.
someonebaggy 29 minutes ago [-]
You can't accidentally run an exit node.
fishgoesblub 8 hours ago [-]
Running a Tor exit node is a manual process. Running a hidden service like a website, or chat server doesn't involve anything like that.
8 hours ago [-]
dalvrosa 8 hours ago [-]
That'd be an exit relay, not doing that atm, just in case
basilikum 8 hours ago [-]
No
dalvrosa 9 hours ago [-]
Thanks for sharing! Happy to get feedback :)
nonasking_ 1 hours ago [-]
No DNS, no CA, no exposed IP. Just a ridiculously long string of characters and a bit of determination.
2 hours ago [-]
shevy-java 44 minutes ago [-]
I like the idea of TOR, but whenever I used it, I hit a speed penalty.
This, in turn, handicaps me searching for information. If they could fix this problem then I would be more likely to make use of TOR. We really need to think long-term about a future web that isn't ruined by Google etc... while also not being locked down such as via age-gating.
dalvrosa 39 minutes ago [-]
Agreed, it can be quite painful
superkuh 5 hours ago [-]
The one thing I learned from hosting superkuhbitj6tul.onion (from a home computer) for ham radio and science stuff for about a decade was that EVERYTHING ON A .ONION IS EPHEMERAL. When the tor project correctly decided that for high security torv2 no longer was anonymous enough they unilaterally wiped out every torv2 .onion site that existed. Every link that was made between these sites came to an end in 2021 when they released a tor client without support for torv2 onions and tore the web to pieces.
Know this: the "dark web" is not for people who just want to own your domain name. It's for SECURITY and that use case is going to drive all their decisions. And if it wipes out every community in the entire tor dark web? So be it. And they'll do it again. Don't build your communities on the sand that is the dark web. You won't like the result.
h0p3 3 hours ago [-]
You're not wrong about significant brittleness and lack of sovereignty (and the same should be said about the web, too, roughly speaking), but I don't think your prescription is correct. Thus far, my only solution has been to maintain a variety of gateways to the same signed object which itself provides the evolving list of connection gateways. Gotta stay ahead of the whackamole through diversity, imho. I've found my i2p and tor identities have actually been some of the longest lasting, especially compared to non-bigcorpo clearnet web hosts. That's definitely not how most people want to use the net, ofc, but it's probably the right kind of practice that we should collectively be engaged in together if we want communities that actually own the means of production about as far as we reasonably can atm. And, these days, LLMs make this process much, much easier, too, as rediscovery and rebuilding custom infra per individual or community is far more doable for the average person (if they really wanted to do it, and I'm not claiming they would*).
brnt 4 hours ago [-]
Don't tie anything to a domain name you mean. Advice that's just as valid for clearnet.
v2 onions being deprecated was announced long in advance so many sites managed their transfer by announced the new URL well in advance. I don't think anyone was really bothered.
charcircuit 6 hours ago [-]
A few more tips.
1. If you want to improve page load speed you need to buy a HTTPS certificate so you are not limited to HTTP/1.1. Multiplexing in HTTP/2 is important for getting sites to load fast.
2. You can set the HiddenServiceExportCircuitID configuration to pass the circuit id to your web server for telemetry or anti abuse purposes. Otherwise your logs will say that all users are coming from the same IP.
Fascinating, onion services are always encrypted by the tor network but still tunnel "cleartext" http inside that, and there are no CAs that issue free of charge certificates for .onion domains, and therefore there's no free of charge way to get http/2 on onion services without self signing.
Which raises the question: why not just trust self-signed certificates on onion services? From my brief look it seems to be because the Tor project views the primary purposes of HTTPS on onion services to be other things rather than just http/2 support: http/2 isn't even mentioned on their page about https for onion services (https://community.torproject.org/onion-services/advanced/htt...). Unfortunate.
charcircuit 5 hours ago [-]
I personally would support automatically trusting self signed https certs since their key is typically secured under the same safety as the hidden service's key. And even when they are not the browser has no warning when you get downgraded to HTTP on an onion compared to a regular site.
Trying to push hidden services to stay on HTTP is going against what the rest of the web is doing and as a minority of web traffic it really should be aligned to the rest of the web and also require HTTPS. Yes, it's technically wasteful, but reduces both work and security risk by keeping security models aligned with the rest of the web.
littlecranky67 1 hours ago [-]
And it breaks Javascript as a lot of APIs only work when the site is served via HTTP - which .onion sites won't be usually. Tor browser treats .onion sites as secure content, but not your regular browser using TOR via proxy.
someonebaggy 27 minutes ago [-]
Who would issue the certificates?
Cider9986 5 hours ago [-]
Can you buy one of these in XMR?
charcircuit 5 hours ago [-]
Not directly.
6510 7 hours ago [-]
Imagine if normal people could install a single normal application and just run a website from a folder. CLI makes it more difficult than hosting a normal website. Typing commands you don't understand doesn't seem all that of a great idea.
If you don't understand what a command does, go learn it.
paulryanrogers 4 hours ago [-]
For us that's fine. It's quite a hill to climb for non technical folks. Even AIs holding their hand will have to do a lot of explaining.
hn9zmdcaou 9 hours ago [-]
Nice thing is you skip port forwarding entirely, which matters a lot if your ISP has you behind CGNAT. Curious how people handle uptime though, since a hidden service going down isn't something you notice until someone tells you.
drxzcl 2 hours ago [-]
Same as you handle uptime on anything else: you use monitoring software.
If people need to tell you your services are down, you end up eating a huge amount of downtime.
dalvrosa 7 hours ago [-]
Agreed yeah. Mine has been up with no issues so far for ~half a year.
My open source project (https://github.com/du82/nonograph) spawns a Tor hidden service with Onion-Location advertising by default, and on the Docker container its always on and self-healing
dalvrosa 53 minutes ago [-]
Thanks for sharing
hndhyc0bdt 9 hours ago [-]
Ran a small onion site for a couple years and the nice part is you never touch a public IP or a cert. Downside is onion v3 addresses are impossible to share verbally and the latency makes anything chatty feel broken. Static pages only, honestly.
someonebaggy 7 hours ago [-]
You have to keep chattiness low, but a lot of SSR stuff works fine. Dread uses SSR, and even nags you if you have JavaScript enabled.
- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).
- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).
- Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.
- Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.
As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.
If you can ship your website to the browser in a single connection, you've won.
I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.
--
[0]: https://news.ycombinator.com/item?id=49872320
EDIT: Formatting of bullet points.
There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).
>avoid JS for them
Using any JS defies the point and makes your site instantly suspicious.
Relyinging the least possible on js, and using CSS for animations sounds like good engineering to me
> HiddenServicePort 80 127.13.37.1:8080
> listen 127.13.37.1:8080;
This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
some single parties called government agencies pretty much can. it’s just much harder to do, so you’re safe from random people
To make sure once in the .onion, you never leave the .onion
This, in turn, handicaps me searching for information. If they could fix this problem then I would be more likely to make use of TOR. We really need to think long-term about a future web that isn't ruined by Google etc... while also not being locked down such as via age-gating.
Know this: the "dark web" is not for people who just want to own your domain name. It's for SECURITY and that use case is going to drive all their decisions. And if it wipes out every community in the entire tor dark web? So be it. And they'll do it again. Don't build your communities on the sand that is the dark web. You won't like the result.
v2 onions being deprecated was announced long in advance so many sites managed their transfer by announced the new URL well in advance. I don't think anyone was really bothered.
1. If you want to improve page load speed you need to buy a HTTPS certificate so you are not limited to HTTP/1.1. Multiplexing in HTTP/2 is important for getting sites to load fast.
2. You can set the HiddenServiceExportCircuitID configuration to pass the circuit id to your web server for telemetry or anti abuse purposes. Otherwise your logs will say that all users are coming from the same IP.
https://blog.cloudflare.com/cloudflare-onion-service
Which raises the question: why not just trust self-signed certificates on onion services? From my brief look it seems to be because the Tor project views the primary purposes of HTTPS on onion services to be other things rather than just http/2 support: http/2 isn't even mentioned on their page about https for onion services (https://community.torproject.org/onion-services/advanced/htt...). Unfortunate.
Trying to push hidden services to stay on HTTP is going against what the rest of the web is doing and as a minority of web traffic it really should be aligned to the rest of the web and also require HTTPS. Yes, it's technically wasteful, but reduces both work and security risk by keeping security models aligned with the rest of the web.
If people need to tell you your services are down, you end up eating a huge amount of downtime.
(There are solutions for CGNAT - https://david.alvarezrosa.com/posts/self-hosting-behind-cgna...)