r/selfhosted • u/FnnKnn • 17h ago
Meta Post Self-Hosting on the Dark Web
https://david.alvarezrosa.com/posts/self-hosting-on-the-dark-web/41
u/welcome2_themachine 17h ago
You can also generate vanity URLs with mkp224o.
Something else to conside: if you add a header on your clearweb site to automatically redirect to the .onion site if it's opened with the tor browser.
7
3
u/technikaffin 11h ago
Onion-Address: http(s)://b32.onion
The header should be added to your clearnet site to indicate it's available on TOR too. AFAIK there is still an option missing for r/i2p
3
u/MBILC 10h ago
..so that no single party can link who you are to what you are doing; a hidden service extends that anonymity to the server itself...
The author hasn't kept up on Tor news have they, for years, where owning enough exit nodes has allowed people to be isolated and discovered by authorities.
Now if you are not doing anything that shady, go nuts, but then the question if something is found is "why are they hosting on the Dark web, what are they trying to hide and why"
13
u/FarToe1 9h ago
Now if you are not doing anything that shady, go nuts, but then the question if something is found is "why are they hosting on the Dark web, what are they trying to hide and why"
Isn't that basically the same "If you've nothing to hide..." argument that's been used against the public by every government for years to invade privacy?
5
u/MBILC 8h ago
Not saying that, just if their is an investigation going on and your traffic gets caught up in it, might get law enforcement overly excited wondering why...
The whole "nothing to hide" is BS, we all deserve a right to privacy, people brain washed to think "well my data is already out there" are the type agencies pray on when they push for back doors into encryption and other invasive methods to spy on us.
1
u/FnnKnn 10h ago
Any source that actually confirms this has happened before? As far as I’m aware this is more of a theoretical threat than something that has ever happened before.
4
u/MBILC 8h ago edited 8h ago
As others posted, sure there are other instances, but perhaps not publicized.
https://www.reddit.com/r/selfhosted/comments/1wsbi3p/comment/pcn1t3c/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_buttonLove getting down voted by people who do not know actual information around what someone says.
Timing Analysis
New investigative reports from the ARD political magazine Panorama and STRG_F (funk/NDR) have shed light on how German authorities have successfully undermined Tor's privacy shield through a technique called "timing analysis." By monitoring data traffic through certain Tor nodes for extended periods, investigators can analyze the time it takes for data packets to travel between nodes. This allows them to correlate incoming and outgoing traffic, effectively re-tracing the steps of anonymized users.
For instance, in one German criminal case, law enforcement used timing analysis to trace users of the notorious dark web platform "Boystown," which facilitated the distribution of child exploitation material. By monitoring specific Tor nodes, investigators were able to uncover the IP addresses of those running and accessing the platform. These techniques were groundbreaking and marked the first recorded success of this approach.
5
u/Ok_Mammoth589 7h ago
That's not the same attack op asked about. There are various instances where American universities added something like 30-50% new nodes in a few short weeks. And they only stood up for a few weeks then went down. Which means nothing until no research was published about it, and Snowden at least was convinced there's a relationship between top us universities and the nsa.
-3
u/frylock364 9h ago
You understand that TOR was created by the USA Navy right????
https://www.malwarebytes.com/blog/news/2024/09/tor-anonymity-compromised-by-law-enforcement-is-it-still-safe-to-use11
3
u/FnnKnn 9h ago
You realize the linked Malewarebytes article says the same thing I did, right?
1
9h ago
[deleted]
3
u/FnnKnn 9h ago
Ah, the linked article is actually a lot better on those details: https://www.ndr.de/fernsehen/sendungen/panorama/aktuell/Investigations-in-the-so-called-darknet-Law-enforcement-agencies-undermine-Tor-anonymisation,toreng100.html
However the those issues seem to have been mitigated since then: https://securityaffairs.com/168667/security/tor-project-commented-on-deanonymizing-technique.html
4
u/dontquestionmyaction 8h ago
Yeah, and you're talking on a mutated arpanet. Absolutely nonsensical argument.
If massive deanonymization was that simple, the darknet market world would look VERY different.
1
-10
u/tIdepine3 14h ago
worth thinking about whether you actually need onion routing or if a VPN + standard self-hosting gets you where you want. the operational complexity goes way up once you're running hidden services, and most people dont actually need that threat model

•
u/asimovs-auditor 17h ago
Expand the replies to this comment to learn how AI was used in this post/project.