This site is now reachable over Tor as a hidden service, at a .onion address that resolves only inside the Tor network. Tor relays and encrypts your traffic as …

355 points•mooreds•3 days ago•117 comments•

117 comments

ivanmontillam3 days ago
What I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:

- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).

- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).

- Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.

- Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.

As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.

If you can ship your website to the browser in a single connection, you've won.

I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.

--

[0]: https://news.ycombinator.com/item?id=49872320

EDIT: Formatting of bullet points.

orbital-decay3 days ago
Also DDoS becomes a problem, and the ways it's done are pretty specific to Tor. Double captchas are necessary when you're getting DDoSed, due to performance reasons. Oh, and captchas are also pretty specific to Tor as well.

There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).

>avoid JS for them

Using any JS defies the point and makes your site instantly suspicious.

Lucasoato3 days ago
> There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).

How can you do this without relying on the normal web? Let’s say you use a normal website to show the onion link, if the website gets taken down, you lost your user-trusted mean to do that.

phrotoma3 days ago
I've done some searching and can't find a description of "site fronting" that fits with my read of your comment.

I thought the whole point of Tor is that I (and only I) am able to serve traffic at a .onion URL that I have generated. How could someone else get in front of that?

dalvrosa3 days ago
How are captchas done?
boredatoms3 days ago
Are these simply good ideas regardless of tor?
nephanth3 days ago
Depends on which ones. Embedding assets as base64 makes little sense nowadays with http pipelining.

Relyinging the least possible on js, and using CSS for animations sounds like good engineering to me

Gigachad3 days ago
Not really. The latency between a client and clearnet sites is tiny, and splitting assets in to separate resources makes caching work better.
ivanmontillam3 days ago
With CDNs of today, they are not so much relevant for the clearnet.
geraldhh3 days ago
Yes, but
DANmode3 days ago
Until you got to the network traffic tricks, those were good practices for any landing page you want to open quickly!
RobotToaster3 days ago
Apart from the 1st one these just seem like good practices in general
p4bl03 days ago
My personal website has been hosted on Tor for years. It's easy to do from your home even behind a NAT because it's an outgoing connection from your point of view (which also makes it a great way to expose local services even when you are behind a NAT and don't not have a static IP), and by design your personal IP is hidden from your visitors.

I wrote about it in 2600 almost ten years ago (already?!). A copy of my article can be found here: https://pablorauzy.fr/outreach/2600/how-to-run-a-tor-hidden-...

If you have an Onion copy of your website, don't forget the Onion-Location http header which will automatically redirect Tor Browser users to the onion version of the website even if they visit it at the clear web address.

If it interests people, I also have a follow up article about I2P: https://pablorauzy.fr/outreach/2600/how-to-run-an-i2p-hidden...

jortizzz3 days ago
I had never heard of the Onion-Location header, thanks!
1vuio0pswjnm72 days ago
onion-location:

http://pablo2httpff4vogufavlmbxw4jkgb3amnywex2xdnchpztkdu2lu...

And for the OP's site

onion-location:

http://dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omx...

Question: Can the .onion sites withstand HN front page traffic

p4bl02 days ago
A link in a comment is not the same as a front page link it terms of traffic, and when this link is a .onion, you probably divide at least by a few hundreds if not thousands the number of people who will click on it (even the few percents who have Tor Browser installed probably visit HN using their regular browser so visiting the link requires to open a new browser — or to change your proxy settings of you use Tor the old school way).

I really believe the single threaded BusyBox httpd running on a low end mini PC in my bedroom will stand hosting my static web site without any trouble.

1vuio0pswjnm71 day ago
To rephrase the question, if a story with an .onion link appeared on the HN front page, could it withstand the traffic from HN users who understand how to access .onion sites

NB. The question poses a hypothetical. No one is suggesting that HN allows stories (submissions) with .onion URLs or that .onion URLs would receive the same amount of traffic as "clearnet" ones

For example, a NYT article using an .onion URL rather than a "clearnet" URL

basilikum3 days ago
You probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it: https://community.torproject.org/onion-services/advanced/oni...
dalvrosa3 days ago
Good call, I'd missed that. Adding it now, thanks.
francodosha3 days ago
Good thought
mzajc3 days ago
Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:

> HiddenServicePort 80 127.13.37.1:8080

> listen 127.13.37.1:8080;

This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.

You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.

someonebaggy3 days ago
It's also possible to use a Unix socket, which can have a descriptive pathname like /var/run/my-service.sock: https://stackoverflow.com/questions/69313114/using-nginx-to-...
jeroenhd3 days ago
Every time I've tried using Unix sockets, I've run into the problem as described in your stackoverflow link. The suggested solution ("just run tor as root") is not exactly best practice.

You can monkey-patch scripts around Tor service activation, but I haven't been able to get my Tor+nginx setup to work reliably after updates/service restarts when using unix sockets.

m00dy3 days ago
using unix socket rather than tcp has advantages
charcircuit3 days ago
A few more tips.

1. If you want to improve page load speed you need to buy a HTTPS certificate so you are not limited to HTTP/1.1. Multiplexing in HTTP/2 is important for getting sites to load fast.

2. You can set the HiddenServiceExportCircuitID configuration to pass the circuit id to your web server for telemetry or anti abuse purposes. Otherwise your logs will say that all users are coming from the same IP.

https://blog.cloudflare.com/cloudflare-onion-service

markasoftware3 days ago
Fascinating, onion services are always encrypted by the tor network but still tunnel "cleartext" http inside that, and there are no CAs that issue free of charge certificates for .onion domains, and therefore there's no free of charge way to get http/2 on onion services without self signing.

Which raises the question: why not just trust self-signed certificates on onion services? From my brief look it seems to be because the Tor project views the primary purposes of HTTPS on onion services to be other things rather than just http/2 support: http/2 isn't even mentioned on their page about https for onion services (https://community.torproject.org/onion-services/advanced/htt...). Unfortunate.

someonebaggy3 days ago
Negotiating HTTP 2 requires an extra round trip btw. It gets absorbed into the several round trips required for TLS.
charcircuit3 days ago
I personally would support automatically trusting self signed https certs since their key is typically secured under the same safety as the hidden service's key. And even when they are not the browser has no warning when you get downgraded to HTTP on an onion compared to a regular site.

Trying to push hidden services to stay on HTTP is going against what the rest of the web is doing and as a minority of web traffic it really should be aligned to the rest of the web and also require HTTPS. Yes, it's technically wasteful, but reduces both work and security risk by keeping security models aligned with the rest of the web.

Cider99863 days ago
Can you buy one of these in XMR?
charcircuit3 days ago
Not directly.

Read the full thread on Hacker News →

Related stories