Live data from Hacker News

Tor's Fall Harvest: The Next Generation of Onion Services

blog.torproject.org

1–10 of 86 posts

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#2
Being undiscoverable is a big help. For our ancillary services, we're taken to using Tor2Web to auth mode HS servers because some random domain is less likely to look interesting for people to poke at. Publishing a .onion, especially with some general-purpose software hosted on it screams that there is something of interest there.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#4
post #2

Being undiscoverable is a big help. For our ancillary services, we're taken to using Tor2Web to auth mode HS servers because some random domain is less likely to look interesting for people to poke at. Publishing a .onion, especially with some general-purpose software hosted on it screams that there is something of interest there.

Gotta be the change you want to see. None of my hidden service .onion sites are anything "of interest". They're just electronics and radio hobby stuff like the web has always had.

Put everything on Tor as a hidden service and eventually the stigma will go away.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#6
post #4
post #2

Being undiscoverable is a big help. For our ancillary services, we're taken to using Tor2Web to auth mode HS servers because some random domain is less likely to look interesting for people to poke at. Publishing a .onion, especially with some general-purpose software hosted on it screams that there is something of interest there.

Gotta be the change you want to see. None of my hidden service .onion sites are anything "of interest". They're just electronics and radio hobby stuff like the web has always had. Put everything on Tor as a hidden service and eventually the stigma will go away.

This is on the front page now right next to a story about how hostile and ad-ridden most commercial websites have become. Thank you for helping keep the original spirit of the web alive on onion space.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#8
I have mixed feelings about Tor. As a proxy to hide your IP address it makes perfect sense to me.

But what's the end result of hidden services?

I want to be anonymous sometimes but I can't think of a time when I want the host of a service I use to be anonymous.

In most situations their identity is actually important to me. I want to know the source of news, to trust that I'm sending a message to the right person, to trust that I'm not relying on a site run by some kid in her parents basement.

And I know that legitimate sites can get certs for onions these days (like facebook)... But doesn't that defeat the original purpose of running a hidden service if the purpose is to hide the owner?

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#9
post #8

I have mixed feelings about Tor. As a proxy to hide your IP address it makes perfect sense to me. But what's the end result of hidden services? I want to be anonymous sometimes but I can't think of a time when I want the host of a service I use to be anonymous. In most situations their identity is actually important to me. I want to know the source of news, to trust that I'm sending a message to the right person, to…

My company (details in profile) relies on Tor. We help people, but governments would like to shut us down. We actually will expose everything via a non .onion, then proxy it to our HS (SSL term done on the hidden service). We'll expose via .onion as well and get a cert. We are hoping with HS v3 the rules will relax. For now, Digicert told us they were not going to issue any more. Maybe if we push.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#10
post #8

I have mixed feelings about Tor. As a proxy to hide your IP address it makes perfect sense to me. But what's the end result of hidden services? I want to be anonymous sometimes but I can't think of a time when I want the host of a service I use to be anonymous. In most situations their identity is actually important to me. I want to know the source of news, to trust that I'm sending a message to the right person, to…

There is another purpose, because when you access a hidden service, you are not using an (unknown, untrustable) exit node – instead, your data remains entirely encrypted until it reaches the owner of the address.
Post reply on HN