‹ BackHN Continuity

Thread

Self-Hosting on the Dark Web

358 points · 118 comments · mooreds

  1. mzajc · · focus · HN ↗
    Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:

    > HiddenServicePort 80 127.13.37.1:8080

    > listen 127.13.37.1:8080;

    This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.

    You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.

    1. someonebaggy · · focus · HN ↗
      It&#x27;s also possible to use a Unix socket, which can have a descriptive pathname like &#x2F;var&#x2F;run&#x2F;my-service.sock: <a href="https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;69313114&#x2F;using-nginx-to-host-tor-hidden-service-through-unix-socket" rel="nofollow">https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;69313114&#x2F;using-nginx-to-...
      1. m00dy · · focus · HN ↗
        using unix socket rather than tcp has advantages
        1. BonerWiener · · focus · HN ↗
          Can you elaborate?
          1. Tepix · · focus · HN ↗
            For starters, it’s twice as fast
            1. someonebaggy · · focus · HN ↗
              AFAIK TCP outperforms Unix sockets for some odd reason, but it&#x27;s irrelevant anyway because you aren&#x27;t getting that much bandwidth through Tor.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.