‹ BackHN Continuity

Thread

Self-Hosting on the Dark Web

358 points · 118 comments · mooreds

  1. ivanmontillam · · focus · HN ↗
    What I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:

    - Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).

    - Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for these, avoid JS for them).

    - Make sure your website is mostly rendered on the backend. If you're to have JS, your website should work without it.

    - Security becomes REALLY fun, as in, avoid XSS, CSRF, SQL Injection attacks and any other injections as much as possible.

    As someone summarizes in another comment[0], keep the chattiness as minimal as possible. By chattiness I understand they mean, pack as much data as you can in the same Keep-Alive connection. Avoid making new HTTP requests as much as possible, as each one might get assigned to a new Onion route making things slow.

    If you can ship your website to the browser in a single connection, you've won.

    I've always been impressed by performance of these big Onion sites, they really push the limits of software engineering creativity, given these constraints and nature of Tor.

    --

    [0]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49872320">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49872320

    EDIT: Formatting of bullet points.

    1. orbital-decay · · focus · HN ↗
      Also DDoS becomes a problem, and the ways it&#x27;s done are pretty specific to Tor. Double captchas are necessary when you&#x27;re getting DDoSed, due to performance reasons. Oh, and captchas are also pretty specific to Tor as well.

      There&#x27;s also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).

      &gt;avoid JS for them

      Using any JS defies the point and makes your site instantly suspicious.

      1. Lucasoato · · focus · HN ↗
        &gt; There&#x27;s also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).

        How can you do this without relying on the normal web? Let’s say you use a normal website to show the onion link, if the website gets taken down, you lost your user-trusted mean to do that.

        1. someonebaggy · · focus · HN ↗
          Your users should have bookmarked it
          1. Lucasoato · · focus · HN ↗
            What about new users?
            1. someonebaggy · · focus · HN ↗
              How did they learn about the site? There&#x27;s nothing you can do to stop your competitor advertising their own identical site in the same way you did - a malicious proxy is just a special case of this principle.
              1. Lucasoato · · focus · HN ↗
                I’m thinking about blockchain provided onion URLs, but maybe I’m fantasizing a bit too much.
                1. orbital-decay · · focus · HN ↗
                  It&#x27;s not an easy problem due to mutually exclusive constraints, look at Yggdrasil and adjacent decentralized DNS tech as an example of thinking in that direction.
                  1. someonebaggy · · focus · HN ↗
                    Yggdrasil doesn&#x27;t have a name system. It often uses internet DNS.
                    1. orbital-decay · · focus · HN ↗
                      &quot;Adjacent&quot; projects, for example Wyrd and its successor Alfis by the same dev:

                      <a href="https:&#x2F;&#x2F;github.com&#x2F;Revertron&#x2F;wyrd" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Revertron&#x2F;wyrd

                      <a href="https:&#x2F;&#x2F;github.com&#x2F;Revertron&#x2F;Alfis" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Revertron&#x2F;Alfis

                2. someonebaggy · · focus · HN ↗
                  Zooko&#x27;s Triangle
        2. orbital-decay · · focus · HN ↗
          &gt;How can you do this without relying on the normal web?

          How can you trust anything you haven&#x27;t experienced personally? By using chains of trust, of course. There are directories that list onion sites, and also sites that link to their peers. That way you can be sure you&#x27;re still in the same bubble at least, and convert the problem into trusting the entire bubble. It&#x27;s not automated and pretty ad hoc, if that&#x27;s what you&#x27;re wondering. Automation in Tor has a history of being circumvented or exploited with novel scams, this is an adversarial environment.

        3. m-p-3 · · focus · HN ↗
          If the website is available on both clearnet and Tor, add a `Onion-Location` header.

          <a href="https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;onion-location&#x2F;" rel="nofollow">https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;oni...

          This way you advertise the onion domain through an established chain of trust and visitors can decide to use that the next time.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.