‹ BackHN Continuity

Thread

Self-Hosting on the Dark Web

358 points · 118 comments · mooreds

  1. charcircuit · · focus · HN ↗
    A few more tips.

    1. If you want to improve page load speed you need to buy a HTTPS certificate so you are not limited to HTTP/1.1. Multiplexing in HTTP/2 is important for getting sites to load fast.

    2. You can set the HiddenServiceExportCircuitID configuration to pass the circuit id to your web server for telemetry or anti abuse purposes. Otherwise your logs will say that all users are coming from the same IP.

    <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cloudflare-onion-service" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cloudflare-onion-service

    1. markasoftware · · focus · HN ↗
      Fascinating, onion services are always encrypted by the tor network but still tunnel &quot;cleartext&quot; http inside that, and there are no CAs that issue free of charge certificates for .onion domains, and therefore there&#x27;s no free of charge way to get http&#x2F;2 on onion services without self signing.

      Which raises the question: why not just trust self-signed certificates on onion services? From my brief look it seems to be because the Tor project views the primary purposes of HTTPS on onion services to be other things rather than just http&#x2F;2 support: http&#x2F;2 isn&#x27;t even mentioned on their page about https for onion services (<a href="https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;https&#x2F;" rel="nofollow">https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;htt...). Unfortunate.

      1. someonebaggy · · focus · HN ↗
        Negotiating HTTP 2 requires an extra round trip btw. It gets absorbed into the several round trips required for TLS.
        1. charcircuit · · focus · HN ↗
          Despite that my benchmark was faster with HTTP 2.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.