8 comments

  • basilikum1 hour ago
    You probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it: <a href="https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;onion-location&#x2F;" rel="nofollow">https:&#x2F;&#x2F;community.torproject.org&#x2F;onion-services&#x2F;advanced&#x2F;oni...</a>
    • dalvrosa1 hour ago
      Good call, I&#x27;d missed that. Adding it now, thanks.
      • dalvrosa1 hour ago
        Done now <a href="https:&#x2F;&#x2F;github.com&#x2F;david-alvarez-rosa&#x2F;homelab&#x2F;commit&#x2F;b495cbe795f07a2dfb75308658fc43869fc51c83" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;david-alvarez-rosa&#x2F;homelab&#x2F;commit&#x2F;b495cbe...</a>
  • mzajc25 minutes ago
    Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:<p>&gt; HiddenServicePort 80 127.13.37.1:8080<p>&gt; listen 127.13.37.1:8080;<p>This way, strangers won&#x27;t be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.<p>You&#x27;ll also need to use separate ports and&#x2F;or bind addresses if you host multiple hidden services and don&#x27;t want people to correlate them - if nginx doesn&#x27;t match the Host header, it will serve whichever site comes first alphabetically.
    • someonebaggy21 minutes ago
      It&#x27;s also possible to use a Unix socket, which can have a descriptive pathname like &#x2F;var&#x2F;run&#x2F;my-service.sock: <a href="https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;69313114&#x2F;using-nginx-to-host-tor-hidden-service-through-unix-socket" rel="nofollow">https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;69313114&#x2F;using-nginx-to-...</a>
  • dherls1 hour ago
    What is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?
    • dalvrosa1 hour ago
      Fair point. Very small things like RSS, canonical link or og:url or microformats use absolute URL<p>To make sure once in the .onion, you never leave the .onion
  • comrade12341 hour ago
    Besides accessing your page are random people able to use your server as an exit node? Am I thinking the right thing... I met someone in Switzerland that was hosting anonymous exit nodes to some anonymous network and he said that it was a pain having to explain what was happening to the police.
    • creatonez28 minutes ago
      Exit node are an entirely optional part of the Tor network. If you run a relay or a hidden service you are not forced to participate in the exit node side of things. It&#x27;s also not recommended to combine these roles because it could have security implications for your hidden service.
    • fishgoesblub1 hour ago
      Running a Tor exit node is a manual process. Running a hidden service like a website, or chat server doesn&#x27;t involve anything like that.
    • dalvrosa1 hour ago
      That&#x27;d be an exit relay, not doing that atm, just in case
    • basilikum1 hour ago
      No
  • dalvrosa2 hours ago
    Thanks for sharing! Happy to get feedback :)
  • 651042 minutes ago
    Imagine if normal people could install a single normal application and just run a website from a folder. CLI makes it more difficult than hosting a normal website. Typing commands you don&#x27;t understand doesn&#x27;t seem all that of a great idea.
  • hn9zmdcaou2 hours ago
    Nice thing is you skip port forwarding entirely, which matters a lot if your ISP has you behind CGNAT. Curious how people handle uptime though, since a hidden service going down isn&#x27;t something you notice until someone tells you.
    • dalvrosa53 minutes ago
      Agreed yeah. Mine has been up with no issues so far for ~half a year.<p>(There are solutions for CGNAT - <a href="https:&#x2F;&#x2F;david.alvarezrosa.com&#x2F;posts&#x2F;self-hosting-behind-cgnat&#x2F;" rel="nofollow">https:&#x2F;&#x2F;david.alvarezrosa.com&#x2F;posts&#x2F;self-hosting-behind-cgna...</a>)
  • hndhyc0bdt2 hours ago
    Ran a small onion site for a couple years and the nice part is you never touch a public IP or a cert. Downside is onion v3 addresses are impossible to share verbally and the latency makes anything chatty feel broken. Static pages only, honestly.
    • someonebaggy19 minutes ago
      You have to keep chattiness low, but a lot of SSR stuff works fine. Dread uses SSR, and even nags you if you gave JavaScript enabled.