HeadlinesBriefing favicon HeadlinesBriefing.com

Self-Hosting Hidden Services Onion Tor

Hacker News •
×

This site is now reachable over Tor as a hidden service, at a .onion address that resolves only inside the Tor network. Open it in the Tor Browser. There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself.

Tor relays and encrypts your traffic as it passes through thousands of volunteer-run servers, so that no single party can link who you are to what you are doing; a hidden service extends that anonymity to the server itself. It is built by the nonprofit Tor Project, which advances human rights and freedoms through free software and open networks, so that anyone can use the internet free from tracking, surveillance, and censorship. The network only works because people use it, so consider supporting them or running a relay—your contribution helps millions stay safe and private online every day.

Install Tor and point a hidden service at a local port. Edit /etc/tor/torrc Hidden Service Dir /var/lib/tor/blog/ Hidden Service Port 80 127.0.0.1:8080. The directory must be a dedicated, Tor-owned path—not your webroot.

Tor stores the service’s private key and hostname file here and insists on owning it (chmod 700, user debian-tor). Point it at site files and Tor refuses to start. Restart Tor and read the address it generates.

Serving the site, Tor forwards the onion’s port 80 to 127.0.0.1:8080, so the web server just needs to listen there. Add an nginx server block for it—no TLS, no HTTP/2, no QUIC, since Tor speaks plain TCP and provides its own encryption.