AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

David Álvarez Rosa reports that his website is now available as a Tor hidden service, using a .onion address and a web server reachable only through a local port. His deployment workflow builds and publishes separate copies for the regular web and Tor; the report does not establish broader adoption or independently verify the service’s security.

David Álvarez Rosa says his website is now available through a Tor hidden service, giving it a .onion address that resolves inside the Tor network. In a technical report, he describes routing Tor traffic to a locally hosted web server and maintaining a separate site build for onion visitors, a setup that lets readers reach the site without using its regular web address.

Álvarez Rosa’s setup uses Tor’s hidden-service configuration to forward traffic for the site’s onion address to 127.0.0.1:8080, a local port where nginx serves the files. The configuration assigns Tor a dedicated directory to store the service’s private key and generated hostname. He says the directory must be owned by Tor and kept separate from the website’s document root.

For the web server, the report gives an nginx configuration that listens on the loopback address and serves the site files from a separate directory. It uses plain HTTP between Tor and the local server; Álvarez Rosa says TLS, HTTP/2 and QUIC are not used in this arrangement because Tor handles encryption for the connection. The report does not provide an independent security audit of the deployment.

The site is static and uses a generated base URL for its links. To keep pages and links on the onion site pointed to the onion address, the deployment process builds a second copy with that address as its base URL. Álvarez Rosa says the pipeline builds once for the regular web and once for Tor, then deploys the versions to separate web roots. He supplies an example onion address in the report.

At a glance
reportWhen: Published date not specified in the sup…
The developmentDavid Álvarez Rosa published a technical report describing how he made his self-hosted static website reachable through a Tor hidden service.

A Separate Route to the Site

The setup illustrates how a self-hosted website can be reached through Tor without publishing the server’s regular IP address through the onion service. Tor’s design routes traffic through relays and provides encryption between a user and a hidden service. The report says the onion address is derived from a public key and does not rely on conventional DNS or a certificate authority.

For readers, the practical result is an alternate route to one site. It may be useful where access to ordinary web addresses is monitored or restricted, or where visitors and operators want to limit the information exposed about their connection. Those are features of the Tor design; the report does not measure how much privacy this particular deployment provides or claim that the website is immune to tracking through other means.

Operating both versions also adds a maintenance requirement: links and generated pages must be built for the address visitors are using. Álvarez Rosa’s automated build addresses that issue for his static site. The account offers a concrete example of the configuration, but does not show that the same steps suit every server, hosting provider or web application.

How the Onion Version Works

Tor, developed by the nonprofit Tor Project, is a network that routes traffic through volunteer-run relays. A hidden service, also called an onion service, makes a server reachable within that network. The source report describes the distinction as extending anonymity to the server as well as the visitor. That is a description of the system’s intended function, not evidence that every deployment or user is anonymous in all circumstances.

In Álvarez Rosa’s account, the Tor service handles the onion address and forwards requests to nginx on the same machine. Nginx then serves static files from a dedicated site directory. Keeping the Tor service’s key files separate from the web root helps preserve the separation between Tor’s service configuration and the content being served.

The reported workflow ties the two versions together. A push to the site’s repository triggers builds for both the standard web address and the onion address, followed by deployment to separate directories. The report points readers to a homelab repository and the site’s deployment workflow for configuration details, but the supplied material does not include an independent review of those files.

“This site is now reachable over Tor as a hidden service, at a .onion address that resolves only inside the Tor network.”

— David Álvarez Rosa, in the report

Limits of the Published Account

The supplied report describes one operator’s implementation. It does not include an independent test of whether the service is reachable now, a security audit, or measurements of visitor privacy. It is also unclear from the material when the report was published and whether the configuration has changed since then.

The article does not state how the server is protected against compromise, how backups and key recovery are handled, or whether the regular web version reveals information that could connect it to the onion service. Tor can obscure network paths, but the report does not establish that the site operator or users cannot be identified through other technical or operational details.

No audience figures, uptime records or evidence of use in response to censorship or surveillance are provided. The described onion address and workflow are attributed to Álvarez Rosa’s account, and the available material does not confirm broader uptake of this approach.

Keeping Both Copies Current

Álvarez Rosa says the deployment pipeline builds and publishes both versions whenever the site repository receives a push. For readers, the next step described is to open the onion address in Tor Browser; the regular version remains served through its usual web address.

The source provides no announced follow-up date or planned technical milestone. Whether the onion service remains available, how it will be maintained, and whether the operator will publish later changes or security information are not specified.

Key Questions

What happened?

David Álvarez Rosa reported that his self-hosted website is reachable through a Tor hidden service with a .onion address.

How does the site reach its web server?

According to the report, Tor forwards requests to nginx listening on a local address and port, 127.0.0.1:8080.

Why does the site need a separate build?

The static-site build places its base URL in links. Álvarez Rosa says he builds a second copy using the onion address so its links continue to point to the Tor version.

Does the report prove the site is fully anonymous or secure?

No. The report describes the intended privacy properties of Tor and the operator’s configuration, but supplies no independent security audit or proof that users or the server cannot be identified through other means.

Source: hn

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Show HN: Codiff, a local diff review tool

Codiff, a new native desktop app for reviewing Git changes locally, has been released, offering fast, minimal diff viewing with inline comments and LLM walkthroughs.

Shai Hulud Surges In Global Coverage

Search interest and media coverage of Shai Hulud have increased sharply, with 14 mentions in recent reports, indicating a significant trend shift.

Parental Consent Management For Kid-facing Vendors

A proposed consent platform for camps and other youth vendors would track parent approvals, expirations and audit records. No pilot results are reported.