Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

According to Tor Project, v2 onion services were "fundamentally insecure" [1]. It sucks that you lost your URL, but wasn't redirection an option?

Tor definitely has a commitment to people building communities using hidden services, but they also have a commitment to your community members' expectations of security, no?

1. https://support.torproject.org/onionservices/v2-deprecation/



You can't redirect clients that cannot even parse your domain name. I can't update the links in all the indices and search engines built the last decade. I can't change the links to my .onion site on other people's sites. No, most .onion domains just went away, poof, inaccessible and sit unvisited while the remaining tor v2 infrastructure goes unused because the tor project clients dropped support. There's more to a web than any single site. And that web of interconnected links was destroyed with no recourse.

As for fundementally insecure, yeah, in a few years maybe by spending $10k you could brute force a hash and take over a domain. So they killed it entirely to protect the people that need absolute privacy and security. They could've left v2 alongside v3 and let people choose but the tor project considers that too risky for their prized use case.

Those of us just using tor for owning our own domains were not important in comparison. That "not being important" will continue. Shadowy users are what tor cares about. Not open communities. Tor is great for pseudo-privacy. It is not great for people wanting to make normal sites on it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: