TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
David Álvarez Rosa reports that his website is now available as a Tor hidden service, using an onion address accessible through the Tor network. His setup runs the site on a local web server and deploys a separate static build for Tor visitors. The report describes one site’s configuration; it does not establish broader adoption or independently assess the service’s security.
David Álvarez Rosa says his website is now reachable as a Tor onion service, giving visitors a way to access it inside the Tor network without using its public-web address. The report describes a self-hosted arrangement that forwards Tor traffic to a local web server and builds a separate copy of the site for the onion address.
In his report, Álvarez Rosa says the service uses a .onion address that resolves within Tor. He describes the address as derived from a public key, with Tor providing end-to-end encryption for the connection. The report says the site’s server address is not exposed through the service in the same way as a conventional public-web server. These are descriptions of the design; the article does not provide an independent security audit.
The configuration sends requests for port 80 on the onion service to 127.0.0.1:8080, where an Nginx server block serves the site files. Tor’s service keys and hostname file are stored in a dedicated directory owned by the Tor service account. Álvarez Rosa cautions that this directory must not be the website’s document root.
The site is built twice: once for its public-web address and once with the onion address as its base URL. According to the report, the deployment pipeline publishes the two builds to separate web roots after each push, keeping both copies in sync. The source provides an example onion address and configuration, but does not state how many visitors the service receives.
A Second Route to the Site
Making a website available as a Tor service gives readers who use Tor a direct route to it within that network. Tor’s hidden-service design aims to conceal both the visitor’s network location and the service’s location from outside observers, according to the Tor Project’s stated purpose as described in Álvarez Rosa’s report. That can matter to readers seeking privacy or access where ordinary connections are monitored or restricted.
The report also shows that a site can keep its existing public-web presence while adding an onion version. For a static site, this requires attention to absolute links: a build that embeds the public domain could send Tor visitors outside the network. The separate build addresses that practical issue, though the report offers no measurement of privacy outcomes or evidence that the setup prevents every form of tracking.
How the Onion Copy Is Served
A Tor onion service is accessed using Tor software, typically the Tor Browser, rather than ordinary public DNS. In the setup described by Álvarez Rosa, Tor handles the onion-facing connection and forwards traffic to a web server listening locally. The Nginx service therefore does not need to listen on a public interface for this route.
Álvarez Rosa identifies the Tor Project as the nonprofit organization behind the software and network. His article is a practical account of adding Tor access to an existing site, rather than a report of a new Tor feature or a change to the network itself. It points readers to his server setup, homelab repository and site deployment workflow for further implementation details.
“That’s it. Read this site over Tor at dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion.”
— David Álvarez Rosa
Security and Reach Remain Unmeasured
The report does not say when the onion service went live, how many people use it, or whether it has undergone an external security review. It also does not provide uptime figures or discuss how the server is protected against compromise. Tor can conceal network relationships under its design, but the article does not claim that hosting a site this way eliminates all risks, such as vulnerabilities in the server or identifying details in published content.
Both Site Builds Will Be Maintained
Álvarez Rosa says his deployment workflow builds and publishes the public-web and Tor versions on each push. The immediate next step described by the report is continued maintenance through that automated process. No further launch, feature change or usage milestone is announced.
Key Questions
What is the news development?
David Álvarez Rosa reports that his website is now available through a Tor onion service, alongside its public-web version.
How do visitors access the onion version?
They need to use the Tor network, for example through Tor Browser, and enter the onion address provided in the report. The address is not meant to resolve through ordinary public DNS.
Does the setup replace the public website?
No. The report describes separate builds and web roots for the public-web and Tor versions, with the deployment pipeline publishing both.
Does the report prove the service is fully secure?
No. It describes the configuration and Tor’s intended privacy properties, but reports no independent security audit, uptime data or assessment of the server’s broader risks.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
