Comment by Lucasoato
14 hours ago
> There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even necessarily the obvious forging and credential stealing). Every site, even a personal blog, has dozens of parasitic fronts, either actively malicious or dormant. You need off-site ways to tell users what is the real address, and provide a smoke test for them (often a part of the address as a picture, for example in a captcha).
How can you do this without relying on the normal web? Let’s say you use a normal website to show the onion link, if the website gets taken down, you lost your user-trusted mean to do that.
If the website is available on both clearnet and Tor, add a `Onion-Location` header.
https://community.torproject.org/onion-services/advanced/oni...
This way you advertise the onion domain through an established chain of trust and visitors can decide to use that the next time.
>How can you do this without relying on the normal web?
How can you trust anything you haven't experienced personally? By using chains of trust, of course. There are directories that list onion sites, and also sites that link to their peers. That way you can be sure you're still in the same bubble at least, and convert the problem into trusting the entire bubble. It's not automated and pretty ad hoc, if that's what you're wondering. Automation in Tor has a history of being circumvented or exploited with novel scams, this is an adversarial environment.
Your users should have bookmarked it
What about new users?
How did they learn about the site? There's nothing you can do to stop your competitor advertising their own identical site in the same way you did - a malicious proxy is just a special case of this principle.
3 replies →