Comment by phrotoma
11 hours ago
I've done some searching and can't find a description of "site fronting" that fits with my read of your comment.
I thought the whole point of Tor is that I (and only I) am able to serve traffic at a .onion URL that I have generated. How could someone else get in front of that?
The attacker simply proxies your site on another .onion address and advertises that fake address in a popular directory or an ad. Any visitors coming through that fake URL interact with your site through the attacker's front. Since .onion URLs aren't easy to tell apart, this kind of phishing works well. If you run a discovery bot you can observe that the .onion zone is full of these fake fronts for all kinds of sites, because even if your site aren't of any interest to an attacker but you link to any other site, then the attacker of that site needs to front yours with that link replaced with a fake, to create a separate circle of trust for the victims.
That's why you need to very carefully choose a trusted entry point into the Torosphere and revise your choice from time to time; always remember your initial entry point because if there's any suspicious drama around it or if you notice a mismatching link on different sites, you might have been duped to enter an impersonator-controlled bubble.
Many things can be done about it: claiming your spot in the directories, smoke test captchas, chains of trust, or you can brute force your .onion to find a valid one that starts with a memorable string (the longer the better, but also the harder). Vanity addresses like this deter non-targeted adversaries by requiring proof of work to forge the lookalike URL. None of that is bulletproof, of course.