Developer self-hosts personal blog as a Tor hidden service
David Alvarez Rosa details a build pipeline that publishes his static site simultaneously to the clearnet and to a .onion address.
What to know
- A developer documented configuring his personal static site as a Tor hidden service, reachable via a .onion address with no CA, DNS, or exposed IP.
- A CI/CD pipeline builds and deploys two versions of the site on every push—one for the clearnet and one with the onion address baked in as the base URL—to keep both in sync.
- The post drew attention on Hacker News (103 points, 34 comments) and was reposted across Mastodon, though no substantive public discussion text was captured in this coverage.
David Alvarez Rosa Blog author and site operatorTor Project Nonprofit developer of the Tor networkmooreds Hacker News submitter
How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts
-
3
Second Mastodon repost circulates the same link
Account hn100@social.lansky.name reposted the article and HN discussion link roughly nine hours after the first Mastodon share, indicating continued cross-platform circulation.
-
The so-called "clearnet" www has suffered from "developers" hell bent on "scraping" and crawling to support their so-called "tech" companies. The situation has gotten worse with "AI" companies scraping and crawling for LLM "training data"These companies also attempt to create "walled gardens" to enable behavioral surveillance and ad targeting on…
2 more of the top 3 · 15 posts in this stretch
-
H
Self-Hosting on the Dark Web Link: https:// david.alvarezrosa.com/posts/se lf-hosting-on-the-dark-web/ Discussion: https:// news.ycombinator.com/item?id=4 9870295
-
My personal website has been hosted on Tor for years. It's easy to do from your home even behind a NAT because it's an outgoing connection from your point of view (which also makes it a great way to expose local services even when you are behind a NAT and don't not have a static IP), and by design your personal IP is hidden from your visitors.I…
-
-
2
Mastodon user hkrn reposts the link with the HN discussion thread
hkrn@mstdn.social shared the article link along with the Hacker News comments URL, extending the post's reach onto the fediverse.
-
What I really love about Onion sites is that if they are big enough, performance engineering really becomes Tor-specific. A few examples:- Making assets embedded as base64 (img src the header logo as base64, all CSS should be inline, etc.).- Leveraging CSS as much as possible (if you use animations and transitions, use CSS as much as possible for…
2 more of the top 3 · 6 posts in this stretch
-
H
Self-Hosting on the Dark Web L: https:// david.alvarezrosa.com/posts/se lf-hosting-on-the-dark-web/ C: https:// news.ycombinator.com/item?id=4 9870295 posted on 2026.09.27 at 16:03:36 (c=0, p=3)
-
Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:> HiddenServicePort 80 127.13.37.1:8080> listen 127.13.37.1:8080;This way, strangers won't be able to connect to a service bound to…
-
-
1
Post reaches Hacker News front page via mooreds submission
User mooreds submitted the post to Hacker News, where it drew a score of 103 and 34 comments, and was separately picked up by the HN Frontpage RSS feed.
“There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself.”
— David Alvarez Rosa, blog author · source -
background
Alvarez Rosa publishes guide to self-hosting on Tor — The author details configuring a Tor hidden service for his static site, including a Tor-owned onion service directory, an nginx block listening on 127.0.0.1:8080, and a dual-build pipeline that generates separate clearnet and onion-base-URL versions of the site on every push.
Also covered reported alongside — the timeline has no entry for these yet
-
2 outlets Self-Hosting on the Dark Web
first by HN Best, 1d ago · also HN Frontpage
What people are saying 13 voices from 2 sites · best of 21 · verbatim
- Yesterday
-
A bit late to the party but check out https://github.com/brewsterkahle/onionpress/ - it's an effort to make self-hosting on Tor hidden services as easy as possible.
-
onion-location:http://pablo2httpff4vogufavlmbxw4jkgb3amnywex2xdnchpztkdu2lu...And for the OP's siteonion-location:http://dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omx...Question: Can the .onion sites withstand HN front page traffic
-
I thought about doing this back when I was self-hosting my blog, purely because I thought there would be a neatness factor to being able to honestly say "I have a site on the dark web".I eventually moved the blog to Cloudflare Pages primarily because I wanted to use Cloudflare Workers to handle the comments, though I have still considered…
-
In a guide like this, it might be helpful to emphasize backing up the generated private key, loss of which would cause you to have to change your onion address.
-
N
Self-Hosting on the Dark Web: https:// david.alvarezrosa.com/posts/se lf-hosting-on-the-dark-web/ Discussion: http:// news.ycombinator.com/item?id=4 9870295
-
Adds a whole new layer of paranoia, but for some things, it's probably the only way to genuinely stay off the grid.
-
I recommend that people give I2P and Yggdrasil a try as well, especially Yggdrasil. It makes no compromises on speed and latency, but it has no anonymity.
-
absolutely love how OP's site is designed. It's clean and minimal, fast and user-friendly, but also stylish.
-
> so that no single party can link who you are to what you are doingsome single parties called government agencies pretty much can. it’s just much harder to do, so you’re safe from random people
-
Also DDoS becomes a problem, and the ways it's done are pretty specific to Tor. Double captchas are necessary when you're getting DDoSed, due to performance reasons. Oh, and captchas are also pretty specific to Tor as well.There's also a problem of site fronting. Anyone could run a proxy pretending to be you, for arbitrary reasons (not even…
- Sep 27
-
You probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it:
-
Besides accessing your page are random people able to use your server as an exit node? Am I thinking the right thing... I met someone in Switzerland that was hosting anonymous exit nodes to some anonymous network and he said that it was a pain having to explain what was happening to the police.
-
What is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?