7 ms·
Dark.fail: Is a darknet site online?
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- buildbuildbuild 7y agoTor admins and cyber researchers rely heavily on this site to disseminate links in the wake of DeepDotWeb’s takedown. DDoS attackers seem to love it too as some sites change their .onion URLs ~hourly. Interesting how all sides of a battle can find a simple verified link so useful.
- aaron695 7y ago> some sites change their .onion URLs ~hourly. Not sure why you would do this? Do you have an example?
- mysterydip 7y agoIf DDoS traffic is aimed at domain1.onion, changing your site to donain2.onion would avoid that, wouldn't it?
- luckylion 7y agoYeah, and nobody would know about the new URL, effectively having the same result as a successful DDoS. On the other hand, notifying your users of the URL change will also notify the attackers. I've seen the response to DDoS mostly be a multiple public URLs, but it seems the results varied greatly, and since these operations are typically very secretive, they won't publish a lot of information (is the ddos still active but they are mitigating it? has the ddos stopped because they mitigated it? have they paid the attackers? etc).
- Liquix 7y agoAddresses are changed when the DDoS takes one down. This mean's the attacker's (usually automated) resources are wasted on a domain no one will ever visit again, while users will just visit dark.fail and get a new link 15 seconds after the site goes down. At the beginning of the DNM large-scale DDoS attacks (Empire in particular), there was panic, confusion, and a whole lot of phishing. As another commenter noted, Empire users have now been trained (or learned the hard way) to visit dark.fail, copy/paste a mirror .onion address they've never seen before, verify it as legitimate through the various captchas/pgp/safeguards on the Empire login page, and then enter their username/password. Sure, it's frustrating and complex the first time - a heck of a departure from cookies and 'sign in with google' buttons. But after five or ten times, it's just the way you log in to the website, and it takes an extra 60 seconds tops. Not saying this is the only/best solution to a dedicated onion DDoS - just sharing that it's been working for Empire.
- theamk 7y agoIs there a reason automated DDOS bots cannot visit dark.fail as well, to automatically attack all the mirrors too? Seems like an obvious next step.
- steveeq1 7y agoDoes anyone know if there's any progress on finding a solution to the DDOS attacks that can run on tor?
- Liquix 7y agoThe v3 onion protocol [0] is supposed to provide better DDoS resistance than v2 [1] - haven't read up on the specifics though. [0] https://www.jamieweb.net/blog/onionv3-hidden-service/ https://www.jamieweb.net/blog/onionv3-hidden-service/ [1] https://darknetlive.com/post/cryptonia-market-countering-ddos-with-new-v3-onions/ https://darknetlive.com/post/cryptonia-market-countering-ddo...
- Forbo 7y agoThey're making progress on it: https://github.com/torproject/tor/pull/1262 https://github.com/torproject/tor/pull/1262
- privdev 7y agoLost 100$ to phishing site back in the day when testing blockchain analysis on my AlphaBay deposits, I deposited into a phisher's wallet and ended up watching that on the blockchain instead with no withdraw ability. I should have PGP verified link. This DarkDotFail guy is honest for now but time will tell. Tor is wild west with PGP the only way to really know anyone is who they claim.
- jamil7 7y agoI don't disagree but isn't this always the case with PGP?
- Leace 7y ago> Accurate URLs verified by PGP. What does it mean? I'm not seeing any PGP clearsigned text in there...
- yessenia1 7y agoHe verifies before adding & has good track record doing so honestly, but yeah it would be better if he posted all of them openly. Most .onion sites host their public key at /pgp.txt, some host mirrors at /mirrors.txt . Empire Market for example has a /safe URL which signs the current URL to prove it is official. Most users don't do it though and trust this site to do it for them instead :/
- cosarara 7y agoSounds like something a plugin for the Tor browser could easily do.
- cyborgx7 7y agoThis has probably already been proposed, but I'm going to do it as a joke anyway. DNS for .onion domains when?
- flotzam 7y agohttps://gitweb.torproject.org/torspec.git/tree/proposals/279-naming-layer-api.txt https://gitweb.torproject.org/torspec.git/tree/proposals/279...
- Sargos 7y agoENS now supports .onion resolution. https://medium.com/the-ethereum-name-service/ens-now-supports-tor-onion-address-resolution-9bb3bdff6217 https://medium.com/the-ethereum-name-service/ens-now-support...
- Drebeat 7y agoI dunno know yet. Would someone enlighten me on this?
- dingdingdanggg 7y agoIs an illegal* site online? If I built this service I’d just log all the IPs from the requests and just hand them to the FBI.
- lacker 7y agoThe BBC just announced the launch of their Tor site. Clearly Tor sites and illegal sites are not equivalent. Unless, perhaps, you live in China.
- throwaway8491 7y agoWhy would you violate your users' privacy just because of the network they are using? Many activists use sites listed here, including ProtonMail, Keybase, DuckDuckGo. If you're so happy to help USA law enforcement without a subpoena it's a very good thing you didn't build Facebook or Twitter.
- dingdingdanggg 7y agoBecause the people who built Facebook or Twitter don’t do that, right? Let’s be serious.
- hluska 7y agoI'm not trying to be a dick and you're obviously free to do what you wish (in case you wonder, I have not downvoted you). But this attitude has absolutely ruined the web. Despite all the improvements in web technologies, browsers and even bandwidth, I have noticeably more difficulty consuming good information today. This is 100% because of lax attitudes to user privacy. Please stop. :)
- Gene_Parmesan 7y agoA few months ago, I had someone tell me on the programming subreddit that, while they were very concerned about privacy and Google Chrome, they tried Firefox but went back to Chrome because (and I am not making this up) the font kerning in Firefox was slightly suboptimal in certain situations. That's what we're fighting against. This was someone on a technical forum who understood the privacy issues at play. But they valued their own privacy so little that they were willing to trade it for slightly improved font kerning. In short, I worry that we're well and truly fucked.
- fatwashed 7y ago"Tor is the uncensored internet." The connection is uncensored? Or the content you discover is uncensored?
- rubbingalcohol 7y agoYes
- Liquix 7y agoWhomever runs this site is doing a great service to the public. There's got to be a non-trivial amount of effort involved in manually verifying links and preventing the list itself from being compromised/DDoS'd. Kudos to you, dark.fail admin!
- T3RMINATED 7y agoSorry, dark.fail has been blocked by your network administrator. This site was blocked due to the following categories: Drugs