Leanpub Header

Skip to main content

Self-Hosting on the Dark Web

Building Private, Anonymous, and Resilient Services on the Tor Network

Self-Hosting on the Dark Web
This book is 100% completeLast updated on 2026-09-28

Go beyond the basics of Tor and learn how to build private, resilient services on the dark web. From onion routing and v3 onion services to real-world threats and secure deployment, this book gives you the technical knowledge and practical skills to host privacy-critical services without exposing where they live.

Minimum price

$25.00

$35.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
181
Pages
About

About

About the Book

This book takes you from the foundational concepts of the Tor network through deep technical understanding of onion routing protocols to hands-on deployment of production-grade self-hosted services accessible only through onion addresses. You will learn how Tor's layered encryption and multi-hop routing actually work at the protocol level, how v3 onion services enable servers to communicate without exposing their physical location, what real threats and attack vectors exist, and how to architect, configure, and maintain resilient onion service infrastructures. Every chapter is grounded in Tor specifications, research literature, and working configurations. Whether you are hosting a personal website, a private messaging system, a file server, or any other privacy-critical service, this book provides the architectural knowledge and practical skills to build it correctly.

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

Building Private, Anonymous, and Resilient Services on the Tor Network

Introduction

Chapter 1: Landscapes of the Invisible Web

  1. The Internet’s Layers: Surface Web
  2. The Deep Web: Everything Behind Login Forms
  3. The Dark Web: Purpose-Built Anonymity Networks
  4. Anonymity vs Pseudonymity vs Privacy
  5. Why Self-Host in the First Place
  6. Legitimate Use Cases and Real-World Motivations

Chapter 2: Origins and Design Philosophy

  1. DARPA’s Purple Gang and Early Onion Routing
  2. Pathway, Mixmaster, and Cryptographic Precursors
  3. The Tor Project is Born: 2002 to Open Source
  4. Funding, Governance, and the Modern Tor Project
  5. Design Goals: Anonymity, Resistance, Usability
  6. The Political and Social Context

Chapter 3: The Tor Network Architecture

  1. What is a Tor Node: Client, Relay, Bridge, Authority
  2. Directory Authorities: The Seven Guardians
  3. Directory Caches and Consensus Distribution
  4. Guard Relays and Stable Path Building
  5. Middle Relays: The Workhorse Tier
  6. Exit Relays: Touchpoints with the Clearnet
  7. Onion Services: Servers on the Tor Network

Chapter 4: The Tor Protocol Stack

  1. The Transport Layer: TCP and TLS Handshakes
  2. Onion Skin Encryption: Layered Keys
  3. Link Keys and Circuit Keys
  4. Key Exchange Protocols: NTor and Older Schemes
  5. Cell Types and Protocol Messages
  6. Version Negotiation and Authentication

Chapter 5: Circuit Construction and Routing

  1. Guard Node Selection and Persistence
  2. Relay Weighting: Bandwidth, Flags, and History
  3. Building a Three-Hop Circuit Step by Step
  4. Exit Node Selection Policies
  5. Circuit Lifetimes, Expiry, and Refresh
  6. Path Isolation and Connection Mapping

Chapter 6: Onion Services: Concept and Evolution

  1. From Hidden Services to Onion Services: Naming Changes
  2. v2 vs v3: Architecture and Security Improvements
  3. The Rendezvous Protocol: Meeting in the Middle
  4. Introduction Points and Rendezvous Points
  5. Service Identifiers and Public Keys
  6. Onion Addresses: Encoding, Structure, and Validation

Chapter 7: The v3 Onion Service Protocol

  1. Private Key Generation and Descriptor Signing
  2. Publishing Onion Service Descriptors
  3. Introducing Points: Registration and Maintenance
  4. Client Discovery: Hash-Based Directory Lookup
  5. Rendezvous Point Selection and Negotiation
  6. End-to-End Circuit Establishment
  7. Descriptor Refresh and Fault Tolerance

Chapter 8: Threat Models and Attack Surfaces

  1. Tor’s Formal Threat Model: What It Promises
  2. Passive Network Observers and Local ISPs
  3. Global Adversaries and Correlation Attacks
  4. Malicious Relays: Observation and Manipulation
  5. Endpoint Compromise and Application Leaks
  6. The Limits of Network-Layer Anonymity

Chapter 9: Traffic Analysis and Correlation Attacks

  1. Passive Correlation: Timing and Volume
  2. Active Attacks: Padding and Probe Techniques
  3. Statistical Fingerprinting and Machine Learning
  4. Network-Wide Correlation at Scale
  5. Defenses: Padding, Guard Diversity, Path Length
  6. Theoretical Guarantees vs Practical Risk

Chapter 10: Fingerprinting and Side Channels

  1. Browser Fingerprinting and Tor Browser Countermeasures
  2. TLS Fingerprinting and JA3 Identifiers
  3. JavaScript Tracking and DOM Fingerprinting
  4. Application-Level Metadata Leaks
  5. Timing Side Channels in Web Applications
  6. Weeping Cryptography and Hidden Data

Chapter 11: Sybil Attacks, Censorship, and Bridges

  1. Sybil Relays and Identity Fabrication
  2. Directory Authority Consensus and Weighting
  3. ISP-Level Blocking and Keyword Filtering
  4. Bridges: Unlisted Entry Points
  5. Pluggable Transports: obfs4 and WebTunnel

Chapter 12: Infrastructure Planning and Design

  1. Jurisdiction and Legal Environment
  2. Hosting Options: Colocation, VPS, Home Hosting
  3. Hardware Requirements and Sizing
  4. Network Topology: Isolation and Segmentation
  5. Power, Connectivity, and Redundancy

Chapter 13: Operating System Hardening and Security

  1. OS Selection: Debian, Alpine, or Specialized Distributions
  2. Minimal Installation and Surface Reduction
  3. Kernel Parameters and Sysctl Hardening
  4. User, Group, and Permission Design
  5. Full Disk Encryption and Key Management
  6. Intrusion Detection and Log Integrity

Chapter 14: Network Configuration and Firewalls

  1. Firewall Fundamentals: iptables and nftables
  2. Default-Deny Policies and Minimal Open Ports
  3. Blocking All Exit Relay Traffic
  4. DNS Resolution Without Information Leakage
  5. Network Interface Isolation
  6. Detecting and Blocking Direct Access Attempts

Chapter 15: Tor Installation and Core Configuration

  1. Installing Tor: Package Managers and Compiling
  2. The torrc File: Structure and Directives
  3. Configuring HiddenServiceDir and HiddenServicePort
  4. Running Tor as a Systemd Service
  5. Validating Circuit and Service Status

Chapter 16: Deploying Your First Onion Service

  1. Minimal Web Server: Nginx Bound to Loopback
  2. First Hidden Service Configuration
  3. Testing with Tor Browser from a Remote Machine
  4. Verifying No Direct IP Accessibility
  5. Checking Descriptor Publication
  6. Troubleshooting First-Time Deployments

Chapter 17: Architectural Pattern: Single-Host Minimal Service

  1. Single Machine Topology Diagram
  2. Nginx Configuration for Loopback Binding
  3. Tor Hidden Service Configuration
  4. Systemd Service Units
  5. SSL/TLS Considerations for Onion Services
  6. Backup and Recovery Procedure

Chapter 18: Architectural Pattern: Hardened Network Segmentation

  1. Three-Tier Network Topology
  2. DMZ Host: Tor and Reverse Proxy
  3. Application Tier Isolation
  4. Database Tier and Access Controls
  5. Internal Firewall Rules Between Zones
  6. End-to-End Request Flow Diagram

Chapter 19: Architectural Pattern: Containerized Multi-Service

  1. Docker Networking and Host vs Container Mode
  2. Tor in a Container vs on the Host
  3. Docker Compose for Multi-Service Stacks
  4. Reverse Proxy Routing to Multiple Onion Services
  5. Persistent Volumes and Secrets Management
  6. Build, Deploy, and Update Workflow

Chapter 20: Private and Authorized Onion Services

  1. Private Onion Services Concept
  2. Client Authorization and ClientAuthFile
  3. Generating and Distributing Authorization Tokens
  4. Combining Tor with Web-Based Authentication
  5. Multi-Factor Authentication over Tor
  6. Managing Revocation and Key Rotation

Chapter 21: Application-Specific Deployments

  1. File Hosting: Nextcloud and FileBrowser
  2. Messaging: Matrix, XMPP, and IRC over Tor
  3. REST and GraphQL APIs behind Onion Services
  4. Remote Administration: SSH and Web Consoles
  5. Personal Cloud and Sync Services
  6. Monitoring and Observability Stacks

Chapter 22: Performance, Scaling, and Optimization

  1. Tor Latency Characteristics and Benchmarks
  2. Bandwidth Limits and Congestion Behavior
  3. Caching and CDN Considerations
  4. Load Balancing Multiple Onion Services
  5. Database Performance Behind Tor
  6. When to Leave Tor Behind for Internal Traffic

Chapter 23: Operations, Monitoring, and Maintenance

  1. Update Cadence and Security Patches
  2. Onion Service Key Rotation
  3. Log Aggregation and Alerting
  4. Backup Strategies: Encrypted and Offsite
  5. Incident Response and Breach Containment
  6. Operational Security Procedures

Chapter 24: Troubleshooting, Diagnostics, and Failure Modes

  1. Verifying Onion Service Reachability
  2. Descriptor Publication Failures
  3. Circuit Construction Problems
  4. Backend Connectivity Issues
  5. HiddenServiceDir Permission Errors
  6. Network-Level Issues
  7. Application-Level Issues
  8. Verifying No IP Address Leakage
  9. Debugging Client-Side Access Issues

Chapter 25: Future Directions and Emerging Technologies

  1. Post-Quantum Cryptography and Proposal 353
  2. Quantum-Safe Onion Service Addresses
  3. Network Growth and Resilience
  4. Decentralized Alternatives and Complementary Technologies
  5. Browser Fingerprinting Evolutions
  6. Machine Learning and Traffic Analysis
  7. Regulatory and Legal Landscape
  8. Practical Skills for the Next Decade

Conclusion

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub