# How to host Onion Services securely?

**URL:** https://discuss.privacyguides.net/t/how-to-host-onion-services-securely/15890
**Category:** Questions
**Created:** 2023-12-28T11:29:30Z
**Posts:** 6

## Post 1 by @jerm — 2023-12-28T11:29:30Z

Torproject has a great guide [Tor Project | Set up Your Onion Service](https://community.torproject.org/onion-services/setup/). (Step 6) and [Tor Project | Advanced settings](https://community.torproject.org/onion-services/advanced/)

But does anyone have a guide/tips that are more advanced other than the ones mentioned in Torproject guide?

---

## Post 2 by @jerm — 2023-12-28T13:35:15Z

> **[Onion Services](https://www.whonix.org/wiki/Onion_Services)**
>
> Anonymously host any server with Whonix and Tor onion services

---

## Post 3 by @jerm — 2024-04-16T20:18:42Z

[https://blog.nihilism.network/servers/endgame/index.html](https://blog.nihilism.network/servers/endgame/index.html)

> EndGameV3 Anti DDOS / Load Balancer / WAF service popularized by Dread

For protecting onion hidden services against DDoS attacks.

---

## Post 4 by @jonah — 2024-04-17T03:41:17Z

Not exactly the same, but I once wrote about how to configure a hidden service in alt-svc mode, in order to improve performance for a _clearnet_ website that’s being accessed over Tor.

> **[Securing Services with Tor and alt-svc - Jonah Aragon](https://www.jonaharagon.com/posts/securing-services-with-tor-and-alt-svc/)**
>
> Some people called for me to write a more technically detailed/in-depth guide to setting up Tor with alt-svc after we set it up on privacyguides.org, so while I do it all over again on our Mastodon server, I figured I’d write this post!...

Improves performance because when you set it up on your website, Tor browsers can access your website via regular relays instead of having to use an exit node.

---

## Post 5 by @jerm — 2024-07-11T22:41:05Z

> **[popets-2024-0117.pdf](https://petsymposium.org/popets/2024/popets-2024-0117.pdf)**
>
> 514.87 KB

> Onion Services in the Wild: A Study of Deanonymization Attacks

> This paper diverges from the common focus on the technical vulnerabilities of the Tor protocol and instead explores the practical aspects of deanonymizing Onion Service users and operators. Despite Tor’s robust security mechanisms, human errors in its usage and operation frequently lead to deanonymization. This study models law enforcement agencies as powerful attackers and evaluates documents from 136 court cases to determine investigative methods. We find that investigators employ different methods depending on the offense, with user mistakes being the dominant angle. Technical attacks, though comparatively rare, are highly effective and can potentially impact a large number of users simultaneously. Attacks on the well-researched Tor protocol are exceptionally rare, but their impact is even more significant. We argue that the human aspect of using Tor is the most critical deanonymization angle and that tailored guidelines for ethical users can help protect them from oppressive retaliation while still enabling the prosecution of criminal activity.

---

## Post 6 by @jerm — 2024-07-20T09:04:52Z

This guide is for how to connect to your VPS anonymously using Tor only, it was made for static sites, but you can also use it for dynamic sites.

> **[Build your own shrine](https://sacredground.click/howto/)**

EDIT; you shouldn’t also host other things on that VPS if you don’t want to link it to your identity.
