Skip to content

Latest commit

Β 

History

History
1184 lines (969 loc) Β· 147 KB

onion-sites.md

File metadata and controls

1184 lines (969 loc) Β· 147 KB

Real-World Onion Sites (v3-addresses only)

This is a list of substantial, commercial-or-social-good mainstream websites which provide onion services.

  • no sites with an "onion-only" presence
  • no sites for tech with less than (arbitrary) 10,000 users
  • no nudity, exploitation, drugs, copyright infringement or sketchy-content sites
  • the editor reserves all rights to annotate or drop any or all entries as deemed fit
  • licensed: cc-by-sa
  • author/editor: alec muffett

You can find techical details and the legend/key for symbols in the footnotes section, below.


Index


Blogs

Ctrl blog πŸ”§

Dropsafe πŸ”

Kushal Das πŸ”

Ming Di Leom πŸ”


Civil Society And Community

Riseup Home πŸ”§

provides shared notepad, file sharing, code hosting, and other services

Systemli Home πŸ”§

provides shared notepad, spreadsheet, pastebin, and other services


Companies And Services

Impffrei.work πŸ”

job agency

decoded:Legal πŸ”§

english law firm


Education


Government


News And Media

also, see language index in titlebar

ProPublica πŸ”

https://www.rfa.org/about/releases/mirror_websites-04172020105949.html

The Intercept πŸ”


Tech And Software

DEF CON Home πŸ”§

DEF CON Media πŸ”§

OnionShare πŸ”§

Qubes OS πŸ”§

everything tor

Whonix Forums πŸ”§

Whonix Home πŸ”§

keybase.io πŸ”§


Web And Internet

DuckDuckGo πŸ”

Facebook πŸ”

Protonmail πŸ”


Globaleaks


Securedrop

via: https://securedrop.org/api/v1/directory/

ABC πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

Aftonbladet πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

Apache πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

CBC πŸ”§

via: https://securedrop.org/api/v1/directory/

Dagbladet πŸ”§

via: https://securedrop.org/api/v1/directory/

Forbes πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

HuffPost πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

NRK πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

ProPublica πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

TV2 Denmark πŸ”§

via: https://securedrop.org/api/v1/directory/

TechCrunch πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

The Guardian πŸ”§

via: https://securedrop.org/api/v1/directory/

The Intercept πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

Toronto Star πŸ”§

via: https://securedrop.org/api/v1/directory/

VICE Media πŸ”§

via: https://securedrop.org/api/v1/directory/

via: https://securedrop.org/api/v1/directory/

iROZHLAS πŸ”§

via: https://securedrop.org/api/v1/directory/


Securedrop For Individuals


Securedrop For Organisations


Legacy Sites

These sites have "legacy" v2 onion addresses.

italian whistleblowing

Adresseavisen πŸ”§

Afrileaks πŸ”§

Aftenposten πŸ”§

Aftonbladet πŸ”

Al-Jazeera πŸ”§

Apache πŸ”§

hungarian leaks

includes resources for many languages

BBC News πŸ”

language index

Bezkorupce.cz πŸ”§

czech anticorruption reporting site

BuzzFeed πŸ”§

BuzzFeed News πŸ”

Coworker.org πŸ”§

Dagbladet πŸ”§

Debian Home πŸ”§

everything debian

ExpressVPN πŸ”§

Forbes πŸ”§

Guardian πŸ”§

HuffPost πŸ”§

IRPILeaks πŸ”§

italian investigative reporting project

Mail2Tor πŸ”§

Mailpile πŸ”§

McClatchy DC πŸ”§

Meduza πŸ”§

Mexico Leaks πŸ”§

NBCNews πŸ”§

NPR πŸ”§

NRK πŸ”§

POGO πŸ”§

project on government oversight

Politico πŸ”§

RISE Moldova πŸ”§

https://www.rfa.org/about/releases/mirror_websites-04172020105949.html

https://www.rfa.org/about/releases/mirror_websites-04172020105949.html

https://www.rfa.org/about/releases/mirror_websites-04172020105949.html

Radio-Canada πŸ”§

Reflets.info πŸ”§

Reuters πŸ”§

Slate πŸ”§

The Atlantic πŸ”§

The Intercept πŸ”§

The Telegraph πŸ”§

USA Today πŸ”

VICE Media πŸ”§

Wildleaks πŸ”§

elephant action league

Wired πŸ”§

XNet Activism πŸ”§

anticorruption whistleblowing

disclose.ngo πŸ”§

taz πŸ”§

slovenian whistleblower organisation


Flaky Sites

These sites have apparently stopped responding.


Footnotes

  • This file (README.md) is auto-generated
    • Do NOT submit changes NOR pull-requests for it
    • Please submit an Issue for consideration / change requests
  • If both v2 and v3 addresses are provided for a service, the v3 address will be preferred / cited
  • At the moment where an organisation runs 2+ onion addresses for closely related services that do not reflect distinct languages / national interests, I am posting a link to an index of their onions. Examples: Riseup, Systemli, TorProject, ...
  • The master list of Onion SSL EV Certificates may be viewed at https://crt.sh/?q=\.onion

RWOS Status Detector

  • βœ” site up
  • ✳ site up, and redirected to another page
  • 🚫 site up, but could not access the page
  • πŸ›‘ site up, but reported a system error
  • πŸ†˜ site returned no data, or is down, or curl experienced a transient network error (may be a problem with the RWOS server connection)
  • πŸ†• site is newly added, no data yet

You can also see the history of updates.

Codes & Exit Statuses

Mouse-over the icons for details of HTTP codes, curl exit statuses, and the number of attempts made on each site.

TLS Security

Due to the fundamental protocol differences between HTTP and HTTPS, it is not wise to consider HTTP-over-Onion to be "as secure as HTTPS"; web browsers do and must treat HTTPS requests in ways that are fundamentally different to HTTP, e.g.:

  • with respect to cookie handling, or
  • where the trusted connection terminates, or
  • how to deal with loading embedded insecure content, or
  • whether to permit access to camera and microphone devices (WebRTC)

...and the necessity of broad adherence to web standards would make it harmful to attempt to optimise just one browser (e.g. Tor Browser) to elevate HTTP-over-Onion to the same levels of trust as HTTPS-over-TCP, let alone HTTPS-over-Onion. Doubtless some browsers will attempt to implement "better-than-default trust and security via HTTP over onions", but this behaviour will not be standard, cannot be relied upon by clients/users, and will therefore be risky.

tl;dr - HTTP-over-Onion should not be considered as secure as HTTPS-over-Onion, and attempting to force it thusly will create a future compatibility mess for the ecosystem of onion-capable browsers.

  • πŸ”§ semi-secure HTTP Onion site, protected by Onion circuits at best; will not respect browser secure/HTTPS behaviour
  • πŸ” secure HTTPS Onion site, protected by both Onion circuits and TLS, will respect browser secure/HTTPS behaviour

Feedback

The issues page is the fastest and most effective way to submit a suggestion; if you lack a Github account, try messaging @alecmuffett on Twitter.


Back to Top