Forcing .onion on Project

From Whonix
Jump to navigation Jump to search

Whonix Onion Website - How to consistently access the Whonix website through its Tor Onion Service

Introduction[edit]

Info Note:

Consistent use of the Whonix onion service affords several benefits. It provides alternative end-to-end encryption that is independent of Kicksecure logo TLSOnion Logo certificate authorities and the mainstream Domain Name System. Additionally, it reduces the load on Tor exit nodes.

The onion domain of Whonix is dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion.

dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion

Or, in machine-readable format (API), here is a raw link that only shows the onion: rawOnion Logo

To use .onion services when browsing whonix.org, follow the links below to the Whonix homepage, forums, download, Debian repository, issue tracker, or the Whonix Debian repository.

Onion-Locationarchive.org iconarchive.today icon: Tor Browser 9.5 and later features an opt-in option for using onion sites automatically for participating websites. The system administrator of individual websites can choose to configure this. [1] Direct connections to onion services are harder to track than the Onion-Location opt-in method, which requires making DNS requests and web server connections from an exit node before switching to the onion service. The whonix.org is participating by setting the Onion-Location header.

Issues[edit]

If special precautions are not taken, some resources from the clearnet whonix.org address might be utilized when navigating the onion address. [2]

Also, note that on a few occasions in the past, it was not possible to log in to the Whonix forums using the onion address. [3] [4]

Forcing onion[edit]

There is currently no known method. This remains undocumented.

  • A) One way might be to configure the browser to block DNS requests to whonix.org. However, this is browser-specific.
  • B) Another way might be to configure the operating system to block DNS requests to whonix.org. For example, on Linux-based operating systems, this can be done using the /etc/hosts file. However, this method is both operating system-dependent and browser-dependent, as some browser such as Firefox in the USA, which uses DNS over HTTPS (DoH), or Tor Browser using Tor, do not ask the operating system to resolve DNS.

Forum Discussion[edit]

Footnotes[edit]

  1. The reason is that MediaWiki and Discourse are using the primary Whonix HTTPS domain. These web applications do not support multiple domains for the same website. See also Kicksecure logo Web Application ShortcomingsOnion Logo and Kicksecure logo Privacy on the Whonix WebsiteOnion Logo.
  2. https://forums.whonix.org/t/onion-forum-site-redirects-to-clearnet/197archive.org iconarchive.today icon
  3. This suggests the Whonix forums' onion address could become (temporarily) inaccessible in the future.

We believe security software like Whonix needs to remain open source and independent. Would you help sustain and grow the project? Learn more about our 13 year success story and maybe DONATE!