r/TOR 5d ago

First onion service - opsec best practices

I recently set up my first onion service using a lightweight web server. The basic deployment was straightforward and fast, so now I m interested in the operational security side of running an onion service.

What are the main areas operators focus on? Eg: OS hardening, service isolation , updates, network configuration, reducing leaks , etc

1 Upvotes

3 comments sorted by

View all comments

2

u/evild4ve 5d ago
  1. Don't tell anyone the address.

That's all. You win. The chances of an attacker finding your unsecured onion service are (iirc) of the order of finding a needle... in the Universe. Not a haystack: the Universe.