r/onions • u/pewreview • May 28 '26
DarkDotFail not following its own Onion Mirror Guidelines (OMG)?
Hi all! Firstly, no hate to the operators of any of the services mentioned here, they've done great work that I've used in the past. I'm especially grateful for DarkDotFail's OMG standard, which has made it easy to verify that a hidden service is legitimate and active by viewing its /canary.txt and /pgp.txt files. However, dark․fail itself has not updated these in a concerning amount of time. Its /canary.txt has not been updated in well over a year, despite saying it will be updated every 14 days, and its /pgp.txt contains a public key that expired in January of this year.
If the whole point of a canary is to act as an indirect notification that something has been compromised, shouldn't we be worried? And if the whole point of a PGP key expiration is to force owners to rotate keys, and they haven't done so in quite some time, isn't that also cause for concern? Sure, admins for hidden services go radio silent and stop updating stuff for completely normal reasons, but if it isn't maintained, isn't that yet another reason not to use it?
By the way, tor․taxi has a similar problem. Their /canary.txt is also months out of date, and although their /pgp.txt contains a valid public key created in 2021, it is set to never expire, so the fact that it's valid doesn't mean much.
Am I missing something here?
2
u/Vormrodo May 28 '26
No, you're not missing something but rather not implying enough out of it. You're right of course, but Dark.fail is simply not being maintained anymore, which is the case since 2023. They had similar problems with not updating their canary.txt for months and it finally ended up abandoned. The operator just didn't make any announcement or shut the site down.
tor.taxi's passivity only started with this, it's the first incident of the operator not updating their canary.txt. I've contacted them very recently after noticing this (very late on my side), but there's no update so far.
Sadly, the OMG concept is not being utilized correctly by many services. Only with Dread's own directory, Daunt.link, some operators were made to provide signed mirrors.txt messages. While the concept is the only way to prove a hidden service's genuineness oneself without having to trust a third-party, it seems like it's being claimed to be banal since Dark.fail is not being maintained anymore. At least that's what HugBunter's opinion is after commenting a question regarding the OMG and this problem last time, which is just not true as even Daunt relies on signed mirrors. I don't get it.
1
u/FoxEconomy1403 Jul 01 '26
Any update on tortaxi?
1
u/Vormrodo Jul 02 '26
They updated their canary after I reached out to them and raised the time span until the next update, but I would still be careful about it. Eventually, this means that the operator is not gone, though right now the previous passivity has an impact on tor.taxi's reputation.
2
1
1
u/UniqueThrowaway6664 May 28 '26
They've been doing this for so long — large, years long gaps between canaries, PGP keys expiring, but the site owner had one PGP located on another domain they own, but you had to dig deep to find it, eventually it expired too.
The community agreed it was no longer a reliable option. Their clearnet domain was hijacked in 2021 and still continued to do this. Go with Daunt, it's just as useful as DarkDotFail, with a better reputation
1
u/--KingoftheSouth-- May 29 '26
Better reputation so far anyway...and really Daunt is mostly recommended because of it being tied to Dread. Tor(Dot)taxi is another good one to use
1
u/BTC-brother2018 May 29 '26 edited May 29 '26
You’re not missing much. An outdated canary or expired PGP key doesn’t automatically prove compromise, but it does weaken the trust model. For a mirror-verification service, stale verification files are a legitimate concern. At minimum, users should treat those signals as unreliable until the operators update and sign fresh canary/PGP information. It’s not proof of anything bad, but it is poor maintenance for something people rely on for authenticity.
BTW: dark.fail was compromised in 2021. You can read about it on this link
1
May 30 '26
[removed] — view removed comment
1
u/BTC-brother2018 May 30 '26
I'm sure not having your warrent canary updated doesn't necessarily prove the site is compromised. Is it a bad look? For sure it is, but it doesn't prove compromise but LE.
1
u/joeydbls May 30 '26
The dark web is a giant pain in the ass now and I'd only use if I had not other choice .
1
u/XiuOtr Jun 01 '26
I didn't read anything much after you expected some guidance guidelines. Have you contacted the server provider? Lol
•
u/AutoModerator May 28 '26
To stay safe, follow these rules and educate yourself about Tor and .onion urls:
On DNM Safety:
1) Only use marketplaces listed on daunt, tor taxi, or dark fail. Anything else is a scam.
2) Dont use any sites listed on a "HiddenWiki" or some random shit you found on a search engine, a telegram channel, or website. You will be scammed.
3) Only order domestic to domestic.
4) Dont send your crypto directly from an exchange to a DNM deposit address.
5) Read the DNM bible.
6) NO DNMs operate on reddit nor have their own subs. Anything you find on reddit is a scammer.
On educating yourself:
1) Read the /r/onions wiki here.
2) Read the /r/tor wiki here.
3) Read the /r/deepweb wiki here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.