Tor Gets An Upgrade – The Fall Harvest

The Tor project are releasing the next generation of onion services! They have been working on this new project ​for the past 4 years and officially launched it two weeks ago by publishing ​their first alpha releases.

Also know as Proposal 224.

This newer version of onion services ("v3") features many improvements over the legacy system, including:

  1. Better crypto (replaced SHA1/DH/RSA1024 with SHA3/ed25519/curve25519)
  2. Improved directory protocol, leaking much less information to directory servers.
  3. Improved directory protocol, with smaller surface for targeted attacks.
  4. Better onion address security against impersonation.
  5. More extensible introduction/rendezvous protocol.
  6. A cleaner and more modular codebase.

You can identify a next-generation onion address by its length: they are 56 characters long, as in 4acth47i6kxnvkewtm6q7ib2s3ufpo5sqbsnzjpbi7utijcltosqemad.onion.Original address - nytimes3xbfgragh.onion

The specification for next gen onion services can be found here: ​https://gitweb.torproject.org/torspec.git/tree/rend-spec-v3.txt

Blog post
https://blog.torproject.org/tors-fall-harvest-next-generation-onion-services

Level Up in Cyber Security: Join Our Membership Today!

vip cta image
vip cta details
  • Nathan House

    Nathan House is the founder and CEO of StationX. He has over 25 years of experience in cyber security, where he has advised some of the largest companies in the world. Nathan is the author of the popular "The Complete Cyber Security Course", which has been taken by over half a million students in 195 countries. He is the winner of the AI "Cyber Security Educator of the Year 2020" award and finalist for Influencer of the year 2022.

  • Misy$ says:

    I love onion

  • Jannifer says:

    nice post.. thank for sharing this.

  • Elliot says:

    Hasn’t Tor been compromised by the security services of the 5 eyes?

  • Arthur says:

    for those that don’t know already, updating to firefox 57, you will lose most of your addons mentioned in the cyber courses. cookie manager and quick java are gone. those were the two I was using.

  • >