.gitignore | ||
01-preamble.md | ||
02-footnotes.md | ||
ct-log.md | ||
ct-log.txt | ||
dump-site.sh | ||
get-ct-log.sh | ||
get-fresh-csv.sh | ||
get-securedrop-csv.py | ||
Makefile | ||
manual-check.sh | ||
master.csv | ||
onion-ctlog.py | ||
README.md | ||
rwos-db.py | ||
securedrop-api.csv | ||
wrapper.sh |
Real-World Onion Sites
Note: database fully reset, 7 june 2023; expect occasional outages and tweaks as it is brought up to date.
This is a list of substantial, commercial-or-social-good mainstream websites which provide onion services.
- no sites with an "onion-only" presence
- no sites for products/technology with less than (arbitrary) 10,000 users
- no nudity, exploitation, drugs, copyright infringement or sketchy-content sites
- the editor reserves all rights to annotate or drop any or all entries as deemed fit
- licensed: cc-by-sa
- author/editor: alec muffett
Legend/Key for Symbols
You can find techical details and the legend/key for symbols in the footnotes section, below.
Regarding Updates and Suggestions
- This file (
README.md
) is auto-generated from a spreadsheet - Please submit an
Issue
for consideration / desired change requests - Do NOT submit changes NOR pull-requests for it
- Re: SecureDrop - all SecureDrop entries are taken automatically from
https://securedrop.org/api/v1/directory/
and must be amended on that site, not this one.
Index
SecureDrop
2600: The Hacker Quarterly
via: https://securedrop.org/api/v1/directory/
- short:
2600.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://cy6wj77vryhcyh6go576hxycjz4wxlo4s5vevdinkw3armwzty5jozyd.onion
- plain:
http://cy6wj77vryhcyh6go576hxycjz4wxlo4s5vevdinkw3armwzty5jozyd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Aftenposten AS
via: https://securedrop.org/api/v1/directory/
- short:
aftenposten.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://tiykfvhb562gheutfnedysnhrxpxoztyszkqyroloyepwzxmxien77id.onion
- plain:
http://tiykfvhb562gheutfnedysnhrxpxoztyszkqyroloyepwzxmxien77id.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Aftonbladet
via: https://securedrop.org/api/v1/directory/
- short:
aftonbladet.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://xm33ge4kupk5o66eqxcd2r4fqcplpqb2sbdduf5z2nw4g2jrxe57luid.onion
- plain:
http://xm33ge4kupk5o66eqxcd2r4fqcplpqb2sbdduf5z2nw4g2jrxe57luid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Al Jazeera Media Network
via: https://securedrop.org/api/v1/directory/
- short:
ajiunit.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://jkta32w5gvk6pmqdfwj67psojot3l2iwoqbdvrvywi5bkudfeandq7id.onion
- plain:
http://jkta32w5gvk6pmqdfwj67psojot3l2iwoqbdvrvywi5bkudfeandq7id.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Apache
via: https://securedrop.org/api/v1/directory/
- short:
apache.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://okd7utbak43lm7qaixr6yv7s62e32mhngjsfpjn26eklokqofg6776yd.onion
- plain:
http://okd7utbak43lm7qaixr6yv7s62e32mhngjsfpjn26eklokqofg6776yd.onion
- proof: link
- check: ❓❓❓❓⏰❓❓❓❓❓❓❓❓⏲️
Bloomberg Industry Group
via: https://securedrop.org/api/v1/directory/
- short:
bloombergindustrygroup.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://33buewrpzrfpttl7kerqvtvzyo3ivumilwwmeqjryzajusltibaqc6ad.onion
- plain:
http://33buewrpzrfpttl7kerqvtvzyo3ivumilwwmeqjryzajusltibaqc6ad.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Bloomberg News
via: https://securedrop.org/api/v1/directory/
- short:
bloomberg.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://ogdwaroarq4p6rnfn2hl4crvldyruyc2g24435qtxmd3twhevg7dsqid.onion
- plain:
http://ogdwaroarq4p6rnfn2hl4crvldyruyc2g24435qtxmd3twhevg7dsqid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
CBC
via: https://securedrop.org/api/v1/directory/
- short:
cbcrc.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://gppg43zz5d2yfuom3yfmxnnokn3zj4mekt55onlng3zs653ty4fio6qd.onion
- plain:
http://gppg43zz5d2yfuom3yfmxnnokn3zj4mekt55onlng3zs653ty4fio6qd.onion
- proof: link
- check: ✅✅✅✅✅✅⏲️✅❓❓❓❓❓❓
CNN
via: https://securedrop.org/api/v1/directory/
- short:
cnn.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://qmifwf762qftydprw2adbg7hs2mkunac5xrz3cb5busaflji3rja5lid.onion
- plain:
http://qmifwf762qftydprw2adbg7hs2mkunac5xrz3cb5busaflji3rja5lid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Disclose
via: https://securedrop.org/api/v1/directory/
- short:
disclose.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://3tcbrdg2ejwu5nzbjg7xqixkis6mdbgkkthcyxmzv2q3oi6v7th5ahqd.onion
- plain:
http://3tcbrdg2ejwu5nzbjg7xqixkis6mdbgkkthcyxmzv2q3oi6v7th5ahqd.onion
- proof: link
- check: ✅✅✅✅⏲️✅✅✅✅✅✅✅✅✅
Financial Times
via: https://securedrop.org/api/v1/directory/
- short:
ft.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://nqu6crmtnzs2hs5abo2uqni53yqsnnwqnerdxuzyz5yxairxlzjzt6yd.onion
- plain:
http://nqu6crmtnzs2hs5abo2uqni53yqsnnwqnerdxuzyz5yxairxlzjzt6yd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Forbes
via: https://securedrop.org/api/v1/directory/
- short:
forbes.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://6zonlfhh7aqtfwoyvdlad3nxn6ljecx2k6tyyy3spt43nn54q6lvncid.onion
- plain:
http://6zonlfhh7aqtfwoyvdlad3nxn6ljecx2k6tyyy3spt43nn54q6lvncid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Forbidden Stories
via: https://securedrop.org/api/v1/directory/
- short:
forbiddenstories.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://fg25fqpu2dnxp24xs3jlcley4hp2inshpzek44q3czkhq3zffoqk26id.onion
- plain:
http://fg25fqpu2dnxp24xs3jlcley4hp2inshpzek44q3czkhq3zffoqk26id.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅⏰✅✅✅✅✅
HuffPost
via: https://securedrop.org/api/v1/directory/
- short:
huffpost.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://ppw2pmtagxykinex6uubypsommtrcg6ytdh6bcr6agq2wxnrweao4cad.onion
- plain:
http://ppw2pmtagxykinex6uubypsommtrcg6ytdh6bcr6agq2wxnrweao4cad.onion
- proof: link
- check: ❓❓❓❓❓❓❓❓❓❓❓❓❓❓
Institute for Quantitative Social Science at Harvard University
via: https://securedrop.org/api/v1/directory/
- short:
iqss.harvard.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://5kcyaqagvnrvyan7y5ntzreqsn2msowqlmtoo46qju2pctlbkzzztxqd.onion
- plain:
http://5kcyaqagvnrvyan7y5ntzreqsn2msowqlmtoo46qju2pctlbkzzztxqd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
NOYB
via: https://securedrop.org/api/v1/directory/
- short:
noyb.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://xjc4s5z26i2z5tzjzj3w6jwzuomedzsahq4tccktwdcs6fldt4ojznqd.onion
- plain:
http://xjc4s5z26i2z5tzjzj3w6jwzuomedzsahq4tccktwdcs6fldt4ojznqd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
NRK
via: https://securedrop.org/api/v1/directory/
- short:
nrk.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://537ztcntpbmspja4mkpxldpsoc46mqlssnsaklqnfw3gnlpj5glcjgid.onion
- plain:
http://537ztcntpbmspja4mkpxldpsoc46mqlssnsaklqnfw3gnlpj5glcjgid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
New York Times
via: https://securedrop.org/api/v1/directory/
- short:
nytimes.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://ej3kv4ebuugcmuwxctx5ic7zxh73rnxt42soi3tdneu2c2em55thufqd.onion
- plain:
http://ej3kv4ebuugcmuwxctx5ic7zxh73rnxt42soi3tdneu2c2em55thufqd.onion
- proof: link
- check: ✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️
POLITICO
via: https://securedrop.org/api/v1/directory/
- short:
politico.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://mzi5yynpd6qqq3lnh7vnaojy36v3hcorytsut47zwkguhnorduyxwead.onion
- plain:
http://mzi5yynpd6qqq3lnh7vnaojy36v3hcorytsut47zwkguhnorduyxwead.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅⏰✅
Public Intelligence
via: https://securedrop.org/api/v1/directory/
- transport: 🔺 HTTP
- link: http://z4gd5t2g6u6kqeqjeddvmvlhhjtjgslg4elh4ztnct7snskcd7phbiyd.onion
- plain:
http://z4gd5t2g6u6kqeqjeddvmvlhhjtjgslg4elh4ztnct7snskcd7phbiyd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Stefania Maurizi
via: https://securedrop.org/api/v1/directory/
- short:
maurizi.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://jxsb4ovmavjy3r64bak4ha63xwggf3nzf3vikvs23r2avm5rhzmaqtqd.onion
- plain:
http://jxsb4ovmavjy3r64bak4ha63xwggf3nzf3vikvs23r2avm5rhzmaqtqd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Süddeutsche Zeitung
via: https://securedrop.org/api/v1/directory/
- transport: 🔺 HTTP
- link: http://udhauo3m3fh7v6yfiuornjzxn3fh6vlp4ooo3wogvghcnv5xik6mnayd.onion
- plain:
http://udhauo3m3fh7v6yfiuornjzxn3fh6vlp4ooo3wogvghcnv5xik6mnayd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
TV2 Denmark
via: https://securedrop.org/api/v1/directory/
- short:
tv2.dk.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://srumyob2jq5nvppzt66aaab333n2wmq6xgkg4khfe24ixdb7umf7mtyd.onion
- plain:
http://srumyob2jq5nvppzt66aaab333n2wmq6xgkg4khfe24ixdb7umf7mtyd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Taz
via: https://securedrop.org/api/v1/directory/
- short:
taz.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://tazleakssvtc2lqrhkpvbzo6qwolcldzkzoexo7wombufd6a573bhlid.onion
- plain:
http://tazleakssvtc2lqrhkpvbzo6qwolcldzkzoexo7wombufd6a573bhlid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
TechCrunch
via: https://securedrop.org/api/v1/directory/
- short:
techcrunch.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://vplxle7awnyvvvduv6exnwrxbf4gzsh7lv7fxosnfl2ecidkttcbfcqd.onion
- plain:
http://vplxle7awnyvvvduv6exnwrxbf4gzsh7lv7fxosnfl2ecidkttcbfcqd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
The Globe and Mail
via: https://securedrop.org/api/v1/directory/
- short:
theglobeandmail.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://a4zum5ydurvljrohxqp2rjjal5kro4ge2q2qizuonf2jubkhcr627gad.onion
- plain:
http://a4zum5ydurvljrohxqp2rjjal5kro4ge2q2qizuonf2jubkhcr627gad.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
The Guardian
via: https://securedrop.org/api/v1/directory/
- short:
theguardian.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://xp44cagis447k3lpb4wwhcqukix6cgqokbuys24vmxmbzmaq2gjvc2yd.onion
- plain:
http://xp44cagis447k3lpb4wwhcqukix6cgqokbuys24vmxmbzmaq2gjvc2yd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
The Intercept
via: https://securedrop.org/api/v1/directory/
- short:
theintercept.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://lhollo6vzrft3w77mgm67fhfv3fjadmf7oinmafa7tbmupc273oi7kid.onion
- plain:
http://lhollo6vzrft3w77mgm67fhfv3fjadmf7oinmafa7tbmupc273oi7kid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
The Washington Post
via: https://securedrop.org/api/v1/directory/
- short:
washingtonpost.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://vfnmxpa6fo4jdpyq3yneqhglluweax2uclvxkytfpmpkp5rsl75ir5qd.onion
- plain:
http://vfnmxpa6fo4jdpyq3yneqhglluweax2uclvxkytfpmpkp5rsl75ir5qd.onion
- proof: link
- check: ✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️✳️
Toronto Star
via: https://securedrop.org/api/v1/directory/
- short:
torontostar.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://yj3b7rgmglcocbbvzrwfbo4d6j2aa7thwupra4yqutbd27v3vxcpvgid.onion
- plain:
http://yj3b7rgmglcocbbvzrwfbo4d6j2aa7thwupra4yqutbd27v3vxcpvgid.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Whistleblower Aid
via: https://securedrop.org/api/v1/directory/
- short:
whistlebloweraid.securedrop.tor.onion
- transport: 🔺 HTTP
- link: http://kogbxf4ysay2qzozmg7ar45ijqmj2vxrwqa4upzqq2i7sqj7wv7wcdqd.onion
- plain:
http://kogbxf4ysay2qzozmg7ar45ijqmj2vxrwqa4upzqq2i7sqj7wv7wcdqd.onion
- proof: link
- check: ✅✅✅✅✅✅✅✅✅✅✅✅✅✅
Flaky Sites
These sites have apparently stopped responding.
Footnotes
- At the moment where an organisation runs 2+ onion addresses for closely related services that do not reflect distinct languages / national interests, I am posting a link to an index of their onions. Examples: Riseup, Systemli, TorProject, ...
- The master list of Onion SSL EV Certificates may be viewed at https://crt.sh/?q=.onion
RWOS Status Detector
- ✅ site up
- ✳️ site up, and redirected to another page
- 🚫 site up, but could not access the page
- 🛑 site up, but reported a system error
- 🆘 site returned no data, or is down, or curl experienced a transient or permanent network error; may also reflect a problem with the RWOS server connection
- ❓ same as 🆘 but curl specifically mentioned inability to fetch an onion descriptor
- ❗ same as 🆘 but curl specifically mentioned inability to connect to the server
- ⏰ same as 🆘 but curl specifically mentioned connection timeout as an issue
- ⏲️ same as 🆘 but curl specifically mentioned ttl expiry as an issue
- 🔑 same as 🆘 but curl specifically mentioned SSL certificates as an issue
- 🆕 site is newly added, no data yet
You can also see the history of updates.
Codes & Exit Statuses
Mouse-over the icons for details of HTTP codes, curl exit statuses, and the number of attempts made on each site.
- codes are from HTTP and are documented elsewhere; RWOS-internal ones include:
901
- malformed HTTP response902
- malformed HTTP response903
- malformed HTTP response, commonly including (e.g.) invalid HTTPS certificate904
- HTTP status code parse error910
- connection timeout
- exits are from Curl and are documented elsewhere; common ones include:
7
- "curl couldn't connect"52
- "curl got nothing", received no data from upstream
TLS Security
Due to the fundamental protocol differences between HTTP
and
HTTPS
, it is not wise to consider HTTP-over-Onion to be "as secure
as HTTPS"; web browsers do and must treat HTTPS requests in
ways that are fundamentally different to HTTP, e.g.:
- with respect to cookie handling, or
- where the trusted connection terminates, or
- how to deal with loading embedded insecure content, or
- whether to permit access to camera and microphone devices (WebRTC)
...and the necessity of broad adherence to web standards would make it harmful to attempt to optimise just one browser (e.g. Tor Browser) to elevate HTTP-over-Onion to the same levels of trust as HTTPS-over-TCP, let alone HTTPS-over-Onion. Doubtless some browsers will attempt to implement "better-than-default trust and security via HTTP over onions", but this behaviour will not be standard, cannot be relied upon by clients/users, and will therefore be risky.
tl;dr - HTTP-over-Onion should not be considered as secure as HTTPS-over-Onion, and attempting to force it thusly will create a future compatibility mess for the ecosystem of onion-capable browsers.
Feedback
The issues page
is the fastest and most effective way to submit a suggestion; if you
lack a Github account, try messaging @alecmuffett
on Twitter.