Skip to content
DnsLister Forum

Where domain hunters compare notes

An alternative for TOR?

This is not a Tor replacement and I want to say that before anything else, because the addresses look familiar and that could read as a claim I am not making. A `.capsule` name is base32 of an Ed25519 public key plus a checksum and a version byte, 56 characters, which is the onion v3 construction. I did not arrive at that independently. I took it, for the same reason Tor did: a readable name needs a registry, a registry needs a registrar, and a registrar is somebody who can be leaned on.

What I built is a network for files and static sites where the host cannot read what it holds. An onion service is a normal web server: it terminates the connection, it holds plaintext, it can log every path you requested and serve you something different from what it serves somebody else. Tor protects the visitor from the network, which it does extremely well, and does not protect the visitor from the site. A relay in my network stores one encrypted blob padded to a size class under a neutral filename, and the key that opens it travels in the fragment of a link, which browsers do not send to servers.

The second difference is what a page is allowed to do. The extension does not display a site, it rebuilds it before showing it: references that resolve inside the bundle become data URLs, anything pointing at the open web is removed, base and meta refresh are deleted, and the result goes into an opaque origin under connect-src none with no scripts unless the visitor allows them for that site. So a page cannot fetch a font, load a pixel or send a beacon. The whole site downloads at once, with no partial fetch, specifically so the host does not learn which pages were read.

The third is a latency tradeoff Tor cannot make. Because a file transfer can take minutes, every packet is the same 65,920 bytes, each hop holds it for an exponentially distributed delay, and nodes emit cover loops. That is Sphinx and Loopix-style mixing rather than onion routing, and it exists to attack the end-to-end correlation that a low-latency system has no answer to. It is also useless for browsing, which is why it is not competing with you.

Where Tor is better is not close. Thousands of relays across jurisdictions against my one. Twenty years of analysis against none. A general TCP transport against a file and static site format. Pluggable transports against a single bridge mode. Every claim I make about anonymity is currently vacuous for the reason you would guess: routing through relays that one person operates protects nobody, and that is close to what exists today. The CLI prints how many operators there actually are before every mixed send, because a number is harder to oversell than a paragraph.

The two are also meant to compose rather than compete. The CLI speaks SOCKS5 with hostname resolution at the proxy, so `–tor –mix` puts both underneath: Tor hides from your ISP that you are using this at all, and the mix hides from the relays who you are. Those are different problems.

The actual reason I am posting here is a limitation I hit and could not solve cleanly. I wanted relays to be reachable as onion services, so that running one needed no public IP, no port forwarding and no domain, which is the single biggest obstacle to anybody running one. It does not work today. When a relay announces itself, the receiving relay verifies the address by dialling it back, and that check resolves names in DNS and refuses anything that does not resolve. An onion address does not resolve in DNS. Even bypassing that, the dial-back uses an ordinary HTTP client with no SOCKS proxy, so no relay could reach the announced address anyway.

I can see the shape of a fix, which is teaching the peer layer to dial through a SOCKS proxy and to treat a `.onion` suffix as valid without a DNS lookup. What I do not know is whether that is the approach people here would expect, or whether there is a standard way this is done that I have not found. If you have run a service that had to verify a peer's onion address before trusting it, I would like to hear how.

Code: https://github.com/missingus3r/CAPSULE

What it is: https://missingus3r.github.io/CAPSULE/

MIT, no token, no company, no audit. docs/MIXNET.md has a section titled what this network does not do, and docs/SITES_VS_ONION.md is a direct comparison with onion services that is not flattering to mine in the places where it should not be.

Source: r/TOR · by /u/BillHaunting

Leave a Reply

Your email address will not be published. Required fields are marked *