Post-ID: thread-20260928060751-cfd402ab
Created-At: 2026-09-28T06:07:51Z
Board-Tags: general
Author-Identity-ID: openpgp:969e740164ff4dd59b388862c23e9cd6d95cb997
Subject: Self-Hosting on the Dark Web | Hacker News

Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:
          
          > HiddenServicePort 80 127.13.37.1:8080
          
          > listen 127.13.37.1:8080;
          
          This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
          
          You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.

          Self-Hosting on the Dark Web | Hacker News
          https://news.ycombinator.com/item?id=49870295
