# Using hidden services to replace exit nodes

**URL:** https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336
**Category:** General Discussion
**Created:** [April 16, 2024, 6:51am UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336 "2024-04-16T06:51:44Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![everydayisoks](https://forum.torproject.org/user_avatar/forum.torproject.org/everydayisoks/32/3044_2.png) [@everydayisoks](https://forum.torproject.org/u/everydayisoks)
#### Post date: [April 16, 2024, 6:51am UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336/1 "2024-04-16T06:51:44Z")

</div>

Tor’s exit nodes are public, including their hidden nodes are made public by [Metrics](https://metrics.torproject.org/rs.html#details/2B4D5AA9997D4DDFF02BC52E173CF0C8FFFD1B9C). Many countries can easily block Tor access by setting up IP blacklists. I’ve seen many users in the forums experiencing the above troubles.

**I suggest that hidden services should be used instead of partial exit nodes to enhance Tor accessibility.** The presence of bridges means that Tor has decided to make some of its nodes semi-public, so for exit nodes, this semi-public approach should be used as well, i.e., using hidden services instead of some of the exit nodes. And the release of these **hidden service bridges** can be modeled after the release of OBFS4, Snowflake, and others.

I strongly believe that using hidden services instead of exit nodes does not require the developer to modify the Tor source code, but rather just a simple configuration. I hope developers will take my suggestion seriously.

---

<div class="post-metadata">

### Author: ![Vort](https://forum.torproject.org/user_avatar/forum.torproject.org/vort/32/63_2.png) [@Vort](https://forum.torproject.org/u/Vort)
#### Post date: [April 16, 2024, 9:44am UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336/2 "2024-04-16T09:44:55Z")

</div>

I think it is almost impossible to hide exit nodes.  
Attacker can just launch Tor Browser, point it to his website and collect IP addresses.

---

<div class="post-metadata">

### Author: ![gus](https://forum.torproject.org/user_avatar/forum.torproject.org/gus/32/16_2.png) [@gus](https://forum.torproject.org/u/gus)
#### Post date: [April 16, 2024, 10:58am UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336/3 "2024-04-16T10:58:08Z")

</div>

> [@everydayisoks](#):
>
> I strongly believe that using hidden services instead of exit nodes does not require the developer to modify the Tor source code, but rather just a simple configuration. I hope developers will take my suggestion seriously.

Georgetown GUSecLab implemented the concept of Exit bridges (with and without onion services):

> Tor exit blocking, in which websites disallow clients arriving from Tor, is a growing and potentially existential threat to the anonymity network. We introduce two architectures that provide ephemeral exit bridges for Tor which are difficult to enumerate and block. Our techniques employ a micropayment system that compensates exit bridge operators for their services, and a privacy-preserving reputation scheme that prevents freeloading. We show that our exit bridge architectures effectively thwart server-side blocking of Tor with little performance overhead.

Website: [Bypassing Tor Exit Blocking](https://seclab.cs.georgetown.edu/hebtor/)

Video presentation: [https://dl.acm.org/doi/10.1145/3372297.3417245](https://dl.acm.org/doi/10.1145/3372297.3417245)

Code: [GitHub - GUSecLab/tor-exit-relays](https://github.com/GUSecLab/tor-exit-relays)

Papers:

- [Ephemeral Exit Bridges for Tor | IEEE Conference Publication | IEEE Xplore](https://ieeexplore.ieee.org/document/9153401)
- [https://dl.acm.org/doi/10.1145/3372297.3417245](https://dl.acm.org/doi/10.1145/3372297.3417245)

Tor forum link:

> [@Why not add the ability to add a proxy in the circuit after the exit node in case a website is blocking Tor?](https://forum.torproject.org/t/why-not-add-the-ability-to-add-a-proxy-in-the-circuit-after-the-exit-node-in-case-a-website-is-blocking-tor/164/3):
>
> I think that’s just a palliative solution that wouldn’t help Tor users in the medium term. For regular Tor users, that would not scale well. But, if you’re trying to solve the Captcha issue and/or websites blocking Tor users, there are more interesting projects and approaches. For example: Monitoring [Exit nodes IP reputation and Captchas](https://gitlab.torproject.org/woswos/CAPTCHA-Monitor/-/wikis/home). We could work with exit nodes operators to rotate their IP addresses more frequently. A ‘Privacy-pass’ like solution. A project that would require more engi…

---

<div class="post-metadata">

### Author: ![WofWca](https://forum.torproject.org/user_avatar/forum.torproject.org/wofwca/32/2302_2.png) [@WofWca](https://forum.torproject.org/u/WofWca)
#### Post date: [April 16, 2024, 6:59pm UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336/4 "2024-04-16T18:59:35Z")

</div>

Similar forum post

> [@Websites blocking Tor](https://forum.torproject.org/t/websites-blocking-tor/6095):
>
> Would it be possible to add some type of “bridge” as last hop? Many websites seems to be able to recognize TOR exits and, subsequently, block the connection.

---

<div class="post-metadata">

### Author: ![system](https://forum.torproject.org/uploads/default/original/2X/d/d3424bed34f4ec18b2e99178c2801ba6dfb655d6.png) [@system](https://forum.torproject.org/u/system)
#### Post date: [May 14, 2024, 1:44am UTC](https://forum.torproject.org/t/using-hidden-services-to-replace-exit-nodes/12336/5 "2024-05-14T01:44:10Z")

</div>

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.
