Suggest Trustworthy Tor Hidden Services as Time Sources for sdwdate


deleted because its offline.

I have rearranged the https+onion into one place.

Forgot to add: (will add later with others after the patch accepted)

worth to add as well:



Just the top level domain. The redirection doesn’t matter. What sdwdate does is similar to this this:

curl --head domain.onion

If the replay includes the Date: header then all is good.

Tiny / anonymous?

Removed, since offline:

http://tbrindusxnnqwmzov5qof56hyion6usmciqwykffxqsawswhk73aq5yd.onion # About me | Tudor Brindus

We now have ~ 20 onions per pool. Therefore:

allowed_failures: 7

These are anonymous? Must be non-anonymous as per sdwdate Time Sources Criteria / sdwdate Time Sources Criteria.


I couldnt prove that the clearnet URL is mirrored over that onion.


They are fine not much different than others available.

Time to re-consider. Which others are similarly tiny / anonymous?

"http://danielas3rtn54uwmofdo3x2bsdifr47huasnmbgqzfrec5ubupvtpid.onion # https://web.archive.org/web/20201231025809/https://danwin1210.me https://danwin1210.me Danial Services"
"http://ctemplarpizuduxk3fkwrieizstx33kg5chlvrh37nz73pv5smsvl6ad.onion # https://web.archive.org/web/20210101193954/https://securityheaders.com/?q=https%3A%2F%2Fctemplar.com%2F&followRedirects=on https://securityheaders.com/?q=https%3A%2F%2Fctemplar.com%2F&followRedirects=on https://ctemplar.com CTemplar Email"
"http://wasabiukrxmkdgve5kynjztuovbg43uxcbcxn6y2okcrsg7gb6jdmbad.onion # https://web.archive.org/web/20210604175753/https://wasabiwallet.io/"
"http://6hasakffvppilxgehrswmffqurlcjjjhd76jgvaqmsg6ul25s7t3rzyd.onion # https://web.archive.org/web/20210604180328/https://bitcoincore.org/en/2020/03/27/hidden-service/"
"http://potatoynwcg34xyodol6p6hvi5e4xelxdeowsl5t2daxywepub32y7yd.onion # https://web.archive.org/web/20210604185104/https://securityheaders.com/?q=https%3A%2F%2Fgo-beyond.org%2F&followRedirects=on"
"http://45tbhx5prlejzjgn36nqaxqb6qnm73pbohuvqkpxz2zowh57bxqawkid.onion # https://web.archive.org/web/20210604185300/https://www.parckwart.de/"
"http://offprivqqdxfmssktx3y5h3miqvceq6yy37s5sxkhz4mojvsz74ohqid.onion # https://web.archive.org/web/20210604190115/https://www.offensiveprivacy.com/"
"http://s3p666he6q6djb6u3ekjdkmoyd77w63zq6gqf6sde54yg6bdfqukz2qd.onion # https://web.archive.org/web/20210604192102/https://securityheaders.com/?q=bisq.wiki&followRedirects=on"
"http://zkaan2xfbuxia2wpf7ofnkbz6r5zdbbvxbunvp5g2iebopbfc4iqmbad.onion # https://web.archive.org/web/20210607180626/https://keys.openpgp.org/about/faq"
"http://searxspbitokayvkhzhsnljde7rqmn7rvoga6e4waeub3h7ug3nghoad.onion # https://web.archive.org/web/20210525165705/https://searx.space/ https://searx.space"
"http://t3qi4hdmvqo752lhyglhyb5ysoutggsdocmkxhuojfn62ntpcyydwmqd.onion # https://web.archive.org/web/20200904001100/https://torstatus.rueckgr.at/ https://torstatus.rueckgr.at"

and with the two above sources (elude,snopyta)

Another question i want to ask but i dont know well the answer if we look at all the clearnet sources for securedrop we see the main website is https://securedrop.org/directory then /entityname then mirrored over different onion v3 link… The issue i see in here is that all these services based on one side control which is securedrop meaning if time being manipulated we will have all of the onion v3 related to securedrop going to be manipulated which is taking the biggest chunk of sdwdate onion sources.

Great list! Giving time for discussion and will review later.

It’s a good point. We do need to rely on on the SecureDrop directory. It’s a useful pointer but not necessarily trusted (as in IT trusted - sometimes you trust because you have to, not because you want to). For example it “gives us a little friendly hint” that ABC news runs a SecureDrop onion". The existence of the ABC news SecureDrop onion however can be verified independently from the SecureDrop directory directly on the ABC news page. https://www.abc.net.au/news/securedrop/ - would have been better to archive that link.

That link is also from the SecureDrop directory but checking that the top level domain abc.net.au is authentic and the real ABC news is again sufficient for verification. Plus on top if we wanted to have a comprehensive review manual, pointing out the obvious, one would have to review that ABC news is a real thing.

