Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
The solution to the website onion services to make it reliable is to not use the anonymity benefit for the website and increase the speed and connection stability. This is adopted back in 2016 by facebook and riseup (and probably every project now which doesnt need anonymity).
Today, we are introducing Single Onion Services! With this new feature, a service can now specify in its configuration file that it does not need anonymity, thus cutting the 3 hops between the service and its Rendezvous Point and speeding up the connection.
Rendezvous single onion services are an alternative design for single onion services, which trade service-side location privacy for improved performance, reliability, and scalability.
Simple solution.
Even extra reliability/speed: We can host our own single node that the hidden service gonna use, this way we control the connection without relying on Tor network relays (but can be done later if needed).
cc @Patrick
Tor upstream DoS issue attacker can force intro point rotation by ddos reported by Tor developer Roger Dingledine. At the time of writing:
- issue opened in year
2018, StatusOpen,Not Scheduled,- last comment by Roger Dingledine in year
2023, - last ticket status change to
Not Scheduledin December2025.
Thats an assumption the mirrors are being attacked by ddos (we need an evidence otherwise its claim), but i think its a general design issue, which made projects are just skipping the anonymity of the server (since its not needed) and increasing the availability, thus everything is working fine on their side.
Either DoS or lots of people updating/installing software in whonix. Is it due to the design and decision to host the forum and repo on same onion address?
Maybe one day there could have been an update to discourse forum software causing conflict now. Also people having the forum in RSS feed is another bandwidth point. I dont recall having this issue in the past (3-4 years ago) with reaching the deb repo.
It’s not an assumption. It’s an example, that Tor upstream maintenance, stability of Tor onions is less than stellar.
More unresolved Tor upstream mysteries: Invalid HS descriptor.
Quote
- https://gitlab.torproject.org/tpo/core/tor/-/issues/41094
- https://gitlab.torproject.org/tpo/core/tor/-/issues/41016
- https://gitlab.torproject.org/tpo/core/tor/-/issues/41101
Other project’s onion’s often also fail to pinpoint the exact reason for their onion reachablity issues, let alone apply durable stability fixes. Examples here:
Onion Domains by Other Projects
A wiki page to collect these kind of issues and troubleshooting tools has been created:
On general networking issues debugging (doesn’t even need to involve Tor, let alone onions):
Unsuitable, at the time of writing also has bugs and maintenance issues, documented here: OnionBalance
docker is a non-issue. download.whonix.org (or its onion) is simple, not docker.
And why do we need to even ask the question “is the onion fine, but the endpoint server broken?”
At least that one can be safely excluded somewhat easily:
The split brain thing is interesting I would guess that configuration would involve the same onion service keys on two different servers for load balancing. Reminds me of having separate and isolated hidden service directories and configs instead of a single torrc for multiple services can cause issues if not set up right.
E-mail received from the server host.
Dear redacted,
We have indications that your server has been attacked. Those responsible for this have been asked to solve the issue and to give us a statement on the cause of the attack.
This is an information email only and does not require any further action on your part.
Important note:
When replying to us, please leave the abuse ID [AbuseID:redacted] unchanged in the subject line.
Please note that we do not provide telephone support in our department. If you have any questions, please send them to us by opening a new ticket via Robot.Kind regards
Network department
Hetzner Online GmbH
redactedDirection IN
Internal redacted
Threshold Packets redacted packets/s
Sum redacted packets/300s (redacted packets/s), redacted flows/300s (redacted flows/s), redacted GByte/300s (redacted MBit/s)
External redacted, redacted packets/300s (redacted packets/s), redacted
Contains a log with packets and MBit/s of participating DDoS IPs.
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Would it be terrible to fall back to e.g. tor+https://deb.whonix.org trixie InRelease, which has been consistently functional? I ask partly from a position of ignorance.
It’s not a problem if you or anyone else wants to do that on their specific system, but to my awareness apt doesn’t really have such a concept as a “fallback URL”. At best we could add both URLs at once, at which point apt would be left to figure out which repo to pull package by itself. Which repo it would pick would be implementation-defined and possibly semi-random.
It’s the default. Related user documentation wiki chapter: Non-functional Onion Services
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Its an assumption to say that our mirrors are down due to DOS. Thats why i suggested more reliable way to solve this (which is suggested by TPO anyway) to remove the anonymity of the servers (since they are on clearnet anyway) and keep up the user anonymity side. So we dont lose a thing if use the more reliable way.
Didnt face that from a known services like brave search engine or startpage or ahmia or proton..etc.
You will loose some of these features:
But i wouldnt call it terrible because its not straight deanonymization or insecure way.
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease
Fail to refresh InRelease: tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion trixie InRelease from tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/dists/trixie/InRelease