you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 15 min ago 255 onions tracked
home / news / tor network
05 November 2024 tor network 4 min read

Why Naive Monitors Lie: The Methodology Behind Honest Onion Uptime Badges

A green badge is a promise. When a status list marks an onion service as online, visitors plan downloads, logins, and purchases around that claim — and most badges are built on a methodology that cannot keep it.

The problem with a single HTTP request

The naive approach looks simple: send one request, mark the site up if anything comes back. On the clearnet that is sloppy; on Tor it is close to meaningless. Reaching an onion service means fetching a descriptor from hidden service directories, building an introduction circuit, and completing a rendezvous handshake before a single byte of content arrives. Any of those steps can fail for reasons that have nothing to do with the server. Academic measurement of onion services has repeatedly shown high churn and volatile availability across the network, which means a lone failed probe tells you almost nothing (Kint et al., Detection and Analysis of Tor Onion Services, ACM CCS 2019). One data point is not a status. It is a coin flip with extra latency.

Probe frequency: often enough to matter, rare enough to be honest

We probe every listed service on a rolling schedule measured in minutes, not seconds. Clearnet monitoring guidance typically recommends 30-to-60-second intervals for production systems, but onion circuits take longer to build and hammering them more often mostly measures circuit luck rather than server health (SSLShopper on reducing false positives in uptime monitoring). Frequency also has an ethical edge. Aggressive probing against services you do not operate is indistinguishable from light scanning, and it wastes relay bandwidth. A disciplined cadence respects the network while still catching real outages within a useful window. Our status checker reflects exactly what these probes saw, nothing more.

Retry discipline: no verdict on the first failure

Here is the rule that separates honest monitors from noisy ones: a single failed probe never flips a badge. We require consecutive failures from independent probes before marking a service down, mirroring the confirmation logic that mainstream monitoring practice recommends for cutting false alarms. Between retries we rebuild the Tor circuit entirely. A fresh path rules out a bad guard, a congested middle relay, or a stale introduction point as the culprit. If three independent paths all fail, the evidence points at the destination. If they disagree, the honest label is degraded or unreachable from our vantage point — not down.

Timeouts: generous by design

Tor is slow, and that is the price of anonymity. Circuit construction alone routinely takes several seconds under load, so a clearnet-style five-second timeout would flag healthy services as dead all day. The Tor Project's own monitoring tooling accounts for this reality with configurable timeouts and per-endpoint metrics (Onionprobe documentation). We use layered timeouts: one budget for descriptor retrieval and circuit setup, another for the HTTP response itself. That distinction matters because it separates "the network could not get there" from "the server stopped answering." Collapsing both into a single clock hides the difference, and the difference is the story.

What a badge actually measures

Even done well, uptime monitoring measures reachability from specific probes at specific moments. It does not measure authenticity, safety, or whether the application behind the port works. Community guides for onion checking make the same caveat: availability signals are noisy, vantage-point-dependent observations, not forensic statements about a service (Altfield, Monitoring Tor onion websites with alerts). Our methodology, in short:
  • Probes run on a rolling multi-minute schedule through independent Tor circuits.
  • A badge flips only after repeated failures confirmed from fresh paths.
  • Circuit-setup and response timeouts are tracked separately.
  • Single-probe anomalies are recorded but never treated as downtime.
No monitor can promise truth about the whole Tor network. A good one promises honesty about what its own probes saw.
That is why our seven-day uptime window aggregates every probe rather than cherry-picking the last check, and why badges sometimes flip between mirrors without the underlying servers changing at all. Methodology is the product. The badge is just its public face.

more notes

all news ›