A page reached through a gateway
The address in the bar ends in a normal domain with an onion glued to the front of it. That means somebody else made the connection on your behalf, and everything you type is passing through their machine in a form they can read.
- What it is
- A relay that fetches onion pages and forwards them to a normal browser
- Where you meet it
- Search results, on a machine where you cannot install anything
- What it settles
- Nothing. You are trusting a party you cannot name
- Cannot tell you
- Whether the page you got is the page that was served
The specimen
lime: the onion address, which looks reassuring and is doing nothing
salmon: the part that actually decides where your traffic goes
A gateway URL, split. The onion address at the front is text. The domain after it is where the connection really goes, and it is an ordinary website belonging to somebody with a hosting bill and a name.
It is not a trust question
A gateway that could not read your traffic could not forward it. Fetching the page, and passing your form submission on, is the entire job. So this is not an operator behaving badly or a flaw waiting for a patch. The exposure is the mechanism, and an honest operator has exactly the same access as a dishonest one.
What it costs, item by item
| What you lose | Because |
|---|---|
| Your password and code | You typed them into a form that goes through their machine |
| Anonymity from the destination | The connection arrives from the gateway, so the protection is protecting them |
| Anonymity from your own network | You visited an ordinary domain, which is visible in ways an onion connection is not |
| The ability to verify anything | The page reached you via a party who could change it, so you would be checking what they chose to show |
| Knowing where you went | They resolved the address. You are trusting them to have gone where you asked |
Why people end up here anyway
Almost always because installing a browser was not possible at that moment. A work machine, a phone, a borrowed computer, a policy that blocks it. Those are practical reasons rather than careless ones, and telling somebody they should have known better does not get them anywhere. The honest answer is that the obstacle was doing the work, and the alternative is Tor Browser from the project itself with the installer signature checked.
If you already used one
Treat the credentials as read and change them from a proper connection, along with anywhere else you used the same ones. Assume anything you typed was seen. Nothing further is recoverable and nothing worse follows from the fact alone, so the useful response is a password change and a browser install rather than alarm.
The one situation where people are right to be annoyed
Being told to install a browser is easy advice to give and not always easy to follow. A locked down work machine, a phone, a borrowed computer, a network that blocks it. Those are real constraints and the honest answer is that there is no safe shortcut around them, not that the person should have tried harder. If you cannot install it, the correct move is to wait until you are somewhere you can, and that is genuinely inconvenient rather than secretly fine.