you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 0 min ago 255 onions tracked
home / news / tor network
11 March 2025 tor network 3 min read

HSDir Stress: Why Descriptor Churn Makes Onion Sites Flicker Offline

An onion service can be running perfectly and still be impossible to reach. When the relays that hold its descriptor come under load, the site flickers in and out of existence for clients while the operator sees nothing wrong on their end.

The phone book nobody sees

Every .onion address depends on hidden service directories, or HSDirs, a distributed hash table formed by relays carrying the HSDir flag. They store the signed descriptor that tells a client which introduction points to use. Without that document, the site effectively does not exist, no matter how healthy its backend is. By default, each service maintains two active descriptors across replica groups, landing on roughly six responsible HSDirs at any moment. As the Tor Project's own measurement work notes, there is always more than one relay to download from, which masks individual failures until several of them coincide (Tor Project). For background on how this fits into connection setup, see our guide to how onion services work.

A clockwork of republishing

The rendezvous specification keeps descriptors deliberately short-lived. Services set a descriptor lifetime of 180 minutes and arm a random timer between 60 and 120 minutes after each upload, then republish to the currently responsible HSDirs when it fires (Tor Rendezvous Specification). Descriptors also rotate wholesale once per time period, normally 24 hours, because the blinded key and the ring position change together. Services must upload ahead of each new period while still refreshing the old one, so two documents stay alive at all times. Miss a cycle, and a slice of clients simply finds nothing.

What overload does to the ring

Stress breaks this clockwork in unglamorous ways. Uploads over congested circuits fail or arrive late, so some of the six copies expire while others survive. Clients fetching from different positions in the hash table get different answers, which looks exactly like a site going up and down. Researchers have shown the failure mode can be forced deliberately. The HSDirSniper attack demonstrated that flooding a directory's descriptor cache with junk volumes can push it to purge stored descriptors entirely, blocking arbitrary target services (ACM Digital Forensic Security 2024). Real campaigns have reached that scale. Describing seven months of denial-of-service activity, the Tor Project wrote:
"At some points, the attacks impacted the network severely enough that users could not load pages or access onion services."
(Tor Project blog)

Why flickering is close to normal

Independent measurements put hard numbers on the churn. A six-month study running six HSDir relays found that fewer than half of observed onions were still reachable 24 hours after publication, and around 30 percent were never connectable at all (Digital Investigation, 2018). Some of that is genuinely abandoned services, but much of it is timing and placement luck. Under load, the usual suspects repeat:
  • Uploads that never land, leaving one replica group empty.
  • Lifetime expiry, when republish timers slip past the 180-minute window.
  • Relays losing the HSDir flag mid-period, shifting ring positions.
  • Cache pressure or attacks that evict otherwise valid descriptors.

Reading an outage correctly

The practical takeaway is that descriptor absence proves nothing about your web stack. Before rebuilding anything, query the directories directly through a status checker and watch tor logs for successful HS_DESC uploads. If uploads succeed intermittently, you are watching network-level stress rather than a local fault. Operators under sustained load should also layer application-side defenses such as proof-of-work prioritization, which the Tor Project documents for introduction-point flooding (onion service DoS guidelines). Flicker caused by directory churn will not respond to bigger servers. It responds only to patience, redundancy, and keeping those republish cycles clean.

more notes

all news ›