The Single-Hop Onion Service Debate: Speed Versus Protection
Every onion service is designed to hide both parties, not just the visitor. A single configuration flag can quietly drop the server side of that promise. Single-hop mode is Tor's official compromise between circuit speed and server anonymity, and it remains one of the network's most misunderstood options.
What one hop actually removes
A standard onion connection stitches together two three-hop circuits, one built by the client and one by the service, joined at a rendezvous point. Six relays stand between the two ends. That redundancy is exactly why connections feel sluggish compared with the clearnet. Single onion services keep the client's circuit untouched but replace the server-side paths with direct, one-hop circuits to the introduction and rendezvous points. The total path shrinks from six hops to four. Connection setup gets faster, streams feel snappier, and the service consumes far less relay capacity. Crucially, the cryptography itself does not weaken. The .onion address still proves the server controls the private key, and traffic remains encrypted end to end. As the rendezvous single onion specification notes, clients cannot even tell whether they are talking to a single or double onion service unless the site tells them.Why the speed argument is real
The performance case is documented, not hypothetical. Proposal 252, which sketched the original design, lists much lower connection latency, reduced stream latency, and improved scalability as core motivations. Skipping rendezvous circuits also frees busy sites from building and rebuilding long paths for every visitor. Measurements back this up. In a 2020 academic study of exit-blocking circumvention, researchers found that running a bridge as a single onion service added a median of just 0.08 seconds of latency, versus 0.25 seconds for a conventional hidden service. For interactive applications, that difference is plainly user-visible. That finding comes from the HebTor paper, and it captures the appeal. Operators whose servers were never meant to be location-hidden anyway face a fair question: why pay an anonymity tax when the address behind the service is already public knowledge?What the service gives up
"Single onion services are a modified form of onion services, which trade service-side location privacy for improved performance, reliability, and scalability." - Tor Proposal 252The trade is blunt. The operator's IP address becomes directly visible to introduction points, rendezvous points, and anyone observing the network around the server. One compromised or hostile relay in those positions learns exactly where the site lives. For whistleblower platforms or anything facing takedown pressure, that alone is disqualifying. Visitors lose something subtler too. Single onions produce distinctive four-hop paths, so traffic analysis can statistically distinguish visits to them, thinning the cover that protects everyone else. The proposal authors themselves warned that each additional flavour of onion service splits the anonymity set shielding ordinary hidden services.
- The server's real IP address is exposed to intro and rendezvous relays
- Four-hop paths can be fingerprinted, shrinking the shared anonymity pool
- Clients have no way to verify which mode a service is running
- A simple config mistake silently turns an anonymous service public