EMZETT.
Login

Darknet

In short: A part of the internet that can only be reached via special software (e.g. Tor) and anonymises users as well as server locations through multiple layers of encryption and rerouting.

In more detail: In the best-known darknet, the Tor network, traffic is routed via several randomly chosen nodes (relays) and encrypted several times over in the process (onion routing) — each node only knows the previous and next step, not the entire route. The darknet itself is technology-neutral (anonymisation), but is often associated in the media with illegal marketplaces. It’s also used by journalists, activists and people in authoritarian states to get around censorship.

In Depth

With onion routing (the namesake of “Tor” = “The Onion Router”), a message is wrapped in several layers of encryption, similar to the layers of an onion:

Client -> [guard node] -> [middle node] -> [exit node] -> target server

The message is encrypted 3 times (for exit, middle, guard).
Each node only removes ITS outermost layer and passes on the rest:

Guard node:  removes layer 1, knows the sender + next node (not the destination)
Middle node: removes layer 2, only knows the previous + next node
Exit node:   removes layer 3, knows the destination (not the original sender)

This construction is crucial: no single node knows both the sender AND the destination at the same time — only if an attacker controls both the guard and the exit node of the same connection (so-called correlation attacks) can the anonymity theoretically be broken. That’s why the route is changed regularly and distributed across several independently operated relays.

In terms of terminology, “darknet” is often confused with the “deep web”, but means something else: the deep web simply comprises all content not indexed by search engines (e.g. content behind a login, private cloud storage) — that’s by far the largest part of the internet and completely everyday. The darknet, on the other hand, is technically separate: it requires special software (Tor Browser) and uses its own address formats (.onion domains), which can’t be resolved at all on the normal internet.

Origins and legitimate use

The Tor network was originally developed in the mid-1990s by the US Naval Research Laboratory to protect the communication of intelligence personnel, and was later released as an open-source project. The paradoxical consequence: the more different user groups (military, activists, journalists, but also criminals) use the same network, the better the anonymity for everyone — a network used by only a single user group would already allow conclusions about identity from its mere use. Reporters Without Borders and other organisations run their own .onion mirrors of their websites so that people in countries with strict internet censorship (e.g. behind China’s “Great Firewall”) get uncensored access to news.

Onion services (formerly “hidden services”)

Besides anonymous browsing of the normal web, Tor also enables so-called onion services: websites that are themselves only reachable via the Tor network and whose SERVER LOCATION also remains hidden (not only the user but also the operator is anonymous). This works via a “rendezvous point” procedure, in which client and onion service meet via a randomly chosen intermediate node without either of the two directly learning the other’s IP address.

Well-known incidents and law enforcement

The darknet became known in the media above all through marketplaces such as Silk Road (2011-2013, the largest drug marketplace, shut down by the FBI), which combined cryptocurrencies for seemingly anonymous payments with Tor for anonymous access. But such marketplaces also showed the limits of anonymity: law enforcement agencies often identified operators not by breaking Tor’s encryption itself, but through mistakes outside the anonymisation network (e.g. reusing a real name in an early forum post, or analysing blockchain transaction patterns in supposedly anonymous cryptocurrency payments).

See also: VPN