If you’ve got a bookmark ending in sixteen characters and .onion, it died in October 2021. The site wasn’t necessarily taken down and it isn’t blocked. That whole category of address was removed from the network, and nothing you do to your browser will bring it back.
Years later this is still one of the more common reasons someone ends up reading a site like this. Their bookmarks stopped working, they went hunting for replacements, and what they found was worse than what they’d lost.
Which kind have you got?
Count the characters before .onion.
Sixteen means v2. Dead since 2021.
Fifty-six means v3. Current, and the only kind that works.
That’s the whole test. There’s no conversion, and no lookup table mapping old addresses to new ones, because the address comes from the service’s own cryptographic key. A site that migrated got an entirely new address bearing no mathematical relationship to its old one. Nobody can reconstruct one from the other. Not the Tor Project, not the site operator, nobody.
What happened, and when
Sixteen months of notice, which is generous as deprecations go.
- July 2020. Timeline announced.
- September 2020. Tor starts warning operators and clients that v2 is on the way out.
- June 2021. Tor Browser starts warning ordinary users.
- July 2021. Tor 0.4.6 lands. No new v2 services can be created, and support comes out of the codebase.
- October 2021. Stable releases disable it outright. From then on the addresses simply don’t resolve.
Plenty of sites migrated and told people. Plenty didn’t, and as far as anyone holding an old bookmark was concerned they just evaporated.
Why
Not fashion. Three specific problems, all of which had been getting worse for years.
The cryptography was old. V2 leaned on SHA-1 and 1024-bit RSA. Both had drifted from acceptable, through uncomfortable, to indefensible over the fifteen years the design had been in service.
The address was too short. Sixteen characters encodes a small enough fingerprint that generating a partial collision was within reach of anyone with real resources.
Services could be enumerated. This was the serious one. Because of the way v2 published service information into the network directory, a relay sitting in the right position could harvest addresses of services it had never been told about. A design meant to hide sites was leaking a list of them.
V3 deals with all three. Modern elliptic curve cryptography, a longer address that’s a full public key rather than a truncated fingerprint, and a directory design that stops handing out an inventory of what exists. The onion services documentation goes into the mechanics if you want them.
The part nobody planned for
Here’s the consequence that actually mattered, and it doesn’t get discussed much.
Overnight, every link directory, forum post, bookmark file and article written before 2021 became worthless. Years of accumulated references, all pointing at addresses that no longer resolved.
Which created enormous, sustained demand for updated lists. Thousands of people every day looking for the new address of something they used to be able to reach.
People wanting a replacement address, with no way to check what they’re handed, is about as close to a perfect market for fraud as you could design deliberately. It got filled accordingly. The wave of directories offering fresh, verified, updated links that appeared after 2021 wasn’t a community rebuilding what it lost. A good deal of it was people who understood precisely what that demand was worth.
The retirement was the right call on security grounds and I’d defend it. It’s also the single biggest cause of the phishing problem that followed, and saying otherwise would be dishonest.
If your bookmarks are dead
One rule, unchanged.
Get the new address from the organisation itself, on the ordinary web, over an encrypted connection. A newspaper publishes its onion address on its own site. A software project publishes its own. An email provider publishes theirs.
Don’t take a replacement from a directory, a forum post, a search result, or anyone who volunteers one. You have no way to check it, and whoever’s offering knows that perfectly well.
If an organisation hasn’t published a v3 address anywhere you can verify, the right conclusion is that you can’t safely reach them — not that you should trust the first address somebody offers.
Next
What an onion service is explains why the address is the key, which is what makes migration impossible and verification unavoidable.