The dark web is a criminal infested section of the internet thats inaccessible with conventional search engines. It can only be accessed with an anonymising browser called Tor.
One common misconception is the confusion between the dark web and the deep web.
The dark web makes up a small part of the deep which, the part of the Internet that is not indexed by search engines.
Before we dive into the details of Tor, how to access the dark web and whether it is safe, let's set the groundwork by understanding the differences between the surface web, deep web and dark web.
The surface web is the portion of the World Wide Web readily accessible and searchable by standard web search engines.
It is the opposite of the deep web, which is the part of the Internet not indexed.
Web indexing is best explained through search engines like Google, Bing or Yahoo and their high-performance system of indexing.
Search engines work by collecting, parsing and storing data about the pages they visit, enabling every day people fast and accurate information retrieval.
When you type "UpGuard" into Google and click on upguard.com, you are searching Google's index of the web, not the entire web.
Google's index is built on the back of a process called crawling. Google engineers write software called a crawler that clicks on every link on a page, follows the link, and then clicks on all the links on the new page ad infinitum.
While this process happens, they save or "index" each URL to their servers, so they can serve it up to you as part of their search engine results.
This is what allows you to ask Google questions or search UpGuard rather than typing in our URL.
Without indexing, the only way to access a site is to type in the URL or click a link.
To most of us, Google is synonymous with searching the Internet but in reality Google's index is a small part of the web, known as the surface web.
In contrast, the deep web is estimated to be anywhere from 400 to 5000 times larger than the surface web.
The deep web, invisible web or hidden web is the part of the World Wide Web not indexed by search engines.
Content is often hidden by HTTP forms, including email, online banking, private or otherwise restricted social media profiles, web forums that require registration or services that need authentication like Netflix.
Contents on the deep web can be located and accessed by direct URL or IP address but may still require a password or other form of authentication to access.
In general, contents on the deep web is there for one of two reasons:
Obscurity and authentication have advantages and disadvantages.
Obscurity is simple to implement but does not secure assets, they're accessible with the right URL, a massive cyber security risk that often results in data leaks.
Authentication is better at preventing unauthorized access but can be complex to implement and vulnerabilities, cyber threats and cyber attacks could expose what's hidden and result in data breaches.
Darknet is an umbrella term to describe parts of the Internet not open to the public or hidden networks superimposed on the Internet. Think of each darknet as a subsection of the overall dark web.
Some examples of darknets include:
Decentralized friend-to-friend network built using virtual private networks (VPNs) and software BGP routers.
Decentralized peer-to-peer network built using VPNs and software/hardware BGP routers. It does not try to establish anonymity for participants and is used to explore routing technologies used on the Internet.
Peer-to-peer platform for censorship-resistance communication. It uses a decentralized distributed data store to keep and deliver information and has a suite of free software for publishing and communicating without fear of censorship.
Software framework for decentralized, peer-to-peer networking that offers link encryption, peer discovery, resource allocation and communication over many transports (such as TCP, UDP, HTTP, HTTPS, WLAN and Bluetooth).
Anonymous network layer designed for censorship-resistant, peer-to-peer communication. Anonymous connections are achieved by encrypting user traffic and sending it through a volunteer-run network of roughly 55,000 computers distributed around the world. Given the high number of possible paths the traffic can transit, third-party surveillance is unlikely.
Privacy-preserving peer-to-peer client design to protect user privacy when sharing data.
Free open-source peer-to-peer communication and file sharing app built on GNU Privacy Guard (GPG).
Anonymity network develop at MIT as a response to issues with the Tor browser. It employs verifiable shuffle and is said to be ten times faster than onion-based networks like Tor.
Open-source software design to syndicate data over a variety of anonymous and non-anonymous computer networks. It can also reach archives situated in I2P, Tor and Freenet.
Free open-source software for anonymous communication. Tor directs traffic through a worldwide volunteer overlay network that consists of more than seven thousand relays that conceal a user's location and usage from anyone conducting network surveillance or traffic analysis.
Open-source decentralized BitTorrent client that allows anonymous peer-to-peer by default.
A decentralized web-like network of peer-to-peer users. Instead of having an IP address, sites are identified by a public key (specially a Bitcoin address). The private key allows the owner of the site to sign and publish changes which propagate through the network. ZeroNet also uses trackers from the BitTorrent network to negotiate connections between peers. It is not anonymous by default but supports routing traffic through Tor.
The dark web is the part of the World Wide Web only accessible through darknets.
Darknets can be small peer-to-peer or friend-to-friend networks, as well as large networks like Tor and I2P operated by organizations and individuals.
The Tor network focuses on providing anonymous access to the Internet and I2P specializes in anonymous hosting of websites.
The identities and locations of users are anonymized through a layered encryption system, a traffic anonymization technique known as onion routing.
Dark web networks route user data through a large number of intermediate servers to protect the user's identity and provide anonymity. The transmitted information can only be decrypted by the subsequent node in the scheme which leads to the exit node.
This system makes it near impossible to reproduce a node path because you must decrypt layer by layer, leading to users of the dark web referring to the surface web as the Clearnet due to its unencrypted nature.
Due to the dark web's encryption, websites cannot track geolocation or IP address of users. Nor can users get this information about website hosts.
This allows users to talk, blog, transact and share files confidentially.
This has led to the dark web becoming a hotbed for nefarious criminal activity, as well as harmless content like complex cryptography puzzles or cat videos you'd find on the surface web.
Researchers at King's College in London finding that 57% of 2,723 live dark web sites hosted illegal content.
This illegal content could include:
Sensitive data like credit card numbers or online banking details, data breaches, data leaks, personally identifiable information (PII) like Social Security Numbers, or hacked Netflix, Spotify or PayPal accounts.
Illegal and prescription drugs, counterfeit goods, counterfeit money, fake passports, fake degrees and stolen goods are sold for cryptocurrency on the dark web on sites like the Silk Road, the dark web's Amazon, which was founded by Ross Ulbricht.
Child pornography, hitmen for hire, gore, human traffic, body parts, poison, guns and other black market activity.
Dark web gambling sites often sell tickets in bitcoin lotteries that may or may not be real.
There are real and fake sites used by ISIL, ISIS and other terrorist groups.
Many hackers sell their services either individually or as part of groups.
In short, like the surface web, you can buy almost anything you can imagine on the dark web. You can probably buy things you would never want to too.
But it's not all illegal content. The dark web can also be used for good. Freedom fighters avoiding mass surveillance of an oppressive political regime may opt to use Tor to protect their identities.
Like most things, it depends. Here are some cybersecurity issues you should consider:
The in-built anonymity of the dark web has led to many different groups of people using for illegal activity, cybercrime and other hidden services such as the trade of firearms, forums for pedophiles and terrorists, as well as law enforcement agencies like the FBI or NSA.
That said, it also provides protection for whistleblowers, journalists, political protesters, anti-censorship advocacy groups, residents of oppressive political regimes and news organizations who need to communicate anonymously due to fear of negative repercussions.
Accessing the dark web is easier than you might think. All you need to do is download a dark web browser like Tor browser. Once installed, it functions like a regular browser: you stype in a URL and you are taken to a website.
That said, finding web pages on the dark net isn't as easy as finding them on the surface web. There is no Google for the dark web, by definition it isn't indexable.
There are places that aggregate links to dark web websites like The Hidden Wiki, but they are not as sophisticated as traditional search engines and often link to the underbelly of the Internet like sites that hijack your webcam, install malware, attempt phishing scams or other cybersecurity concerns.
Tor is free, open-source software designed for anonymous communication. The name Tor is derived from the original project's name "The Onion Routing Project".
Which was developed by Roger Dingledine and Nick Mathewson and launched on September 20, 2002. Today, Tor is run by a non-profit organization The Tor Project, Inc. which was founded by Dingledine, Mathewson and five others.
Tor anonymizes traffic by pushing it through a free, worldwide volunteer overlay network that consists of thousands of relays that conceal location and usage from mass network surveillance or traffic analysis.
The Tor Project has a free browser that connects to Tor called the Tor browser. The Tor browser makes it difficult to trace your Internet activity including:
The intention is to protection personal privacy of individuals and promote freedom of speech and the ability to conduct confidential communication without being monitored.
One thing to note is Tor cannot prevent online services from knowing they are being accessed through Tor. Tor's main concern is user privacy, not hiding the fact the user is using Tor.
This had led to some services restricting functionality to Tor users. For example, Wikipedia blocks edit attempts from Tor users unless special permission is requested.
Onion routing is the form of encryption used by Tor.
It encrypts the application layer of a communication protocol stack and got its name due to its nested nature akin to the layers of an onion.
While Tor may be a pain for law enforcement around the world today, it was initially funded and developed in the 90s by researchers Paul Syverson, Michael G. Reed and David Goldschlag at the United States Naval Research Laboratory.
Onion routing encrypts data, including the next node destination IP address multiple times by sending it through a virtual circuit of successive, randomly selected relays.
Each relay decrypts a layer of encryption to reveal the next relay in the circuit and passes the remaining encrypted data on.
The final relay decrypts the innermost layer and sends the original data to its destination without revealing or knowing the source IP address.
The routing of communication is partly concealed at every relay, eliminating any single point at which communicating peers could be determine with network surveillance that relies on knowing source and destination.
Like all low-latency anonymity networks, Tor is not perfect. It cannot and does not attempt to protect against monitoring traffic at the boundaries of the Tor network (traffic entering and exiting). Nor can it prevent traffic confirmation (end-to-end correlation).
Tor is susceptible to the following cyber attacks:
UpGuard can protect your business from data breaches, identify all of your data leaks, and help you efficiently manage vendor security risks with its risk remediation software.