Credentials read by a gateway
Ranks lower because fewer people use one, and it is worth its own entry because the exposure is total and nobody has to be dishonest for it to happen.
- How often
- Uncommon
- Typical size
- The account and its balance
- Recoverable
- Sometimes
- Cost to prevent
- A few minutes, once
How they work
A gateway lets you open an onion address in an ordinary browser, usually by appending a suffix. Underneath, the operator makes the connection themselves, fetches the page, and forwards it to you.
Everything therefore passes through their machine in a form they can read. Usernames, passwords, second factor codes, messages, destinations. Not encrypted end to end to the market.
What else it costs
- Anonymity from the destination. The connection arrives from the gateway, so the protection is protecting them.
- Anonymity from your own network. You visited an ordinary clearnet domain, which is visible in ways an onion connection is not.
- The ability to verify anything. The page reached you via a party who could change it, so you would be checking whatever they chose to show.
- Knowing where you went. The gateway resolved the address, and you are trusting it to have gone where you asked.
The lookalikes
Domains closely resembling the market name, marketed as an easy way in. These are usually not gateways at all, because if the goal is collecting credentials there is no reason to build the proxying part. The tell is that they want you to log in, and a real gateway has no interest in whether you do. Anything on the clearnet asking for market credentials is collecting them.
The alternative
Tor Browser from the project directly, with the installer signature checked, at the highest security setting. A few minutes once, and every item on this page disappears. People use gateways because installing a browser is an obstacle, and the obstacle was carrying the protection.
Why people end up on one
Almost always because installing a browser was inconvenient at that moment: a work machine, a phone, a borrowed computer, or a policy that blocks the install. The gateway removes a real obstacle, and the obstacle was doing the work. That is worth stating without sneering, because the reasons are practical rather than careless, and telling somebody they should have known better does not help them.
What each party can see
| Party | With a gateway | Without one |
|---|---|---|
| The gateway operator | Everything you send and receive | Does not exist |
| Your network or provider | That you visited a clearnet domain associated with this | That you used Tor, and nothing about where |
| The destination | A connection from the gateway | A connection with no origin information |
| Anybody watching the domain | Your address and your timing | Nothing to watch |
If you already used one
Treat the credentials as read and change them from a proper connection, along with anything reused elsewhere. Assume the messages you sent through it were read. Nothing further is recoverable and nothing worse is coming from the fact alone, so the useful response is a password change and a browser install rather than alarm.