Inspired by a post I came across earlier this week
I’m putting together a directory and knowledgebase on rooted[dot]wtf --- no CDNs, no JavaScript (duh!)
⚠️Rooted Onionspace⚠️
Why? Because most directories out there have terrible UX and rarely get updated. For example many still list exchanges like Xchange
Directories might hand you a rod, but they never teach you how to fish.🐟
I’m planning to include beginner-friendly OPSEC guides and best practices. The goal is to provide users with practical knowledge, instead of just links.
hopefully it’ll be a resource that actually helps people navigate the space safely
feedback would be greatly appreciated!
General
Rooted -- Discover. Learn. Stay Private. Building yet another directory and knowledgebase.
Started by RootedWTF · May 7, 2025
I like the design but I feel I've seen it somewhere before. My main concern here is that you're using a completely normal American server host. You aren't using a CDN to hide your operations at all. I read the AUP and ToS of your server host and they basically completely prohibit what you're trying to do. If you need some good reliable DDoS protected server host recommendations I can provide you with some.
Now here's some less important things. I don't see any way to manually PGP verify the links on the site so I would change that. Providing the public keys for each site would be nice for ease of access. I realize though you could easily change them at any time so the security of this is questionable. If the idea of the directory is on guides then I think you should actually have some guides and make the guides part a main focus instead of links. You can copy guides from other people and format them properly for your website if you don't have time to write them yourself.
Now here's some less important things. I don't see any way to manually PGP verify the links on the site so I would change that. Providing the public keys for each site would be nice for ease of access. I realize though you could easily change them at any time so the security of this is questionable. If the idea of the directory is on guides then I think you should actually have some guides and make the guides part a main focus instead of links. You can copy guides from other people and format them properly for your website if you don't have time to write them yourself.
Love the UI. Missing core features like PGP verification and such. Please add that ASAP.
I opted not to use a CDN to avoid the phishing warnings that we now see on tforum and fail. If you use a CDN, don't you share your information with the CDN provider in order to access the site? The provider I am using is from my directory. I would appreciate your recommendations!
I do plan on providing the public keys and a way of verifying the links. Regarding being able to easily change the links, that is true. The idea I had was to make it immutable, either by hosting it on IPFS or Arweave with eth[dot]limo. Wouldn't this setup address your main concern while providing immutability?
The idea is to focus on practical OPSEC knowledge and guides while also providing verifiable, reliable links. These links complement the guides and knowledge base ---- for example: someone wanting to know how to securely communicate using PGP and Protonmail would find both the guide and verified links to these services. I completely agree on making the guides the main focus point. I just need to get around to making them. It is planned.
First I want to address the concern you raised. do you think my proposed solution for immutability and content delivery is reasonable or not? I have not seen other directories take this approach, though I could be wrong.
I do plan on providing the public keys and a way of verifying the links. Regarding being able to easily change the links, that is true. The idea I had was to make it immutable, either by hosting it on IPFS or Arweave with eth[dot]limo. Wouldn't this setup address your main concern while providing immutability?
The idea is to focus on practical OPSEC knowledge and guides while also providing verifiable, reliable links. These links complement the guides and knowledge base ---- for example: someone wanting to know how to securely communicate using PGP and Protonmail would find both the guide and verified links to these services. I completely agree on making the guides the main focus point. I just need to get around to making them. It is planned.
First I want to address the concern you raised. do you think my proposed solution for immutability and content delivery is reasonable or not? I have not seen other directories take this approach, though I could be wrong.
Thank you. Appreciate the feedback! PGP verification should be done soon. I'm working on it.
I'm first addressing the immutability concern raised by root.
I'm first addressing the immutability concern raised by root.
IPFS relies on special software or clearnet reverse proxies. The content on IPFS is immutable but requires special software and a special address. The clearnet reverse proxies can just censor you normally. If you need special software and a special address why not just use Tor? You don't need to use a CDN if your host is good but it hides who your host is which can help. There are much better options than Cloudflare, DDoS Guard, or Bunny that don't care at all about what you do. As for your chosen host I don't know who it is but they're using a US EGI Hosting IP address.
I opted not to use a CDN to avoid the phishing warnings that we now see on tforum and fail. If you use a CDN, don't you share your information with the CDN provider in order to access the site? The provider I am using is from my directory. I would appreciate your recommendations!
The phishing warnings can happen if you use CDN or not. Safebrowsing, DNS, Antivirus can all block your domains on the same ground. Tor taxi had to move to ddosguard it seems which makes no difference because they don't give a fuck about you any more or less than cloudflare will. You are better off having a CDN because your IP is completely exposed and not only will people ddos it out of boredom, this completely makes it trivial for law enforcement to get your server and start serving legal papers for your shit. Also your hosting provider can ignore shit if they don't "know" you are on their network doing this shit but if they can easily see it attributed to their own ip space they'll drop you.
If you are so worried then keep the directory on tor and you resolve all the problems.
I am not worried. I know using Tor exclusively is ideal but accessing via clearnet is important because it is easier to remember for initial access.
This risk has been mitigated, and the server has been moved to another jurisdiction.
This risk has been mitigated, and the server has been moved to another jurisdiction.
This is a great directory. I suggest you add an I2P link section for hidden services that use I2P.