OnionShare

{{Short description|A file sharing application over tor network}}

{{Infobox software

| title =

| name =

| logo = Onionshare-logo.png

| logo caption =

| logo alt =

| logo size =

| collapsible =

| screenshot =

| screenshot size =

| screenshot alt =

| caption =

| other_names =

| author =

| developer = Micah Lee, et al.

| released =

| ver layout =

| discontinued =

| latest release version = {{wikidata|property|preferred|references|edit|P348|P548=Q2804309}}

| latest release date = {{Start date and age|{{wikidata|qualifier|preferred|single|P348|P548=Q2804309|P577}}|df=yes}}

| latest preview version =

| latest preview date =

| repo = {{URL|https://github.com/onionshare/onionshare/}}

| qid =

| programming language = Python

| middleware = Tor

| engine =

| operating system = Linux, macOS, Windows, iOS, Androidhttps://onionshare.org/mobile/

| platform =

| included with =

| replaces =

| replaced_by =

| service_name =

| size =

| standard =

| language count = 68{{cite web | url=https://github.com/onionshare/onionshare/tree/main/desktop/onionshare/resources/locale | title=Onionshare/Desktop/Onionshare/Resources/Locale at main · onionshare/Onionshare | website=GitHub }}

| language footnote =

| genre =

| license = GPLv3

| website = {{URL|https://onionshare.org/}}

| AsOf =

| games list =

}}

{{Portal|Free software}}

OnionShare is an open source file sharing application using tor network to share files, available on most major platforms. It also lets users host websites and chat in a secure and anonymous manner. It uses peer-to-peer sharing over Tor network to preserve privacy and anonymity.{{Cite magazine |last=Higgins |first=Parker |title=The Troubling Truth of Why It's Still So Hard to Share Files Directly |language=en-US |magazine=Wired |url=https://www.wired.com/2014/06/the-troubling-truth-of-why-its-still-so-hard-to-share-files-directly/ |access-date=2022-07-05 |issn=1059-1028}}{{Cite web |last=Legrand |first=David |date=2020-04-02 |title=OnionShare : partager des fichiers ou publier un site via Tor |url=https://www.nextinpact.com/article/30164/107562-onionshare-partager-fichiers-ou-publier-site-via-tor |access-date=2022-07-05 |website=www.nextinpact.com |language=fr}}{{Cite book |last=Hassan |first=Nihad Ahmad |url=https://www.worldcat.org/oclc/958455645 |title=Data hiding techniques in Windows OS : a practical approach to investigation and defense |date=2016 |publisher=Syngress |others=Rami Hijazi, Helvi Salminen |isbn=978-0-12-804496-4 |location=Cambridge, MA |oclc=958455645}}{{Cite web |title=Share Files Securely Over Tor Network With OnionShare |url=https://itsfoss.com/onionshare/ |access-date=2022-07-20 |website= itsfoss.com |date=24 August 2020 |language=en-US}}

Features

Its main features are:{{Cite news |title=Simple Online Security: Sending Messages and Files Safely |language=en-US |work=The New York Times |date=22 April 2022 |url=https://www.nytimes.com/wirecutter/guides/online-security-secure-messaging-apps/ |access-date=2022-07-05 |issn=0362-4331}}{{Cite web |date=2017-01-05 |title=How To Share Files Anonymously Using Tor's Darknet And OnionShare? |url=https://fossbytes.com/share-files-anonymouslytors-darknet-onionshare/ |access-date=2022-07-05 |website=Fossbytes |language=en-US}}

  • Sending and receiving large files peer-to-peer over tor network.
  • Chat ephemerally.
  • Host a website.

The distinguishing feature of OnionShare is that users can do these things while maintaining anonymity. So, sensitive document sharing and whistleblowing is a prime target audience of the app.{{Cite web |date=2014-06-27 |title=Meet Onionshare, the File Sharing App the Next Snowden Will Use |url=https://gizmodo.com/meet-onionshare-the-file-sharing-app-the-next-snowden-1597056567 |access-date=2022-09-10 |website=Gizmodo |language=en-us}}

= Sending files =

Sending large files over the internet is a hassle without centralized servers.{{Cite magazine |last=Greenberg |first=Andy |title=Free App Lets the Next Snowden Send Big Files Securely and Anonymously |url=https://www.wired.com/2014/05/onionshare/ |magazine=Wired |language=en-US |issn=1059-1028 |access-date=2022-07-05}} OnionShare made it easier to share files because of its peer-to-peer nature. This also circumvented surveillance, possible because of centralized services. The circumvention is allowed by hosting shared files on tor network.{{Cite web |title=Golem.de: IT-News für Profis |url=https://www.golem.de/sonstiges/zustimmung/auswahl.html?from=https%3A%2F%2Fwww.golem.de%2Fnews%2Fonionshare-einfach-anonym-dateien-teilen-2105-156215.html |access-date=2022-07-05 |website=www.golem.de}}

= Hosting websites =

OnionShare allows hosting static websites without JavaScript from the app. This feature became available as of version 2.2. These sites can be visited by any browser that supports .onion sites, such as Tor Browser.

= Usage =

OnionShare is most notably aimed at being used for sharing sensitive files and whistleblowing.{{Cite book |last1=Hassan |first1=Nihad A. |url=http://link.springer.com/10.1007/978-1-4842-2799-2 |title=Digital Privacy and Security Using Windows |last2=Hijazi |first2=Rami |date=2017 |publisher=Apress |isbn=978-1-4842-2798-5 |location=Berkeley, CA |language=en |doi=10.1007/978-1-4842-2799-2|s2cid=12194324 }}

History

OnionShare was released in 2014. Its initial release was hampered by RIAA and MPAA who wanted to limit peer-to-peer file sharing solutions. Lobby group such as RIAA and MPAA actively lobbied against peer-to-peer protocols and software that they had a hard time finding investment and development, hence why it took so long to release such a tool.

In February 2019, OnionShare 2 was released. It came with macOS sandbox enabled by default, support for v3 onion services, translations etc. The .onion addresses were ephemeral by default, as always.{{Cite web |last=R |first=Bhagyashree |date=2019-02-21 |title=OnionShare 2, an open source tool that uses Tor onion services for securely sharing files, is now out! |url=https://hub.packtpub.com/onionshare-2-an-open-source-tool-that-uses-tor-onion-services-for-securely-sharing-files-is-now-out/ |access-date=2022-07-05 |website=Packt Hub |language=en-US}}

In October 2021, OnionShare patched two low risk vulnerabilities which were uncovered in a security advisory by IHTeam.{{Cite web |date=2021-10-05 |title=OnionShare: Secure communications platform used by whistleblowers and journalists patches data exposure bug |url=https://portswigger.net/daily-swig/onionshare-secure-communications-platform-used-by-whistleblowers-and-journalists-patches-data-exposure-bug |access-date=2022-07-05 |website=The Daily Swig {{!}} Cybersecurity news and views |language=en}}

In December 2021, Radically Open Security published their penetration report of the audit conducted on OnionShare.{{Cite web |title=Golem.de: IT-News für Profis |url=https://www.golem.de/sonstiges/zustimmung/auswahl.html?from=https%3A%2F%2Fwww.golem.de%2Fnews%2Fonionshare-shield-tv-c-its-schnelles-internet-fuer-die-iss-2201-162480.html |access-date=2023-07-27 |website=www.golem.de}}{{Cite web |title=2021 Penetration Test Report.pdf |url=https://raw.githubusercontent.com/onionshare/onionshare/develop/security/2021%20Penetration%20Test%20Report.pdf}} It was financed by Open Tech Fund and targeted version 1.1. The most impactful vulnerability found allowed to render arbitrary HTML inside the desktop application and a denial-of-service attack based on previously undisclosed Qt image parsing. 2 elevated, 4 low and 3 moderate severity issues were found. All issues were resolved before publication of the report.

References

{{Ref-list}}