Start with a clean Debian 12 VPS provisioned with anonymous payment and pseudonymous email. Apply immediate hardening before any service configuration: disable password SSH login, set up key-based authentication only, update all packages, and enable automatic security updates. These baseline hardening steps prevent compromise before the hidden service configuration is complete.
apt update && apt upgrade -y apt install -y unattended-upgrades apt-listchanges dpkg-reconfigure --priority=low unattended-upgrades sed -i 's/#PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config systemctl restart ssh
Install Tor from the official Tor Project repository rather than Debian default mirrors to ensure you have current security patches:
echo "deb [signed-by=/usr/share/keyrings/tor-archive-keyring.gpg] https://deb.torproject.org/torproject.org bookworm main" > /etc/apt/sources.list.d/tor.list wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor > /usr/share/keyrings/tor-archive-keyring.gpg apt update && apt install -y tor deb.torproject.org-keyring nginx