Why nine and not one
New readers read a long list as hedging. It is the opposite: a single address would be the fragile arrangement.
What actually breaks
Reaching a hidden service is a chain, and almost every link that fails is in the path rather than at the destination. The service can be running perfectly the whole time.
| Failure | Per address or per market? |
|---|---|
| Directory lookup fails | Per address. Resolves on its own, usually within the hour. |
| Meeting points drop out | Per address. Connections fail while replacements are chosen. |
| Flooding aimed at an address | Per address, and aimed at the ones that are most widely published. |
| Your own circuit is bad | Neither. It is your path, and a new circuit fixes it. |
| Network conditions | Everything at once, including unrelated onion services. |
| The market itself | Per market, and the least common of these. |
Four of the six are per address. That is why a set helps: the probability that all nine are affected by unrelated path problems at the same moment is far lower than for any one of them.
Why a permanent single address would be worse
- A stable address is a stable target. It can be flooded indefinitely with no way to move out of the way.
- It gets built into every copy permanently. Somebody building a convincing imitation around a fixed string never has to update anything.
- It accumulates junk. Scrapers, dead bookmarks and abandoned lists send more traffic to an old address every year, and none of it is people.
- It teaches the habit that gets people caught. Somebody who has typed the same string for two years stops looking at it.
What nine does not buy
Any assurance about authenticity. All nine could be listed correctly and a tenth could be circulating that resembles one of them, and the length of the list has no bearing on that at all. It also does not buy availability during a genuine market outage, because a shared backend fails for all of them together. The set is insurance against path problems and nothing else.