Anantam IASPost · 5 May 2026

Dark Web vs Deep Web: Surface Web, Tor, Onion Routing, and India’s Cyber Response

Study Notes · Science & Tech

A complete UPSC GS-III explainer on Dark Web vs Deep Web. Covers the three layers of the internet, onion routing, Tor and I2P, legality, and India's response through Kerala Cyberdome and CBI Operation Chakra.

The internet most people use every day is a thin shell. Behind the visible layer indexed by Google sits a much larger zone of password-protected pages, paywalled databases, and intranets that ordinary search engines never see. And tucked inside that larger zone is a tiny, intentionally hidden region that requires specialized software to reach. The three layers carry the names Surface Web, Deep Web, and Dark Web. In policy debates, the second and third are often confused. They are not the same thing.

For a UPSC aspirant, the topic sits at the intersection of internal security, cybercrime, and the regulatory limits of the modern state. The Dark Web is where ransomware operators sell stolen data, drug markets settle in cryptocurrency, and child sexual abuse material circulates beyond easy reach of law enforcement. The Deep Web, in contrast, is where your bank statement and your medical record live. Conflating the two leads to bad regulation. This article separates them, explains the technology that hides the Dark Web, and walks through India’s institutional response.

Quick Facts on Surface, Deep, and Dark Web

Iceberg of the Internet: Surface, Deep, and Dark Layers

The Surface Web is the part of the internet indexed by ordinary search engines like Google, Bing, and DuckDuckGo. Estimates put its share of total online content at roughly four percent. The Deep Web is everything not indexed, including private email inboxes, online banking dashboards, academic databases, and corporate intranets. It is by far the largest layer.

The Dark Web is a small subset of the Deep Web that has been deliberately hidden using anonymizing networks. The most widely used such network is Tor, short for The Onion Router. Other networks include I2P and Freenet. Access to the Dark Web is technically legal in India and most democracies. The actions taken on it, however, may not be.

What the Three Layers Actually Are

The Surface Web is what a search engine crawler can find by following hyperlinks. A page is on the Surface Web if a crawler can reach it without a password, without a paywall, and without a script that hides the content. Wikipedia, news sites, and most commercial homepages live here.

The Deep Web is everything else that is still on the ordinary internet but kept out of the index. Your Gmail inbox is on the Deep Web. So is your Netflix queue, your bank account dashboard, your employer’s intranet, and the academic journals behind a JSTOR subscription. The Deep Web is not sinister. It is simply the part of the internet that requires authentication, that lives behind a paywall, or that has been told through robots.txt to stay out of search results.

The Dark Web is the small, deliberately concealed portion of the Deep Web that requires specific software to reach. Its websites do not have ordinary domain names. They use addresses like a long string of characters ending in dot-onion. They cannot be opened in Chrome or Safari. The user must run Tor Browser, I2P, or a similar anonymizing client.

Background and Historical Context

Onion routing, the technology that powers the Dark Web, was invented in the mid-1990s by researchers at the United States Naval Research Laboratory. The original purpose was to protect United States intelligence communications by making it impossible to trace the source and destination of an internet message. The research was made public, the code was released as open source, and in 2002 the Tor Project was founded as a non-profit. Funding initially came from the United States government, with later support from the Electronic Frontier Foundation, private donors, and other sources.

By the late 2000s, Tor had attracted three very different user bases. Journalists and dissidents in authoritarian countries used it to evade surveillance. Cryptography enthusiasts and privacy advocates used it on principle. And criminals discovered that the same anonymity that protected a Chinese dissident also protected a drug dealer. The launch of Silk Road in 2011, the first large-scale Dark Web drug marketplace, marked the moment the Dark Web entered popular consciousness. Silk Road was shut down by the FBI in 2013, but successors emerged within months.

In India, awareness of the Dark Web as a policy issue grew through the late 2010s as ransomware attacks on hospitals, financial fraud, and the trade in stolen credentials began to be traced back to Dark Web markets. The link between internal security policy and cyber-anonymity tools became impossible to ignore.

How Onion Routing Works

The technology behind Tor is called onion routing because of the way it wraps a message in layers of encryption. When a Tor user requests a web page, the request is not sent directly to the destination server. It is wrapped in three layers of encryption and bounced through three randomly selected relay nodes before reaching the destination.

The first relay can see who the user is, but not what the user is requesting or where the request is going. The second relay can see neither end. The third relay, called the exit node, can see the destination but not the user. Each relay peels off one layer of encryption, like the layers of an onion, until the request reaches the exit node and is forwarded in plain form to the destination.

For Dark Web sites that end in dot-onion, the destination is itself inside the Tor network. There is no exit node and no plain-text emergence onto the regular internet. Both the user and the server are anonymous to each other. This double anonymity is what makes the Dark Web genuinely difficult to police.

Why Dark Web Matters for Policy

Access Mechanisms: Browser, Login, and Tor / I2P Compared

The Dark Web matters because it has become the operating environment for a significant share of organized cybercrime. Ransomware-as-a-service operators advertise on Dark Web forums and accept payment in cryptocurrency. Stolen credit card data, Aadhaar numbers, and corporate login credentials are sold on Dark Web markets within days of a major breach. Child sexual abuse material circulates on hidden services that have proven extremely difficult to take down. Weapons, narcotics, fake passports, and counterfeit currency are listed on Dark Web markets the way a regular product would be listed on a normal e-commerce site.

The Dark Web also matters as a legitimate tool. Investigative journalists use Tor to communicate with sources in repressive regimes. Whistleblowers use SecureDrop, a Tor-based platform, to leak documents to news organizations without revealing their identity. Citizens of countries with heavy internet censorship use Tor to read banned news.

A blanket ban on Tor would harm the second group without seriously inconveniencing the first. The criminal user already operates from a position of evasion. The dissident, the journalist, and the privacy-conscious ordinary user lose the tool they actually need.

Detailed Analysis of Threats and Vectors

The threats most relevant to India fall into a few categories. The first is data leakage. Major breaches of Indian companies and government databases have been followed within weeks by listings on Dark Web markets offering the leaked data for sale. The 2018 Aadhaar-related leaks, leaks from telecom operators, and breaches of e-commerce platforms have all surfaced on hidden marketplaces.

The second is ransomware logistics. Indian hospitals, municipalities, and corporates that have been hit by ransomware attacks typically receive a ransom note pointing to a dot-onion address for negotiation. Payment is demanded in Bitcoin or Monero. The attackers themselves often advertise on Dark Web forums for affiliates and initial-access brokers.

The third is narcotics. Indian law enforcement agencies, including the Narcotics Control Bureau, have arrested individuals running Dark Web drug operations targeting Indian customers. Synthetic drugs, prescription medication, and cannabis have all moved through these channels.

The fourth is hostile-state cyber operations. Tor and similar networks are used by some state-sponsored threat actors as a layer in their command-and-control infrastructure, intersecting with broader cyber security concerns and the regulatory limits captured in the internet shutdowns in India 2024 trend legal framework discussion.

Comparative Matrix: Surface vs Deep vs Dark

A clean comparison helps separate the three layers in revision.

FeatureSurface WebDeep WebDark Web
IndexingIndexed by Google, BingNot indexedNot indexed and hidden
AccessPublic, any browserLogin or paywall requiredTor, I2P, or similar required
Approximate shareRoughly 4 percentRoughly 90 percent or moreLess than 0.1 percent
Domain namesdot-com, dot-in, dot-orgSame as Surface Webdot-onion, dot-i2p
ExamplesWikipedia, YouTubeBanking, email, intranetsHidden markets, leak portals
Legality of access in IndiaLegalLegalLegal in itself

The legality column matters. Simply opening Tor Browser and visiting a hidden site is not a crime in India. Buying narcotics, downloading child sexual abuse material, or trading in stolen data is a crime regardless of which layer of the internet the act takes place on.

India’s Institutional Response

India's Dark Web Response: Cyberdome to Operation Chakra

India has built its Dark Web response in layers, mirroring the layered nature of the threat. The Kerala Cyberdome, set up by the Kerala Police, has acquired specialized capability in monitoring Dark Web forums for indicators of crimes targeting Indian residents, including child sexual abuse material and drug trafficking. It functions as a research-and-development arm of the police rather than a routine investigation unit, providing technical inputs to investigators across the country.

At the central level, the Central Bureau of Investigation launched Operation Chakra, a series of coordinated crackdowns on cyber-enabled financial crime networks, many of which used Dark Web infrastructure for laundering and communication. The operation moved through several phases between 2022 and 2024, leading to arrests, seizure of cryptocurrency wallets, and dismantling of call-centre fraud rings whose downstream payments routed through hidden services.

The Indian Computer Emergency Response Team coordinates technical response when an Indian organization is hit by a Dark-Web-routed ransomware attack. The Indian Cyber Crime Coordination Centre, popularly called I4C, runs the National Cybercrime Reporting Portal and coordinates investigative support across state police forces. The Ministry of Home Affairs has expanded the National Cyber Forensic Laboratory’s capability to handle dot-onion intelligence.

Challenges in Policing the Dark Web

The challenge is structural. Tor was designed to defeat traffic analysis, and it does so well enough that direct technical attack is rare and expensive. Most successful prosecutions of Dark Web operators globally have come not from breaking the Tor protocol but from operational mistakes by the operators, infiltration of forums by undercover investigators, and cooperation from informants.

For Indian agencies, the additional challenges are manpower, training, and cross-border cooperation. Dark Web investigations are technical and time-consuming. They typically require cooperation from foreign law enforcement, exchanges of evidence under mutual legal assistance treaties, and coordination with cryptocurrency exchanges that may sit outside Indian jurisdiction. The pace of mutual legal assistance is slow. The pace of crime is not.

A second challenge is legal. Indian law has yet to catch up with the realities of cryptocurrency, anonymous browsing, and cross-border data flows. Procedural codes were written for a world of physical premises and identifiable parties. The Bharatiya Nagarik Suraksha Sanhita and the Bharatiya Sakshya Adhiniyam, which replaced the older codes in 2024, have introduced provisions for electronic evidence, but the actual practice of seizing and admitting Dark Web evidence in court is still evolving.

A third challenge is the privacy paradox. Strong measures against the Dark Web, such as deep packet inspection at internet exchange points, would catch criminals but also normalize mass surveillance. The constitutional principles laid down in the Puttaswamy judgment of 2017 limit how far the state can go without triggering proportionality review. Striking the balance is the policy task of the next decade.

Prelims Pointers

Mains Practice Questions

  1. Distinguish the Surface Web, the Deep Web, and the Dark Web. Examine the technological architecture that enables anonymity on the Dark Web and discuss the policy challenges this poses for Indian law enforcement.
  1. Critically evaluate the institutional response of the Indian state to Dark Web enabled cybercrime, including the role of the Kerala Cyberdome, Operation Chakra, and the Indian Cyber Crime Coordination Centre. What gaps remain?
  1. The Dark Web is used both by criminals and by journalists, dissidents, and privacy-conscious citizens. Discuss the regulatory dilemma this poses for a democracy and suggest a balanced policy framework.

Way Forward

A workable Dark Web policy for India has to do four things at once. It has to invest in technical capability inside the police and the central agencies, including the ability to run Dark Web informants, analyze cryptocurrency flows, and process electronic evidence at scale. It has to build cross-border cooperation through faster mutual legal assistance, including bilateral arrangements with the United States and the European Union, where most large hosting providers and exchanges are based.

It has to update the criminal law and procedural law to handle anonymous payments, anonymous communications, and evidence obtained from foreign jurisdictions. And it has to do all this without sliding into mass surveillance that would catch the dissident along with the dealer.

The model is not prohibition. The model is targeted, well-resourced, rule-of-law policing. The Dark Web is small. Most crime even on the Dark Web is committed by a relatively small number of operators. Patient, technical work, sustained over years, has historically produced the most durable results. India’s institutional architecture is in place. The next phase is execution at scale.

Frequently Asked Questions

Is it illegal to use the Dark Web in India?

No, accessing the Dark Web is not in itself illegal in India. Downloading and running Tor Browser, visiting a dot-onion site, or reading Dark Web forums does not violate Indian law. What is illegal is performing acts that would be criminal anywhere, such as buying narcotics, possessing child sexual abuse material, or trading in stolen data.

Are the Deep Web and the Dark Web the same thing?

No. The Deep Web is the entire portion of the internet not indexed by search engines, including ordinary email, banking, and intranets. The Dark Web is a small, deliberately hidden subset of the Deep Web that requires anonymizing software to access. Most of the Deep Web is mundane and lawful.

What is onion routing?

Onion routing is a technique that wraps a message in multiple layers of encryption and routes it through a sequence of intermediate relay nodes. Each relay peels off one layer and forwards the message to the next. No single relay knows both the source and the destination. This is what gives Tor its anonymity property.

Who created Tor?

Tor grew out of research at the United States Naval Research Laboratory in the 1990s on protecting government communications through onion routing. The Tor Project, the non-profit that now develops and maintains Tor, was incorporated in 2002.

What is the Kerala Cyberdome?

The Kerala Cyberdome is a specialized cyber research and monitoring centre set up by the Kerala Police. It develops technical capability to track Dark Web activity relevant to Indian crime, including child sexual abuse material and drug trafficking.

What is Operation Chakra?

Operation Chakra is a series of coordinated crackdowns by the Central Bureau of Investigation on cyber-enabled financial crime networks, many of which routed through Dark Web infrastructure. The operation has moved through multiple phases since 2022 and resulted in arrests across the country.

Can the police shut down a Dark Web site?

Sometimes. Most successful takedowns of major Dark Web markets globally have relied not on breaking the Tor protocol itself but on operator mistakes, infiltration by undercover agents, and international cooperation. Direct technical attack on Tor remains expensive and rare.

Why does the United States government fund Tor when criminals use it?

The argument is that Tor is also a critical tool for journalists in repressive regimes, dissidents, intelligence officers operating abroad, and ordinary citizens seeking privacy. Banning the technology would harm those users without significantly slowing committed criminals, who would migrate to other anonymizing tools. Funding for Tor has come from a mix of United States government grants and private donors over the years.

What share of the internet is the Dark Web?

Estimates vary, but the Dark Web is widely believed to make up well under one tenth of one percent of total online content. The Surface Web is roughly four percent. The bulk of the internet by volume is the lawful Deep Web, dominated by databases, email, and other authentication-gated content.

How does India’s response to the Dark Web compare globally?

India’s institutional architecture, including the Indian Cyber Crime Coordination Centre, the Kerala Cyberdome, and CBI Operation Chakra, is comparable to that of many mid-tier jurisdictions. Capacity at the operational level is improving but still lags the United States, the United Kingdom, and Germany in the speed of investigations and the depth of cryptocurrency forensics.