Ongoing trends in law, policy and technology threaten anonymity as never before, undermining our ability to speak and read freely online. These trends also undermine national security and critical infrastructure by making communication among individuals organizations, corporation, and governments more vulnerable to analysis and threat.
What is Tor ?
Tor is free software and an open network that helps you defend against traffic analysis, a form of network surveillance the threatens personal freedom and privacy, confidential bussiness activities and relationships and state security. It provides a network of virtual tunnels that allows people and groups to improve their privacy and security on the internet. It also enable software developers to crrate new communication tools with built in privacy features. Tor provides the foundation for a range of applications that allow organization and individuals to share information over public network without compromising their privacy. Individual also use Tor for socially sensetive communications. Chat rooms and web forums for rap and abuse survivors, or people with illeness. Journalists use Tor to communicate more safely with whistle blowers and dissidents. Non governmental organisation use Tor to allow their workers to connect to their home website while they are in a foreign country, without notifying everybody nearby that they are working with that organization
Who made Tor?
Tor was originally desined, implemented, and deployed as a third generation onion routing project of the U.S. Naval research laboratory, with the U.S. Navy in mind, for the primary purpose of protecting gpvernment communication. Today it is used for a wide variety of purposes by normal people, the military, journalists, law enforcement officers, activities, and many others. Each new user and relay provides additional diversity, enhancing Tor’s ability to put control over your security and privacy back into the hands of people.
Can Tor protect you
Yes. Using the protects you against a common form of internet surveillance known as “traffic analysis”. Traffic analysis can be used to infer who is talking to whom over a public network. Knowing the source and destination of your internet traffic allows others to track your behaviour and interests. This can impact your check book if, for example, an e-commerce site uses price discrimination based on your country or institution of origin. It can even threaten your job and physical safety by revealing who and where you are.
Analytical for the Tor network, including graphs of its available bandwidth and estimated userbase. This is a great resource for researchers interested in detailed statistics about Tor.
A terminal (command line) application for monitoring and configuring For, intended for command-line aficionados and ssh connections. This functions much like the top do for system usage, providing real-time information on Tor’s resource utilization and state.
Web-based protocol to learn about currently running Tor relays and bridges.
OONI (open observatory of network interference) –
a global observation network, monitoring for network censorship, which aims to collect high-quality data using open methodologies, using free and open-source software (FL/OSS) to share observations and data about the various types, methods, and amounts of network tampering in the world.
tor for google android devices, in collaboration with the guardian project, replacing the deprecated orfox.
a library for use by any android application to route internet traffic through or not Tor.
Pluggable transports –
It helps circumvent censorship. Transform the Tor traffic flow between the client and the bridge. This way, censors who monitor traffic between the client and the bridge will see innocent-looking transformed traffic instead of the actual Tor traffic.
Relay search –
a site providing an overview of the Tor network.
a discrete event network simulator that runs the real Tor software as a plugin. Shadow is open-source software that enables accurate, efficient, controlled and repeatable Tor experimentations.
Python library for writing scripts and applications that interact with Tor.
Tails (The Amnesic Incognito live system) –
A live CD/USB distribution preconfigured so that everything is safely routed through Tor and leaves no trace on the local system. Tor birdly Tor button for thunderbird and related bird forks.
Tor browser –
Customization of Mozilla firefox which uses a tor circuit for browsing anonymously and with other features consistent with the Tor mission.
Free software and an open network that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationship and state security.
python and twisted event-based implementation of the Tor control protocol. Unit test, state and configuration abstraction, documentation. On PyPI and Debian.
Tor is a free, global network that lets you browse the internal and the dark web anonymously. There are, however a few things you need to keep in mimd to use Tor securely.
As online surveillance becomes more and more prevalent, tools that can help you stay private and secure online are critical. While VPNs are one such tool (learn why you should use a VPN), there are other options. Tor (which stands for “The Onion Router”) is a powerful tool for online anonymity.
However, there is no such thing as 100% security, and even Tor has some vulnerabilities. It is essential to consider its threat model and make sure that you understand what Tor can and can’t protect you against. Furthermore, if you do not adhere to certain best practices when using Tor, you could expose yourself to vulnerabilities and exploits that could compromise your privacy or your device.
This article will explain the factors to consider before using Tor and what you can do to mitigate its weaknesses.
Is Tor illegal?
This is often the first question users ask because Tor and the “dark web” have become associated with illegal enterprises like the Silk Road marketplace. The answer is no. It is not illegal to be anonymous, and Tor has many legitimate uses. The dark web itself is a powerful tool to protect privacy and free speech.
Tor is an open network of servers run by volunteers and free software (the Tor Browser) that is guided by the non-profit Tor Project. Both the network and the software can be used to browse the “clearweb” (the Internet most of us are familiar with) like any other browser. According to the Tor Project, neither the network nor the browser is illegal anywhere in the world, and using Tor is not a criminal act.
Like any technology, Tor is not 100% secure, and attackers can still compromise Tor’s security. In 2014, a research team from Carnegie Mellon University gained control of enough servers in the Tor network to observe the relays on both ends of the Tor circuit and compare the traffic timing, volume, and other unique characteristics to identify which other Tor relays were part of which circuits. By putting the entire circuit together, the researchers were able to see the IP address of the user on the first relay and the final destination of their web traffic on the last relay, allowing them to match users to their online activity. (For those interested in a more technical explanation, the Tor Project analyzed the attack.) The FBI then used this attack to round up a number of criminals on the dark web as part of their Operation Onymous. Tor upgraded their relays to deal with the specific protocol used by the researchers, but correlation attacks (identifying users through the timing and volume of their traffic) are still possible.
These instances should not dissuade you from using Tor; rather they illustrate that even Tor is not 100% secure.
How to use Tor safely
Like with any privacy tool, proper usage is critical. Misusing Tor can compromise your online privacy in unexpected ways.
Tor will encrypt your data as it passes through the Tor network, but the encryption of your traffic between the final Tor relay and your destination site depends upon that website. Only visit websites that use the Hypertext Transfer Protocol Secure, or HTTPS. This protocol establishes an encrypted link between the final Tor relay and your destination website. Any site that has a URL that begins with “https://” uses HTTPS, and the Tor Browser comes with the HTTPS Everywhere add-on. The Electronic Frontier Foundation has a great diagram that illustrates how Tor and HTTPS work together to protect your data.The Tor Browser blocks many plugins, such as Flash, RealPlayer, and QuickTime. These plugins can be manipulated into exposing your IP address in ways that Tor cannot prevent.If you are using the Tor Browser, be aware that only the Tor Browser’s Internet traffic will be routed through Tor. Other apps on your device will still connect normally to the Internet and may expose your real IP address.You should not maximize the Tor Browser window. If you maximize the Tor Browser, websites can determine the size of your device’s screen, which can narrow down which device you are using and help those sites track your activity.
Tor recommends you always use the Tor Browser’s default screen size.You should not open documents downloaded through the Tor Browser while you are online. These documents could contain Internet resources that would reveal your true IP address. If you need to view a .doc or .pdf file, you should disconnect your computer from the Internet first, or you should use the Tor OS, Tails.Similarly, you cannot use BitTorrent over Tor. Torrenting will send out your real IP address in the tracker GET request, deanonymizing your torrent and web traffic. It will also slow down the entire Tor network.It is also important to note that Tor will not protect your privacy from a website you must sign in to. Once you sign in, you have identified yourself to that website — and anyone who might be observing the activity on that site.Finally, if you are using Tor to access the dark web, you must be extremely cautious. Only use dark web URLs you know to be accurate. Do not click on any ads on any site on the dark web. Inspect every link on the dark web before you click it. Visiting unknown sites on the dark web is a quick way to infect your device. Trusted sites on the dark web, such as ProtonMail’s Tor email portal, usually will have a valid SSL certificate.
Secure alternatives to Tor
Tor provides an excellent way to anonymize online activity, but certain limitations, particularly its slow browsing speeds, can be quite limiting for the average Internet user.
For users who find Tor too complex or need higher performance, a trustworthy VPN like ProtonVPN is a good alternative. A VPN will encrypt your online traffic and prevent attackers from monitoring your browsing activity. It is also much faster and easier to use than Tor. Once you install the VPN app, all it takes is a single click to establish an encrypted VPN connection. Switching your connection between countries is also much easier with a VPN than with Tor. The ProtonVPN feature Tor over VPN also lets you access onion siteswithout having to download and set up the Tor Browser. However, VPNs, like Tor, also have their limitations when it comes to security and privacy, so it is important to understand the VPN threat model.