The Tor Browser provides anonymity that no standard browser, VPN, or privacy extension can match. By routing traffic through a three-hop circuit of volunteer-operated relays before it reaches the destination, it obscures the user’s IP address from the destination and browsing content from the ISP and any network observer. For a broader walkthrough, our Complete Guide to Security and Privacy is a good next read.
But using Tor Browser correctly is more nuanced than simply downloading it and clicking Connect. Misuse — logging into personal accounts, installing extensions, resizing the window, opening downloaded files — can break the anonymity model that makes Tor valuable in the first place. This guide covers how to use it safely, what it genuinely protects, and where its limits are.
Who actually benefits from Tor Browser
The practical use cases are broader than commonly assumed: journalists protecting source communications, activists in repressive jurisdictions, researchers accessing information without revealing their inquiry to their ISP, security professionals testing from a clean IP, and individuals who want to browse without building a surveillance profile with their ISP or network. The key is matching the tool to the actual threat it addresses — not using it as a daily browser replacement.
Installation and first launch
Download only from the official source: torproject.org → Downloads. The Tor Project provides cryptographic signature files for every release; verify the signature before installation using GPG. Downloading from third-party download sites or unofficial repositories creates risk that the binary has been modified to compromise its protections. This is not paranoia — it’s the specific attack that modified Tor browsers have been used for in documented cases.
After installation: launch the browser, wait 10–30 seconds for the Tor network connection, and then set the security level using the shield icon in the toolbar. Three options:
- Standard: all features enabled; adequate for casual privacy browsing where the goal is ISP non-logging
- Safer: disables JavaScript on non-HTTPS sites
- Safest: disables JavaScript entirely, restricts media, limits other potentially-identifying features
The security level choice is the most important configuration decision for the threat model. JavaScript has been used in documented attacks that successfully deanonymised Tor users by exploiting browser vulnerabilities. Safest mode eliminates this attack surface at the cost of JavaScript-dependent site functionality. For high-sensitivity anonymity — source communication, accessing restricted information in adversarial jurisdictions — Safest mode is the appropriate setting.
The rules for maintaining anonymity — no exceptions
- Never log into personal accounts. Logging into any account — Google, Facebook, email, social media — while using Tor tells that service your account identity, linking the account to a Tor exit node. More critically: if you’ve used that account on non-Tor connections, the service can potentially correlate activity. Create new accounts not linked to any real identity if accounts are needed within Tor sessions. “Just once” is exactly what breaks the anonymity model.
- Do not change the browser window size. The Tor Browser opens at a specific standardised size shared across all users. Maximising or resizing changes the screen resolution fingerprint, making your browser profile more distinctive. Keep the window at the default size.
- Do not install extensions. The browser comes pre-configured with specific privacy settings and extensions (NoScript, Torbutton). Adding any extension changes the fingerprint, making your instance distinct from other Tor Browser users. The uniformity of all users is the protection — any deviation reduces it.
- Do not open downloaded files while connected. Files downloaded through Tor and opened in external applications (PDF readers, Office, media players) may connect to the internet through the regular network connection rather than through Tor — revealing the real IP address. Disconnect from the internet before opening downloaded files, or use an isolated machine.
- Use HTTPS sites. Tor encrypts traffic between the user and the exit node, but the exit node sees the destination and content of HTTP (unencrypted) traffic. HTTPS ensures end-to-end encryption so the exit node operator cannot read the content. The browser’s HTTPS-only mode (enabled by default) automatically upgrades connections.
- Use New Identity between different activities. Each Tor circuit is held for a session. For a completely fresh identity with new circuits for all connections: Tor Browser menu → New Identity. This restarts the browser and creates entirely new circuits, preventing activity correlation between different browsing purposes.
According to the Tor Project’s official documentation, the most consistent anonymity failures in published research have come from users logging into accounts that could be correlated with their non-anonymous identity — not from technical attacks on the Tor protocol itself. The protocol is solid; the human behaviour is where anonymity breaks.
What Tor does not protect against
- Endpoint compromise: if the OS running the Tor Browser is infected with malware, the malware can observe browser activity regardless of Tor’s encryption and routing. This is why the Tor Project recommends Tails OS — a live operating system running from a USB drive that routes all traffic through Tor by default and leaves no traces on the host machine.
- Full traffic correlation by a global adversary: a sophisticated attacker who can observe both the user’s entry point to the Tor network and the destination’s traffic can potentially correlate timing patterns to deanonymise the connection. This is a high-capability attack beyond most users’ threat models, but it’s worth understanding for high-stakes use cases.
- Other applications on the device: Tor Browser anonymises browser traffic only. Other network connections — OS updates, application traffic, cloud sync — continue through the regular connection. A network observer can see the timing of Tor traffic alongside other activity from the same IP. For true device-wide anonymisation, Tails OS routes all traffic through Tor.
- Account-level tracking: if you log into any account, that service knows who you are regardless of Tor.
- Content-level analysis: if the content of what you write identifies you (writing style, specific personal details, references to real-world activity), Tor doesn’t protect you from identity inference through the content itself.
Tor vs VPN — choosing the right tool
| Property | Tor Browser | VPN |
| IP address from destination | Hidden (exit node’s IP shown) | Hidden (VPN server’s IP shown) |
| Browsing content from ISP | Hidden (only sees Tor entry) | Hidden (encrypted tunnel) |
| Trust required | No single party — distributed across 3 relays | VPN provider (sees destination and timing) |
| Speed | Significantly slower — 3 hops, volunteer hardware | Minimal slowdown on good providers |
| Anonymity from destination | Strong (exit node IP, not user IP) | Moderate (VPN IP, but VPN knows real IP) |
| Anonymity from the provider itself | High (Tor Project can’t see connections) | Dependent on VPN’s no-logs policy and jurisdiction |
| Site compatibility | Many sites block Tor exit nodes | Minimal compatibility issues |
| Best for | High-stakes anonymity; source protection; repressive jurisdictions | Routine privacy; ISP surveillance prevention; public WiFi |
A VPN hides your activity from the ISP but requires trusting the VPN provider. Tor distributes that trust across three independent relays — no single party sees both who you are and what you’re accessing. For routine privacy (preventing ISP logging, public WiFi protection), a VPN is faster and more compatible. For genuine anonymity where trust in a provider is a concern, Tor is the appropriate tool.
Tails OS — Tor for the full operating system
For the highest-sensitivity use cases — source communication, operating in adversarial environments — Tails OS (tails.boum.org) provides Tor protection at the operating system level rather than just the browser. Tails is a live OS that:
- Boots from a USB drive on any computer without installing
- Routes all traffic through Tor by default (no other connections are possible)
- Leaves no trace on the host computer — RAM is securely wiped on shutdown
- Includes a pre-configured set of privacy tools (email client, office suite, file encryption)
Tails requires more setup than Tor Browser alone but provides comprehensive protection against the limitations that Tor Browser can’t address on its own (other applications sending traffic outside Tor, leaving traces on the host OS). The Tor Project and Electronic Frontier Foundation both recommend Tails for high-risk communications. For most users doing routine private browsing, the Tor Browser alone is sufficient. For journalists receiving sensitive documents or activists operating under surveillance threat, Tails changes the threat model meaningfully. For Tor’s official documentation on correct use and known limitations, the Tor Browser User Manual covers all configuration options and the specific threats each security level addresses.
Accessing .onion sites — the Tor hidden services layer
.onion addresses are websites accessible only through the Tor network — they route traffic entirely within the Tor network without an exit node, providing stronger anonymity for both the user and the server. Several legitimate services maintain .onion addresses:
- The New York Times: nytimesn7cgmftshazwhfgzm37qxb44r64ytbb2dj3x62d2lljsciiyd.onion
- Facebook: facebookwkhpilnemxj7asfy7id7tdab3ovpf4pcex6hxbhx1mb4oqd.onion (allows access in countries where Facebook is blocked)
- DuckDuckGo: duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onion
- SecureDrop: most major news organisations maintain SecureDrop .onion addresses for source submissions
Accessing .onion addresses through the Tor Browser means neither the exit node nor any external observer can see the destination — the entire circuit is within the Tor network. This is more anonymous than accessing clearnet sites through Tor, where the exit node can see the destination (but not the content of HTTPS traffic).
Not all .onion addresses are legitimate. The Tor network hosts both legal and illegal content. Accessing legitimate .onion services (news organisations, SecureDrop, privacy-focused services) uses the same Tor Browser without any additional configuration — type or paste the .onion address in the address bar. Use .onion addresses only from verified official sources; don’t visit .onion addresses from unverified links.
Tor bridges — bypassing Tor blocking
Some networks and ISPs block connections to the Tor network’s known relay addresses — corporate networks, certain country-level censorship systems. Tor bridges are unlisted relay nodes that allow connecting to Tor when direct connection is blocked.
Accessing bridges: Tor Browser → Connect to Tor → “Use a bridge” → choose from built-in bridges (obfs4, snowflake) or request bridges at bridges.torproject.org. Snowflake bridges use WebRTC (the same technology as video calls) to disguise Tor traffic as regular web traffic, making it harder for censors to identify and block. If this sounds familiar, Chrome as Default Browser is worth a look.
Bridges are relevant for users in countries with active Tor censorship or for users on corporate networks that block Tor. For users without these constraints, a direct connection to the Tor network (the default) is simpler and equally effective. Our guide on Use Public WiFi Safely covers an adjacent issue.
Using Tor Browser safely is ultimately about discipline in maintaining the anonymity model — the protocol itself is robust, but it’s only as strong as the practices of the person using it. The rules (no personal account logins, no extensions, no window resizing, no opening downloaded files online) exist because each one addresses a specific documented deanonymisation vector. Following all of them consistently is what makes Tor Browser the strongest anonymity tool available for everyday use. See also Privacy Focused Browser for a related case.






