Actions

Tor Browser Basics

From Whonix

(Redirected from Tor Browser/Download Confirmation Screen)



Tor Browser Icon
Tor browser youtube.png
Tor browser duckduckgo2.png
Tor browser how tor works.png

Contents

Introduction[edit]

Ambox warning pn.svg.png Warning: Only Tor Browser is recommended for use in Whonix ™ when browsing the Internet. [1]

Tor Browser [archive] [2] is a fork [archive] of the Mozilla Firefox ESR [archive] web browser. It is developed by The Tor Project [archive] and optimized [archive] and designed [archive] for Tor, anonymity and security. [3] Most will have browsed with Firefox and be familiar with the user interface that resembles those found in other popular, modern browsers. [4]

It is strongly encouraged to read this entire chapter so Tor Browser is used effectively and safely on the Whonix ™ platform. Advanced users may also be interested in the Tor Browser Adversary Model. Regularly consult the Tor Project blog [archive] to stay in tune with Tor / Tor Browser news and the latest release information.

Anonymity vs Pseudonymity[edit]

Ambox warning pn.svg.png Warning: Using regular browsers is pseudonymous rather than anonymous.

If browsers other than Tor Browser are used in Whonix ™, the IP address and Domain Name Service (DNS) requests [5] are still protected. However, only Tor Browser provides protocol level cleanup, which includes unique features like proxy obedience, state separation, network isolation, and anonymity set preservation.

In stark contrast to regular browsers, Tor Browser is optimized for anonymity and has a plethora of privacy-enhancing patches [archive] and add-ons. [6] By sharing the Fingerprint with around two million other people [archive], [7] Tor Browser users "blend in" with the larger population and better protect their privacy.

Encryption[edit]

HTTPS Encryption[edit]

It is important to understand the difference between HTTP and HTTPS: [8]

Hypertext Transfer Protocol Secure (HTTPS) is an extension of the Hypertext Transfer Protocol [archive] (HTTP). It is used for secure communication [archive] over a computer network [archive], and is widely used on the Internet. In HTTPS, the communication protocol [archive] is encrypted [archive] using Transport Layer Security [archive] (TLS), or, formerly, its predecessor, Secure Sockets Layer (SSL). The protocol is therefore also often referred to as HTTP over TLS, or HTTP over SSL.

The principal motivation for HTTPS is authentication [archive] of the accessed website [archive] and protection of the privacy [archive] and integrity [archive] of the exchanged data while in transit. ...

HTTPS Advantages[edit]

Info Only rely on services providing HTTPS when sensitive information is sent or received. Otherwise, passwords, financial / personal information or other sensitive data can be easily stolen or intercepted by eavesdroppers. HTTP webpage contents can also be modified on their way to the browser for malicious purposes.

HTTPS advantages include: [8]

  • Authentication of the website and web server that is being communicated with.
  • Protection against Man-in-the-middle Attacks.
  • Bidirectional encryption of communications between a client and server. This protects against eavesdropping and tampering with / forging of communication contents.
  • A reasonable expectation that the website being communicated with is genuine. [9]

In the Tor Browser context, this means HTTPS should be preferred over HTTP so communication is encrypted while browsing the Internet. While traffic is encrypted throughout the Tor network, the exit relay (third of three servers) can see traffic sent into Tor if it is plain HTTP. If HTTPS is used, the exit relay will only know the destination address. [10]

As an example, the screenshot below captures the browser appearance when visiting the Whonix ™ website. [11]

Figure: A Secure Connection to www.whonix.org

Tbbbbbb.png

Take note of the small, left-hand area of the address bar. Indicators of an encrypted connection are www.whonix.org is highlighted with a padlock and "Secure Connection" in green writing, and the URL begins with https:// instead of http://

HTTP / HTTPS Connections with and without Tor[edit]

The following figures from EFF provide an overview of HTTP / HTTPS connections with and without Tor, and what information is visible to various third parties. The descriptors are as follows: [12]

Potentially visible data includes: the site you are visiting (SITE.COM), your username and password (USER/PW), the data you are transmitting (DATA), your IP address (LOCATION), and whether or not you are using Tor (TOR).

Figure: Tor and HTTPS

Tor-with-https.png


Figure: Tor and No HTTPS

Tor-without-https.png


Figure: No Tor and HTTPS

Without-tor-with-https.png


Figure: No Tor and No HTTPS

Without-tor-https.png

Onion Services Encryption[edit]

Whenever possible, utilize Onion Services (.onion addresses) so communications and web browsing stay within the Tor network. These resources are still commonly referred to as "hidden services", even when their location is publicly known. [13]

Onion Services Advantages[edit]

URLs ending in the .onion extension provide a superior level of security and privacy, since the connection forms a tunnel which is encrypted (end-to-end) using a random rendezvous point within the Tor network; HTTPS is not required. These connections also incorporate perfect forward secrecy (PFS) [archive]. PFS means the compromise of long-term keys does not compromise past session keys. As a consequence, past encrypted communications and sessions cannot be retrieved and decrypted if long-term secrets keys or passwords are compromised in the future by adversaries. [14]

Onion services provide several other benefits: [15]

  • Passive surveillance by both network observers and the Tor exit node is prevented, unlike the plain Tor + HTTPS configuration. Adversaries cannot easily determine which destination is being connected from/to.
  • Onion services establish "rendezvous points" in the Tor network for web services, meaning neither the hosting service nor the user can discover the other's network identity.
  • Onion services can be combined with SSL/TLS to provide additional protection. Only a handful of sites currently provide this service, including DuckDuckGo: https://3g2upl4pq6kufc4m.onion [archive] and ProtonMail: https://protonirockerxow.onion [archive]. [16] [17]
  • Onion services do not use the insecure DNS system. Strong authentication comes from the self-authenticating address: the address itself forms a cryptographic proof of the .onion's identity. [18] [19]

To learn more about how onion services work, refer to the technical description.

Tor Browser Add-Ons[edit]

Introduction[edit]

Any default add-ons that are installed in Tor Browser should not be removed or disabled in the about:addons page. Tor developers have considered the security and anonymity benefits of this configuration, even though NoScript blocking is disabled (JavaScript is enabled) in Tor Browser by default [archive] (see footnote). [20] Developers have reasoned that this helps to avoid feature breakage and focuses efforts on designing a private browsing environment that does not rely on filters.

HTTPS Everywhere[edit]

HTTPS Everywhere logo

HTTPS Everywhere [archive] is a Firefox extension shipped in Tor Browser and produced as a collaboration between The Tor Project [archive] and the Electronic Frontier Foundation [archive]. It helps to encrypt communications with a number of major sites.

Many sites on the Internet offer some limited support for encryption over HTTPS, but make it difficult to use. For instance, sites may default to unencrypted HTTP or fill encrypted pages with links that return to the unencrypted version of site. The HTTPS Everywhere extension addresses these problems by rewriting all site requests to HTTPS.

To learn more about HTTPS Everywhere, visit:

NoScript[edit]

NoScript logo

NoScript is a free, open source extension that comes bundled with Tor Browser and other Mozilla-based web browsers. NoScript can provide significant protection with the correct configuration: [21]

By default, NoScript blocks active (executable) web content, which a user can wholly or partially unblock by whitelisting a site or domain from the extension's toolbar menu: Sites can be set as 'allowed', 'trusted', or 'untrusted', and the whitelist persists between sessions. Temporarily allowed sites won't by added to the permanent whitelist, and work only until the browser session ends. Active content may consist of JavaScript [archive], web fonts, Java [archive], Flash [archive], Silverlight [archive], and other plugins [archive]. The add-on also offers specific countermeasures against security exploits. ... This is based on the assumption that malicious websites can use these technologies in harmful ways.

NoScript protects against cross-site scripting [archive] (XSS), whereby attackers inject malicious client-side scripts into destination web pages, bypassing the same-origin policy [archive]. [22] The same-origin policy refers to web browser enforcement of permissions -- scripts in the first web page are usually only allowed to access data in a second web page if they have the same origin (URL scheme, hostname and port number). [23]

When NoScript is enabled, a host of tracking / profiling services are neutralized because they rely on JavaScript. For example, various operating system and browser configuration details are revealed if JavaScript is not disabled. [21] Another unintended benefit concerns the use of system resources. When JavaScript is disabled, studies reveal that bandwidth consumption can be reduced by more than 40 per cent on the top 150 Alexa websites. Similarly, less system resources are required to display a web page in the browser. [24]

Security vs Usability Trade-off[edit]

Info The Security Slider (see further below) also involves a security versus usability trade-off. Higher slider levels improve security and reduce usability, while the opposite is true of other settings. Fingerprinting risks are greatly reduced at higher slider levels, but some site functionality may also be lost.

In the stock Tor Browser configuration, JavaScript is enabled by default for greater usability. The Tor Project FAQ provides a rationale for this decision: [25]

We configure NoScript to allow JavaScript by default in Tor Browser because many websites will not work with JavaScript disabled. Most users would give up on Tor entirely if a website they want to use requires JavaScript, because they would not know how to allow a website to use JavaScript (or that enabling JavaScript might make a website work).

There's a trade-off here. On the one hand, we should leave JavaScript enabled by default so websites work the way users expect. On the other hand, we should disable JavaScript by default to better protect against browser vulnerabilities (not just a theoretical concern! [archive]). But there's a third issue: websites can easily determine whether you have allowed JavaScript for them, and if you disable JavaScript by default but then allow a few websites to run scripts (the way most people use NoScript), then your choice of whitelisted websites acts as a sort of cookie that makes you recognizable (and distinguishable), thus harming your anonymity.

The take-home message is disabling all JavaScript with white-list based, pre-emptive script-blocking may better protect against vulnerabilities (many attacks are based on scripting), [26] but it reduces usability on many sites and acts as a fingerprinting mechanism based on the select sites where it is enabled. [21] On the other hand, allowing JavaScript by default increases usability and the risk of exploitation, but the specific fingerprint has more in common with the larger user pool. [27] [28] [29]

Developers are unaware of any JavaScript vulnerabilities that could compromise Whonix ™ anonymity. That said, it is inadvisable to change NoScript settings in Tor Browser unless the potential impacts are known. To enable/disable JavaScript, Java and/or plugin execution, left-click the NoScript status bar icon or use the the contextual menu [archive]. [30] Permissions can be granted either temporarily or on a permanent basis using a whitelist. "Temporarily Trusted" will only enable a script(s) for that site until the browser session is closed, or until the permission is manually revoked.

For further information, refer to the NoScript website [archive] and features overview [archive], or the Torbutton design document [archive].

You should Disable JavaScript by Default![edit]

Info Update: Whonix now ships with a desktop file and menu options which affect the security slider setting after launching Tor Browser. This provides a choice between maximum security (high setting) versus maximum usability (low setting); see this forum thread [archive] for further details.

As noted in the previous section, disabling JavaScript by default may worsen fingerprinting. There are several other reasons why Whonix ™ has not made any modifications:

  • Whonix ™ is not a "secure browser" project - the focus is on creating a stable, reliable anonymity distribution which aligns with best practice security and privacy principles, informed by educated researchers in the field.
  • Possible fingerprinting or security issues with default settings in Tor Browser are the domain of core Tor developers.
  • Whonix ™ has limited manpower, meaning the resources do not exist to create a more secure browser, even if it was desirable. [31]
  • Tor Browser is not significantly modified for the same reasons Whonix ™ does not modify or attempt to improve Tor. [32]
  • Having Whonix ™ share the fingerprint of other Tor Browser users is good for anonymity.

Experienced Tor developer Mike Perry has provided justification for enabling JavaScript by default in a tor-talk mailing list topic; see "Tor Browser disabling Javascript anonymity set reduction" [archive]. In summary, Tor Button and Tor Browser patches handle the most serious JavaScript concerns, such as IP address / location bypass problems. [33]

Due to the loss in functionality, disabling JavaScript by default might place Whonix ™ users in a small subset of the Tor Browser population. The JavaScript behavior of the broader population is an open research question, so it safest to avoid changes which might reduce the anonymity set. Keep in mind the fingerprinting potential is also dependent on Tor Browser's security [archive] slider settings. Ultimately individuals are free to turn JavaScript on or off, depending on their security, anonymity and usability preferences [archive].

NoScript Custom Setting Persistence[edit]

It is possible to save custom NoScript settings between browser restarts with a preference. [34] This preference is disabled by default, which means custom NoScript settings will not persist across successive Tor Browser sessions.

Warning[edit]

This preference sacrifices privacy for convenience and is therefore not recommended. While frequently visited sites do not require the constant enabling/disabling of scripts across separate Tor Browser sessions, a number of anonymity risks are introduced: [35]

  • Disk hygiene: Tor Browser is designed to prevent the persistent storage of history records and other on-disk information. This preference violates that design principle by allowing the storage of NoScript per-site permissions, thereby increasing the chance an adversary can extract valuable information from that data.
  • Long-term fingerprinting vectors: Persistent per-site settings allow a website to profile Tor Browser users, particularly if first-party isolation [archive] is not enforced. For example, consider the negative anonymity impact of whitelisting Google or Facebook, since their advertisements and tracking widgets are ubiquitous.
  • Expert opinion: Experienced Tor developers have confirmed that enabling this preference is dangerous and caution should be exercised. [36]

Persistent NoScript Settings[edit]

Info Note:

  1. By defining custom settings in NoScript, this will override the current Tor Browser Security Slider setting.
  2. When extensions.torbutton.noscript_persist is set to true, these changes will persist across Tor Browser restarts.

If this is acceptable, in the Tor Browser address bar:

  • "Type" about:config"Press" enter"Choose" I accept the risk!"Type" extensions.torbutton.noscript_persist"Toggle" to true [37]

This preference will be overridden and all custom per-site settings lost, if:

  • The security slider setting is changed afterwards; or [36]
  • extensions.torbutton.noscript_persist is again set to false, [38] since NoScript settings are reset after Tor Browser syncs with the Security Slider position.

Non-default Add-ons[edit]

As Tor Browser is based on Firefox, any browser add-on that is compatible with Firefox can also be installed in Tor Browser. In this context, add-ons are the collective name given to extensions, themes and plugins: [39]

  • Extensions add new features to Firefox or modify existing ones, like video downloaders, ad blockers and so on.
  • Themes change the appearance of the browser, such as buttons, menus and the background image.
  • Plugins add support for Internet content and often include patented formats like Flash and Silverlight which are used for video, audio, online games and more. [40]

Non-default Add-on Risks[edit]

The Tor Project explicitly warns against using non-default add-ons with Tor Browser: [39]

However, the only add-ons that have been tested for use with Tor Browser are those included by default. Installing any other browser add-ons may break functionality in Tor Browser or cause more serious problems that affect your privacy and security. It is strongly discouraged to install additional add-ons, and the Tor Project will not offer support for these configurations.

...

Video websites, such as Vimeo make use of the Flash Player plugin to display video content. Unfortunately, this software operates independently of Tor Browser and cannot easily be made to obey Tor Browser’s proxy settings. It can therefore reveal your real location and IP address to the website operators, or to an outside observer. For this reason, Flash is disabled by default in Tor Browser, and enabling it is not recommended.

Recommendations[edit]

Ambox warning pn.svg.png Warning: For the safest Tor Browser experience, it is recommended to avoid Java, JavaScript, Flash, themes, browser plugins and other non-default add-ons.

The problem with non-default add-ons is that they are often comprised of non-free software, which can lead to the linkage of activities conducted under one pseudonym. They also worsen fingerprinting and open up attack vectors in the form of remote exploits.

This advice holds true even though Whonix ™ is configured to prevent these applications (along with malware) from leaking the real external IP address, even if they are misconfigured (see Features). Before installing non-default add-ons, first consider the various alternatives such as HTML5 or online media converters. [41]

Torbutton[edit]

Info As noted in the Tor Button Design entry, the release of Tor Browser 9.0 [archive] resulted in both the Torbutton and Tor Launcher extensions being tightly integrated into Tor Browser:

... Torbutton has been moved from the URL bar and neither appears on the about:addons page. Other changes include the New Identity function shifting to the URL bar and the New Tor Circuit function being accessible via the hamburger menu. ... No functionality has been lost -- Torbutton's functions in Tor Browser behavior have simply moved into direct Firefox patches [archive].

Tor alone is not enough to protect anonymity and privacy while browsing the Internet. All modern web browsers support JavaScript [archive], Adobe Flash [archive], cookies [archive] and other features which are capable of defeating the anonymity [42] provided by the Tor network.

In Tor Browser, these features are handled from inside the browser, because it is a modified (patched) version of Firefox [archive] and it contains direct patches (based on the former Torbutton extension [archive]) that take care of application-level security and privacy concerns in Firefox. This means many types of active content are disabled. [43]

It is recommended to learn more about Fingerprinting and Data Collection Techniques to better understand the potential threats. Advanced users can also review detailed information about the former Torbutton design and its various functions here.

New Identity Function[edit]

Ambox warning pn.svg.png Warning: The New Identity feature will likely create a new Tor exit relay and a new IP address, but this is not guaranteed.

The "New Identity" menu option sends the protocol command "signal newnym" to Tor's ControlPort. This clears the browser state, closes tabs, and obtains a fresh Tor circuit for future requests. [44]

Sometimes Tor only replaces the middle relay while using the same Tor exit relay; this is by design and the Tor default. Further, "signal newnym" does not interfere with long-lived connections such as an IRC connection.

New Identity is not yet perfect and there are open bugs; this is not a Whonix ™-specific issue. [45] For greater security, it is better to completely close Tor Browser and restart it. In Qubes-Whonix ™, the safest option when performing sensitive activities is using a Whonix-Workstation ™ DisposableVM. To completely separate distinct activities, shut down the DispVM and create a new one between sessions.

There are two ways to use the New Identity feature:

  1. Left-click the Hamburger IconSelect "New Identity"
  2. Left-click the 'broom' icon in the URL bar

Please read New Identity and Tor Circuits and the New Identity Design to learn more about this option and its limitations.

New Tor Circuit Function[edit]

Ambox warning pn.svg.png Warning: This function does not attempt to clear Tor browsing session data or unlink activity, unlike the "New Identity" feature.

The "New Tor Circuit for this Site" feature creates a new circuit for the current Tor Browser tab, including other open tabs or windows from the same website. [46] If it is really necessary to separate contextual identities, it is always safer to close and then restart Tor Browser.

There are several, potential use cases for this feature: [47]

  • The Tor exit relay is located in a country which negatively affects the presentation of the website due to language localization.
  • The site is censored due to the current Tor exit relay in use (caused by Tor IP address blacklisting).
  • To bypass Google CAPTCHA [archive] or reCAPTHA [archive] systems protecting sites from abuse if these are showing unsolvable captcha or no captcha at all.
  • Connections to websites become unresponsive or slow.
  • To change the Tor exit relay IP address without losing all open tabs.

To use it: Left-click the Hamburger IconSelect "New Tor Circuit for this Site"

Advanced users who want to learn more about this function should refer to the New Tor Circuit Design entry.

Check for Tor Browser Update[edit]

Notifications will automatically appear if a Tor Browser update is available; see Tor Browser Internal Updater for further information and screenshots of this process. Note that multiple methods exist for updating Tor Browser.

To manually check for Tor Browser updates: Enter about:preferences in the URL barScroll down to "Tor Browser Updates"Click "Check for updates"

Disabled Functions[edit]

Readers who are interested in why the "Open Networking Settings" and "Tor Circuit View" features have been disabled in Whonix ™ can learn more here.

Tor Browser: How-To[edit]

Security Slider[edit]

Tor Browser includes a “Security Slider” that allows the disabling of certain web features that can be used to compromise security and anonymity. At present there are three levels: "Safest", "Safer" and "Standard". It is necessary to make a trade-off between security, usability and privacy. At the higher levels the slider will prevent some sites from working properly. [48] Note that as of Tor Browser release v8.5, the security slider function has shifted to the taskbar. [49] [50]

To use this feature: Click Security Level button (taskbar 'shield')Click "Advanced Security Settings..."Select desired security level

To learn more about the exact effect of each setting level, refer to the Security Slider design entry. For information on related Tor plans for redesigning browser security controls, see here [archive].

Start Tor Browser[edit]

From the Menu[edit]

Start Tor Browser.

If you are using Qubes-Whonix ™.

Qubes Start MenuWhonix-Workstation ™ AppVM (commonly called anon-whonix)Tor Browser

If you are using Non-Qubes-Whonix ™.

Start MenuTor Browser

From the Command Line[edit]

Open a terminal.

If you are using Qubes-Whonix ™, complete the following steps.

Qubes App Launcher (blue/grey "Q")Whonix-Workstation ™ AppVM (commonly named anon-whonix)Xfce Terminal

If you are using a graphical Whonix with XFCE, run.

Start MenuXfce Terminal

From the command line, Tor Browser can either be started normally or in debugging mode (see next section). To start Tor Browser "normally" in a terminal, run. [51]

torbrowser

In Debugging Mode[edit]

If Tor Browser problems emerge, launch it from the command line in debugging mode for detailed output.

Open a terminal.

If you are using Qubes-Whonix ™, complete the following steps.

Qubes App Launcher (blue/grey "Q")Whonix-Workstation ™ AppVM (commonly named anon-whonix)Xfce Terminal

If you are using a graphical Whonix with XFCE, run.

Start MenuXfce Terminal

To start Tor Browser in debugging mode, run. [52]

~/.tb/tor-browser/Browser/start-tor-browser --debug

Successful Tor Browser Connection[edit]

If Tor Browser successfully launches and connects to the Tor network, Check Torproject [archive] should show the following message.

Figure: Successful Tor Browser Connection

Tbb2.png

File Downloads[edit]

Warnings[edit]

Whonix ™ protects against the threats outlined below, such as files that inadvertently or maliciously attempt to reveal the real IP address of the user, or third-party, external applications that can leak information outside of Tor. Despite this protection, it is recommended to always follow best safety practices.

Do not Open Documents Downloaded via Tor while Online[edit]

The Tor Project explicitly warns against opening documents handled by external applications. The reason is documents commonly contain Internet resources that may be downloaded outside of Tor by the application that opens them. [53]

This warning is not strictly relevant to the Whonix ™ population since all traffic is forced over Whonix-Gateway ™ and the IP address will not leak. Nevertheless, for better safety files like PDFs and word processing documents should only be opened in offline VMs.

Malicious files or links to files pose a greater threat and can potentially compromise your system. Therefore, follow the wiki advice and avoid opening random links or files in Whonix-Workstation ™. Instead:

Do not Torrent over Tor[edit]

See File Sharing.

Secure Downloads[edit]

Preventing SSLStrip Attacks[edit]

Info If clicking or pasting a download link, make sure it is https://. The s in https:// stands for "secure".

A common misconception is that a secure, green padlock and a https:// URL makes any download from that particular website secure. This is not the case because the website might be redirecting to http. In fact, an SSLstrip attack [archive] might succeed if a link is pasted or typed into the address bar without the https:// component (e.g. torproject.org instead of https://torproject.org [archive]) -- the reason is a padlock is not visible; it just appears empty. [54]

To avoid this risk and similar threats, always explicitly type or paste https:// in the URL / address bar. The SSL certificate button or padlock will not appear, but that is nothing to be concerned about. Unfortunately, few people follow this sage advice; instead most mistakenly believe pasting or typing www.torproject.org into the address bar is safe.

Other Precautions[edit]

For improved safety when downloading files or installing software, follow the advice below.

Table: Software and File Download Advice

Category Recommendations
File Source and Verification
Multiple Whonix-Workstation ™ Consider using Multiple Whonix-Workstation ™ when downloading and installing additional software. It is safer to compartmentalize discrete activities and minimize the threat of misbehaving applications.
Onion Service Downloads Files should be downloaded from Onion Services (via .onion addresses) whenever possible. Onion service downloads improve security for several reasons:
  • The connection is encrypted end-to-end (with PFS).
  • It is difficult for network adversaries to:
    • Target specific individuals.
    • Determine where someone is connecting to/from.

Navigating Tor Browser Downloads[edit]

For those who regularly download Internet files, Tor Browser's default download folder is inconvenient. For example, if the sample image below was downloaded with Tor Browser, the download path is /home/user/.tb/tor-browser/Browser/Downloads by default. It is time-consuming to navigate to this folder so far down the directory tree.

Figure: Default Tor Browser Download Folder

Tbbd.png

To make things simpler, the following steps change Tor Browser preferences so files are saved directly inside /home/user/Downloads

1. Navigate to Tor Browser preferences.

Choose one of the following three methods:

  • Click the "hamburger" symbolClick Preferences
  • Navigate to the Edit menuclick Preferencesclick General tab
  • Enter about:preferences in the Tor Browser address bar.

Figure: Tor Browser Preferences

Tbbd6.png

2. Select the Save files to download option.

Figure: Custom Download Path Option

Tbbd8.png

3. Change the default download folder location.

It is recommended to set /home/user/Downloads as the custom path.

Figure: Set the Custom Download Path

Tbbd7.png

User files will now be downloaded to the /home/user/Downloads folder. Navigate to this folder using either Dolphin or Konsole.

To access files that were stored inside the "wrong" download folder, please press Expand on the right.

1. Start Dolphin.

2. Enable the hidden files view.

To show hidden files:

Navigate to the View menuclick Show Hidden Files

Figure: Hidden Files in Dolphin

Tbbd2.png

3. Navigate to the downloaded files.

Double-click the .tb folder

Figure: Hidden Tor Browser Folder

Tbbd3.png

Use the following path: tor-browserBrowserDownloads

Figure: Default Tor Browser Download Folder

Tbbd4.png

Now it is possible to review the downloaded files.

Figure: Downloaded Files

Tbbd5.png

Browser Language[edit]

In 2019, the stable and experimental Tor Browser binaries with additional language packs support 32 languages. Recent additions include: Catalan, Irish, Indonesian, Icelandic, Norwegian, Danish, Hebrew, Swedish, Traditional Chinese, Macedonian and Romanian. [55] [56] [57] For instructions on changing the Tor Browser interface to a language other than English, see Tor Browser Language. [58]

Local Connections[edit]

Info Web HTTP(S)/SOCKS proxies have different instructions and will not work with these steps, see Tor Browser Proxy Configuration.

Sometimes it is necessary to access the local application interface on 127.0.0.1 in order to run specific applications like I2P. [59] Due to potential fingerprinting and information leakage risks, this behavior is no longer possible in Tor Browser unless an exception is configured. [60] [61]

To configure an exception for local connections in Tor Browser: [62]

PreferencesGeneral TabNetwork Proxy | Settings...No Proxy for: "127.0.0.1"click "OK"

The configured exception means a small trade-off in privacy, but it is much safer than using another browser (see Local Connections Exception Threat Analysis).

Recommendations[edit]

For better anonymity:

  • Browse with JavaScript disabled in Tor Browser and enable it only when needed. Disabled JavaScript mitigates these browser fingerprinting issues completely.
  • Set passwords for web interfaces listening on the localhost.
  • Run sensitive daemons with local WebGUIs on a separate, dedicated Whonix-Workstation ™ and virtual network instance. TODO: expand or link how to do that

Bypass Tor Censorship[edit]

Info This section outlines how to bypass Tor blocks by destination websites. If connections to the Tor network are blocked at the ISP level, then bridges or other circumvention tools are necessary.

A number of websites or services actively block Tor users [archive] via:

There are various ad-hoc methods available to try and circumvent blocks. In most cases it is unnecessary to create a tunnel which pairs Whonix ™ with other protocols (such as a VPN) in order to access the content.

The following services fetch content via other websites, which is a privacy trade-off. Further, only some services are effective with embedded, non-static content or support specific file types like PDF, .exe and mp3. [63]

Table: Tor Censorship Circumvention Options [64]

Service URL Comment Non-static Embedded Content PDF, .exe, mp3
The Internet Archive's WaybackMachine web.archive.org/save/_embed/<URL> Archive.org respects robots.txt restrictions, works best with JS enabled No Yes
Archive.fo archive.fo/?run=1&url=<URL> And their official onion service: archivecaslytosk.onion/?run=1&url=<URL> Ideal for news sites, doesn't require JS No No
Google Cache webcache.googleusercontent.com/search?q=cache:<URL without "http://"> Google sometimes blocks these requests No - static only No
Startpage.com (1) Find the URL by searching, (2) Click on the proxy option "anonymous view" Not always efficacious No No
Searx.me (1) Find the URL by searching, (2) Click on the proxied option Not always efficacious No No
Hypothes.is via.hypothes.is/<URL> Behind Cloudflare Yes Yes
Online Proxies hide.me/en/proxy, www.proxysite.com/, www.proxysite.club/ [65] - Yes Yes

The Tor Project also recommends: [66]

To avoid captchas that are sometimes required when visiting YouTube, use hooktube.com/ (behind Cloudflare).

imgur.com blocks Tor uploads, to upload images on an imgur domain go to a stackexchange website (for example tor.stackexchange.com), click on Ask a Question, use the image upload tooltip to upload the image, the resulting url will have a i.stack.imgur.com/... form.

Harden Tor Browser[edit]

Anonymity and safety can be materially improved via: AppArmor, Firejail confinement, Tor Browser settings, sandboxing, multiple Tor Browser instances, and operation of Whonix-Workstation ™ DisposableVMs (Qubes-Whonix ™) or multiple Whonix-Workstation ™.

Tor Browser provides reasonable security in its stock configuration. However, mitigating the risk of Tor Browser security breaches makes sense, because it is an untrusted application with a huge attack surface; it is frequently attacked successfully in the wild by adversaries.

Table: Tor Browser Hardening Options

Domain Recommendations
AppArmor Confinement
  • AppArmor can help to protect the user's system and data. [67] [68] To mitigate the threat of specific attacks against Tor Browser, the Whonix ™ Tor Browser AppArmor profile can be easily applied -- see the footnote for download workarounds. [69]
  • Update the package lists. Install the apparmor-profile-torbrowser package.

sudo apt-get update
sudo apt-get install apparmor-profile-torbrowser

Firejail Confinement Firejail can be used as an alternative sandboxing measure to restrict the Tor Browser process. The Tor Browser Starter by Whonix developers in Whonix testers repository includes a “hardening” option that permits certain features to be enabled that on the upside increase security, but on the downside might decrease anonymity. [70]

It is necessary to make a trade-off between security, usability and privacy. With “hardening” enabled, certain website features might be non-functional or Tor Browser may no longer start after an upgrade. Also, the fingerprint seen by websites ('web fingerprint') might reveal subtle differences between Tor Browser instances that have enabled this feature compared to the default configuration. The population of Linux Tor Browser users who regularly utilize Firejail is likely to be tiny. At the time of writing (2019) there were no reports confirming a detectable fingerprint, but there is also no known research being undertaken in this area. [71] [72] [73] This issue is not within the control of the Whonix ™ project.

To use this feature, apply the following instructions.

1. Open /etc/torbrowser.d/50_user.conf in an editor with root rights.

Open file /etc/torbrowser.d/50_user.conf in an editor with root rights.

(Qubes-Whonix ™: In TemplateVM)

This box uses sudoedit for better security [archive]. This is an example and other tools could also achieve the same goal. If this example does not work for you or if you are not using Whonix, please refer to this link.

sudoedit /etc/torbrowser.d/50_user.conf

2. Add the following setting.

tb_hardening=true

3. Save the file.

The procedure is complete.

Multiple Tor Browser Instances and Whonix-Workstation ™
  • Multiple Tor Browser Instances: To better separate different contextual identities, consider starting multiple Tor Browser instances and running them through different SocksPorts. This method is less secure than the method outlined below.
  • Multiple Whonix-Workstation ™: For tasks requiring different identities and/or additional software, it is recommended to compartmentalize activities and use two or more Whonix-Workstation ™ VMs. In this way, an exploit in Tor Browser in one Whonix-Workstation ™ cannot simultaneously read the individual's identity in another VM (for example, an IRC account). [74] This method is less secure than using a Whonix-Workstation ™ DisposableVM with Tor Browser (see below).
Sandboxing and DisposableVMs
  • Sandboxing: The Tor Project's official sandboxed Tor Browser is compatible with Whonix ™ 14 and later releases, however it is no longer recommended since The Tor Project has officially abandoned its development. [75]
  • Whonix-Workstation ™ DisposableVMs: One of the safest configurations is to assume future compromise and run all instances of Tor Browser in an uncustomized Whonix-Workstation ™ DisposableVM in Qubes-Whonix ™. This configuration creates fresh Whonix-Workstation ™ and Tor Browser instances for discrete Internet activities, while ensuring that previous, potentially compromised versions of both are destroyed. [76]
Tor Browser Series and Settings
  • Series: Prefer the stable Tor Browser release over the alpha series in line with Tor developer recommendations; see footnotes. [77] [78] [79] [80] Both the stable and alpha Tor Browser series now benefit from Mozilla's content level sandboxing, as well as being multi-process (e10s) compatible.
  • Settings: Follow relevant System Hardening Checklist recommendations, such as routinely using onion services for search queries and browsing (where possible), running the Security Slider in the highest position and disabling Javascript by default.

Update Tor Browser[edit]

Introduction[edit]

Info It is recommended to follow The Tor Project blog [archive] to stay informed about recent updates.

Unfortunately, updating Tor Browser is more complex than regular system updates due to technical limitations outside of Whonix's control. [81] However, the following instructions will keep Tor Browser up-to-date at all times.

There are three options for updating Tor Browser in Whonix ™:

  1. The Whonix ™ Tor Browser Downloader. [82]
  2. Tor Browser's Internal Updater. [83]
  3. Tor Browser manual updates.

The first two methods are suitable in most circumstances. Manual updates are only required if the Whonix ™ Tor Browser update script ever breaks. Never continue to use an outdated version of Tor Browser, otherwise serious security flaws may degrade anonymity or result in a VM compromise. [84]

Tor Browser Downloader by Whonix ™[edit]

Installation Process[edit]

Note: Tor Browser Downloader (Whonix ™) is really just a downloader, not a updater. This means it is incapable of retaining user data such as bookmarks and passwords. In order to preserve data, use the Internal Updater method instead.

To use Tor Browser Downloader (Whonix ™), follow these instructions in Whonix-Workstation ™.

1. Launch Tor Browser Downloader.

If you are using Qubes-Whonix ™, to ensure that new AppVMs and DispVMs are created with a copy of the latest Tor Browser version, complete the following steps:

Qubes App Launcher (blue/grey "Q")Whonix-Workstation ™ TemplateVM (whonix-ws-15) → Tor Browser Downloader (Whonix ™)

If you are using Qubes-Whonix ™, to re-install the latest Tor Browser version in existing Whonix-Workstation ™ AppVMs, complete the following steps:

Qubes App Launcher (blue/grey "Q")Whonix-Workstation ™ AppVM (anon-whonix) → Tor Browser Downloader (Whonix ™)

If you are using a graphical Whonix-Workstation ™, complete the following steps:

Start MenuApplicationsSystemTor Browser Downloader (Whonix ™)

If you are using a terminal, complete the following steps:

update-torbrowser

The downloader will show it is checking for updates.

Figure: Checking for Updates

Tor Browser Downloader (Whonix ™) checking for updates.

2. Selected the preferred Tor Browser version when prompted.

Select the Tor Browser version and confirm installation. Take heed of the warning in the confirmation box stating the existing Tor Browser user profile (including bookmarks and passwords) will be lost during this process.

Figure: Download Confirmation

Tor Browser Downloader (Whonix ™) Download Confirmation

After agreeing to the download process, a progress indicator will be displayed by the downloader. This process can be lengthy depending on the speed of the Tor network connection.

Figure: Downloading Tor Browser

Tor Browser Downloader (Whonix ™) Downloading Tor Browser.

3. Check the Tor Browser signature was correctly verified.

Once the download has finished, the downloader will provide verification (or not) of the cryptographic signature associated with the Tor Browser binary, highlighting the key used to sign it and the date. The downloader will then ask for confirmation to install the package: see Installation Confirmation Notification for steps on identifying a possible targeted attack.

Figure: Tor Browser Installation Confirmation

Tor Browser Downloader (Whonix ™) Installation Confirmation.

4. Confirm installation of Tor Browser.

If the installation process is confirmed, the downloader will extract Tor Browser.

Figure: Extracting Tor Browser

Tor Browser Downloader (Whonix ™) Extracting.

5. Optional: Launch Tor Browser.

In the final step, the downloader will prompt whether the upgraded Tor Browser should be launched, unless the procedure was completed in a Qubes Whonix-Workstation ™ TemplateVM (whonix-ws-15).

Figure: Finalized Tor Browser Installation

Tor Browser Downloader (Whonix ™) Finished Installing Tor Browser.

(Also available as CLI version [archive].)

Download Confirmation Notification[edit]

This step is designed to keep Whonix ™ users safe, since at present there is no reliable and secure way for a program to determine the latest stable version of Tor Browser with reasonable certainty. [85] [86] When the version format changes, the automated parser of version information could falsely suggest:

  • An earlier stable version that is still considered secure.
  • An alpha series release.
  • A beta Tor Browser build.
  • A release candidate or nightly Tor Browser build.

Alternatively, one might be targeted by a denial of service, indefinite freeze or rollback (downgrade) attack. [87] [88]

To counter these threats, user intelligence is utilized as a sanity check. The Download Confirmation Notification provides a way to detect such situations and abort the procedure. In this instance, it is recommended to rotate the Tor circuits and attempt the download process again.

Version numbers that are visible under Online versions come from an online resource. The Tor Browser RecommendedTBBVersions [archive] versions file is provided by The Tor Project, and is parsed by Whonix ™ Tor Browser Downloader. The Whonix ™ downloader will indicate that no upgrade is required if the installed Tor Browser version matches the up-to-date online version.

TODO: expand.

Installation Confirmation Notification[edit]

This step is also designed to protect users, since at present there is no reliable and secure way for a program to determine (with reasonable certainty) if the Tor Browser download was targeted by an indefinite freeze or rollback attack. [89] [90]

When verifying cryptographic signatures, several important aspects must be considered:

  • The signature should be made by a trusted key.
  • Trusted keys will have signed other files in the past. It is also necessary to check if the right file was received, and not just any file that was signed by a trusted key.
  • Even if the correct file type is received, [91] it is necessary to check it has a current signature attached and not a historical one. This step counters the threat of indefinite freeze and rollback attacks.

By the time the Installation Confirmation Notification is visible, the verification of the signature (and hash) will have already succeeded. However, the signature creation dates in the figure below must be carefully examined to confirm that an indefinite freeze or downgrade attack did not occur.

Previous Signature Creation Date: When Tor Browser was previously installed by tb-updater, the creation date of the accompanying signature that signed Tor Browser will have been stored. The Previous Signature Creation Date field displays that date.
Last Signature Creation Date: This field displays the date of signature creation for the downloaded file.

Figure: Tor Browser Installation Confirmation

torbrowser-updater_signature_verification_screen.

[92] [93]

Note: Tor Browser local version number detection is not currently implemented [archive] in Whonix ™.

TODO: expand.

In Qubes-Whonix ™[edit]

Ambox warning pn.svg.png Do not run Tor Browser in a TemplateVM (whonix-ws-15) or DVM Template (whonix-ws-15-dvm)!

Unfortunately, updating Tor Browser is more complex than regular system updates due to technical limitations outside of Whonix's control. [94] Apply the following instructions to keep Tor Browser up-to-date at all times.

New AppVMs and DisposableVMs[edit]

In Qubes-Whonix ™, Tor Browser Downloader by Whonix (update-torbrowser) automatically runs when the Whonix-Workstation ™ TemplateVM (whonix-ws-15) package tb-updater is updated. Therefore, running Tor Browser Downloader by Whonix inside the TemplateVM (whonix-ws-15) ensures that new AppVMs and DispVMs are created with a copy of the latest Tor Browser version.

If the Tor Browser Downloader by Whonix package tb-updater has not been updated yet, it is advised to manually run it in the Whonix-Workstation ™ TemplateVM (whonix-ws-15). For instructions, see Tor Browser Downloader by Whonix ™.

DVM Template[edit]

Ambox warning pn.svg.png Do not run Tor Browser Downloader by Whonix inside the DVM Template (whonix-ws-15-dvm)! It should only be run in the TemplateVM (whonix-ws-15) or in a whonix-ws-15-based AppVM (anon-whonix). [95] [96]

For further information on installing, updating and using Tor Browser in Qubes DispVMs, see: How to use DisposableVMs in Qubes-Whonix ™.

Existing AppVMs[edit]

Follow these steps to update Tor Browser in an existing Whonix-Workstation ™ AppVM such as anon-whonix:

  1. Start Tor Browser: Qubes Start MenuWhonix-Workstation ™ AppVM (commonly called anon-whonix)Tor Browser
  2. Use Tor Browser Internal Updater.

Tor Browser Internal Updater[edit]

Tor Browser upgrades are possible from within the browser. [97] When a new Tor Browser version is available but the browser has not completed an automatic upgrade in the background (the default), a warning prompt appears recommending a manual upgrade. To upgrade, either:

  • Enter about:preferences in the URL barScroll down to "Tor Browser Updates"Click "Check for updates"; or
  • Open MenuHelpAbout Tor BrowserWait until the download finishesRestart to update Tor Browser

Figure: Tor Browser Update Notification

TBBupdater.png

Tor Browser Manual Update[edit]

Info If the Tor Browser update script ever breaks it is advised to update manually.

Modern Tor Browser releases are generally easy to install and update on well-supported platforms like Whonix ™, leading most to have a comfortable and reliable experience over long periods. However, if/when Tor Browser "breaks", some might find it difficult to perform a manual installation. [98]

Whonix ™ Bugs[edit]

Sometimes Tor Browser Downloader inside Whonix-Workstation ™ breaks because torproject.org changes the way Tor Browser can be downloaded or verified. This program is maintained by the Whonix ™ team and The Tor Project is not responsible for necessary fixes. Generally, Whonix ™ news [archive] will be published within a few days with working instructions on how to fix the problem. If this does not happen, then Whonix ™ developers are unaware of the issue.

Any bugs should be discussed in the Whonix ™ User Help Forum [archive] or Bug Tracker [archive]. To date, no bugs were ever discovered in Tor Browser that were directly related to Whonix ™ code and which might cause serious problems such as website pages failing to load.

Prerequisite Knowledge[edit]

The manual Tor Browser download procedure assumes basic knowledge of:

  • Software Verification: The Tor Browser package must be verified with PGP, using the associated file signature and Tor signing keys (relevant links are provided). [99]
  • Troubleshooting: If Tor Browser problems occur in Whonix ™ such as webpages failing to resolve, then:
    • The same tests should be performed on the host (Non-Qubes-Whonix) or in a non-Whonix ™ VM (Qubes-Whonix ™); see Non-Whonix ™ Tor Browser. This step helps to determine whether the problem is related to Whonix ™ or not.
    • It is also sensible to search for the problem on torproject.org's bug tracker [archive] and report a bug upstream if it has not been notified yet. In that case, when upstream (TPO) fixes the issue, the issue will most likely also get fixed in Whonix ™.

Unsafe Tor Browser Habits[edit]

It is important to develop a set of safe habits when communicating, browsing or downloading with Tor Browser. Even the world's premier anonymity software cannot protect people if they shoot themselves in the foot.

The following is an inexhaustive list of unsafe behaviors. It is recommended to also read the Whonix ™ Tips on Remaining Anonymous entry, along with Tor Project documentation [archive] before using Tor Browser for serious activities necessitating anonymity.

Table: Unsafe Tor Browser Habits

Category Unsafe Configuration or Behavior
Add-ons Add non-default add-ons to Tor Browser.
Configure persistent, customized NoScript settings.
Remove or disable default add-ons in Tor Browser.
Anonymity Modes Mix modes of anonymity.
Fail to compartmentalize Tor Browser activities.
Bridges Expect that Tor relay bridges will absolutely disguise all use of Tor / Tor Browser.
Browser Settings Change browser settings if the implications are unknown. [100]

Maximize or change [archive] [101] the default window size setting. [102] Letterboxing [archive] which was introduced in Tor Browser version 9 does not change this recommendation. [103]

Communications Send "anonymous" communications or other data over unencrypted channels using plain HTTP [archive].
File Downloads Torrent over Tor.
Open documents or other files downloaded by Tor while online.
Open random files or links.
Paste or type download links into the address bar without https://
Download and install unsigned software from the Internet.
Download and install signed software or import keys without first verifying key fingerprints and digital signatures.
HTML5 Canvas Image Data Allow extraction of canvas image data by websites.
Identities Disclose identifying data.
Maintain long term identities.
Use different online identities at the same time.
JavaScript Enable JavaScript for websites of a dubious nature.
Logins Login to Google, Facebook or other corporate accounts with a real name or pseudonym. [104]
Login to accounts that have ever been used without Tor.
Generally login to banking, financial, personal or other important accounts.
Local Connections Configure a local connection exception for applications, unless aware of the risks.
Networking Configure Tor Browser so that it leads to a Tor over Tor scenario.
Other Browsers Use browsers other than Tor Browser with Tor.
Use a clearnet browser and Tor Browser at the same time.
Passwords and Usernames Save passwords and usernames with the Tor Browser Password Manager [archive] feature. [105] [106] [107] [108]
Personal Websites and Links Visit personal websites over Tor.
Be the first person to spread a personal link.
Phone Verification Use (mobile) phone verification.
Proxy Settings Change or remove default proxy settings if unaware of the implications.
Qubes-Whonix ™ Launch Tor Browser in a TemplateVM (whonix-ws-15) or DVM-TemplateVM (whonix-ws-15-dvm).
Launch Tor Browser Downloader in a DVM-TemplateVM (whonix-ws-15-dvm).
Server Connections Connect to a server anonymously and non-anonymously at the same time.
Tor Browser Functions Use the "New Identity" and "New Tor Circuit for this Site" functions and expect complete anonymity in the following browsing session.
Updates Ignore download and/or installation confirmation notifications or warnings when updating Tor Browser.
Use an outdated version of Tor Browser.
User Mentality Feel invincible running Tor Browser (irrespective of the platform), due to significant adversary capabilities and interest in unmasking or infecting Tor users.

Whonix ™ Tor Browser Differences[edit]

Tor Browser Bundle versus Whonix Tor Browser[edit]

The regular Tor Browser Bundle and Whonix ™ Tor Browser slightly differ. The reason is Tor Browser must be adjusted by Whonix ™ to work behind Whonix-Gateway ™. Despite environmental variable adjustments, the network and browser fingerprint remain the same.

The main Whonix ™ Tor Browser differences can be summarized as follows: [109]

  • tor-launcher (Tor connection wizard) will not be shown in Whonix-Workstation ™ Tor Browser. Instead, Anon Connection Wizard is available in Whonix-Gateway ™.
  • The Tor Circuit View and Open Network Settings functions have been disabled. The former is unsupported for security reasons, [110] while the latter would have no effect since Tor must be configured in Whonix-Gateway ™.
  • The default landing page after Tor Browser starts is set to a local Whonix ™ resource. [111]
  • Tor over Tor scenarios are prevented in Whonix-Workstation ™. [112]
  • Extracted to folder ~/.tb/tor-browser.

Whonix ™ does not:

Tor Browser Functionality on Different Platforms[edit]

Info It is not valid to make a comparison [archive] between the Windows version of TBB and the Whonix ™ Tor Browser concerning functionality, for instance why the warning message does not appear in Whonix ™ when maximizing the browser window. [114]

The reason is this comparison includes a host of platform-specific differences which confound the result. For example, a more valid comparison would examine the differences between:

Similarly, these comparisons would be helpful in order to help with TBB (non-Whonix ™) development:

  • TBB in Debian (real Debian, not in Qubes) vs TBB in Windows.
  • TBB in different Linux distributions.
  • TBB in different Windows platforms.

Troubleshooting[edit]

Tor Browser Launch Errors[edit]

Occasionally after a new Tor Browser update is released, errors might occur upon launch. [115]

ERROR: Tor Browser ended with non-zero (error) exit code!

Tor Browser was started with:

/home/user/.tb/tor-browser/Browser/start-tor-browser --allow-remote /usr/share/homepage/whonix-welcome-page/whonix.html

Tor Browser exited with code: 1 

To see this for yourself, you could try: 
Start Menu -> System -> Xfce Terminal 
Then run: 
torbrowser

Even though this is happening inside Whonix ™, the cause is most often unrelated to Whonix ™ code. Tor Browser is developed by The Tor Project [archive], which is an independent entity. The is the norm in Linux distributions. To learn more about such relationships see Linux User Experience versus Commercial Operating Systems.

Whonix ™ does integration work to get Tor Browser into the platform. To use a simple analogy, Whonix ™ stays "on the outside". Very few internal modifications are made to Tor Browser as described in the Whonix ™ Tor Browser Differences chapter.

To remedy this kind of issue, there are three options.

Delete and Reinstall Tor Browser[edit]

If browser settings like bookmarks, saved passwords and so on are not too important, Tor Browser can be completely deleted and reinstalled. Tor Browser usually functions normally after this procedure. The easiest method is using Tor Browser Downloader by Whonix ™ for this process.

Attempt to Debug the Issue[edit]

Info Debugging attempts are not guaranteed to work, but are encouraged to help fix outstanding issues. It is suggested to directly contact The Tor Project to report the issue and any outcome/s.

Advanced users can try to start Tor Browser without the help of /usr/bin/torbrowser by Whonix ™, thereby bypassing that part of Whonix ™ Tor Browser integration. Tor Browser resides in folder ~/.tb/tor-browser. Therefore Tor Browser can be launched in Debugging Mode, which is a Tor Browser (not Whonix ™) feature.

Additionally, the whole ~/.tb/tor-browser folder could be copied to a Debian buster machine or better yet, a virtual machine. For better security, a virtual machine might even be non-networked before attempts are made to launch Tor Browser. This error is likely to be reproducible outside Whonix ™ and this step will provide confirmation.

During debug attempts, do not use /usr/bin/torbrowser or the Tor Browser start menu entry because these are provided by Whonix ™ and are not the cause here. On the other hand, The Tor Project is responsible for errors that emerge when Tor Browser is started manually or in debug mode.

Be aware the Tor Bug Tracker [archive] already has various, existing bug reports related to incremental updates via the Tor Browser internal updater. These are most likely related to Tor Browser launch failures:

Backup and Restore Browser Settings[edit]

Steps to perform a backup and restore of browser settings (like bookmarks) is currently undocumented in the Whonix ™ wiki. However, any online instructions for this process in Tor Browser or even Firefox should equally apply in Whonix ™. The only difference is the Whonix ™ Tor Browser folder location: ~/.tb/tor-browser.

Glossary and Key Terminology[edit]

Glossary[edit]

It is recommended to become familiar with terms regularly used by The Tor Project and Whonix ™. One useful resource is the v1.0 Tor glossary [archive] which is now available on The Tor Project community wiki page.

Key Terminology[edit]

Tor vs Tor Browser[edit]

Tor is an anonymizer developed by The Tor Project. Tor Browser is a web browser developed by the Tor Project which is optimized for privacy. Please do not confuse Tor with Tor Browser when conversing about Whonix ™ topics.

Tor Browser Transparent Proxying[edit]

The Tor Browser "transparent proxying" feature [116] and/or the environment variable TOR_TRANSPROXY=1 often cause confusion. It was an unfortunate naming decision by The Tor Project. This feature actually removes proxy settings. With no proxy set, the user's system reverts to its default configuration. The effect of this decision is that Tor Browser networking will work in a similar fashion to an unconfigured Firefox browser.

This is potentially dangerous when done outside of Whonix ™ because Tor Browser's transparent proxying feature could result in clearnet traffic; for instance if the gateway does not have a transparent torification feature (like Whonix-Gateway ™). In the case of Whonix ™, even if the transparent proxying feature is set, Whonix-Gateway ™ will "torify" traffic and force it through Tor. Similarly, if transparent proxying is set and happens to use a JonDo-Gateway, traffic will be forced through JonDo.

One downside of the transparent proxying feature is that even when it is used inside Whonix ™, it breaks Tor Browser's top level isolation for each separate tab [archive].

Transparent proxying should not be confused with:

TODO: expand.

Advanced Users[edit]

Refer to this wiki entry if any of the following advanced topics are of interest:

  • Tor Browser and former Torbutton design.
  • Tor Browser without Tor.
  • Setting a custom homepage.
  • A custom Whonix ™ configuration or Workstation is in use.
  • Proxy settings changes are necessary.
  • Differences between tor-launcher and tor-browser launcher.
  • Qubes-Whonix ™ topics:
    • Split Tor Browser.
    • Tor Browser in a DisposableVM.
    • Tor Browser in a Qubes DVM Template.
  • Tor Browser debugging is required.

Running Tor Browser in Qubes DVM Template[edit]

This entry has been moved here.

Footnotes / References[edit]

  1. For a comprehensive list of reasons, readers are encouraged to review some or all of the references in this section.
  2. https://tb-manual.torproject.org/ [archive]
  3. https://blogs.gnome.org/muelli/2018/12/the-patch-that-converts-a-firefox-to-a-tor-browser/ [archive]
  4. A good overview of the browser component is provided by The Tor Project design document [archive].

    The Tor Browser is based on Mozilla's Extended Support Release (ESR) Firefox branch. We have a series of patches against this browser to enhance privacy and security. Browser behavior is additionally augmented through the Torbutton extension, though we are in the process of moving this functionality into direct Firefox patches. We also change a number of Firefox preferences from their defaults.

    Tor process management and configuration is accomplished through the Tor Launcher add-on, which provides the initial Tor configuration splash screen and bootstrap progress bar. Tor Launcher is also compatible with Thunderbird, Instantbird, and XULRunner.

    To help protect against potential Tor Exit Node eavesdroppers, we include HTTPS-Everywhere. To provide users with optional defense-in-depth against JavaScript and other potential exploit vectors, we also include NoScript. We also modify several extension preferences from their defaults.

    To provide censorship circumvention in areas where the public Tor network is blocked either by IP, or by protocol fingerprint, we include several Pluggable Transports in the distribution. As of this writing, we include Obfs3proxy, Obfs4proxy, Scramblesuit, meek, and FTE.

  5. DNS is a distributed database which keeps track of computer's names and their corresponding IP addresses on the Internet https://web.stanford.edu/class/msande91si/www-spr04/readings/week1/InternetWhitepaper.htm [archive]. DNS servers enable the browser to know where resources are located on the Internet, and the corresponding IP address for fetching these.
  6. See below for a further description of these features.
  7. On average. Mid-2019 has seen a sudden spike to over 3 million users -- in recent years, sharp increases in the number of Tor clients were suspected to be adversary attacks on the network.
  8. 8.0 8.1 https://en.wikipedia.org/wiki/HTTPS [archive]
  9. HTTPS is not foolproof due to reliance on the Certificate Authority (CA) system that issues digital certificates (private keys) for websites. As a trusted third party, this trust can be abused or the CAs can be subject to adversary attacks.
  10. https://2019.www.torproject.org/docs/faq#AmITotallyAnonymous [archive]
  11. https://www.whonix.org [archive]
  12. https://www.eff.org/pages/tor-and-https [archive]
  13. https://riseup.net/en/security/network-security/tor/onionservices-best-practices [archive]
  14. This does not however defend against improved cryptanalysis that breaks underlying ciphers being used, for example by the emergence of quantum computers. Only post-quantum ciphers resistant to these attacks will prevail.
  15. https://2019.www.torproject.org/docs/onion-services [archive]
  16. Extra layers of encryption are not strictly necessary, since a completely encrypted tunnel is already formed (but it certainly does not hurt). Until recently, these certificates would not validate because of the *.onion hostname.
  17. https://riseup.net/en/security/network-security/tor/onionservices-best-practices [archive]
  18. https://blog.torproject.org/blog/cooking-onions-names-your-onions [archive]
  19. This is why onion addresses appear absurdly long and random.
  20. Experienced Tor developer Mike Perry has noted that even with scripts globally enabled, NoScript still provides significant protection in Tor Browser [archive]:

    We provide NoScript mostly for the non-filter features it provides, such as click-to-play for media, webgl and plugins, XSS protection, remote font blockage, and so on.

  21. 21.0 21.1 21.2 https://en.wikipedia.org/wiki/NoScript [archive]
  22. XSS effects vary in range from petty nuisance to significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner.

  23. Anti-clickjacking [archive] was previously available to protect against hidden or disguised user interface elements masquerading as trusted web page buttons, links and so on. This is no longer available following the shift to Firefox extensions in Tor Browser based on Firefox 60 ESR. This feature protected against malicious activation of microphones or webcams, as well as user interaction with hidden elements to steal important financial, personal or other data.
  24. https://ianix.com/pub/firefox-addons-and-bandwidth-consumption.html [archive]
  25. https://2019.www.torproject.org/docs/faq#TBBJavaScriptEnabled [archive]
  26. Javascript has previously been used in Windows to deanonymize Tor Browser users with a zero-day exploit [archive] which revealed the computer's MAC address to the attackers.
  27. Having a large user base is important for strong anonymity, as Roger Dingledine explains here [archive].
  28. Another related discussion justifying JavaScript's enabling by default was held on tor-talk; see Tor Browser disabling Javascript anonymity set reduction [archive].
  29. The Tor Project bug report: NoScript configured to globally allow all scripts [archive]
  30. https://noscript.net/ [archive]
  31. Even if the manpower existed, it would make more sense to establish a new "Privacy Browser" project, rather than merge its development with Whonix ™. At a later stage, the theoretically more secure browser could then be bundled with the Whonix ™ platform.
  32. Whonix ™ includes Tor Browser by default, with only minor differences.
  33. Although there are unresolved tbb-fingerprinting [archive] and tbb-linkability [archive] issues.
  34. This preference was first offered in alpha Tor Browser v8.5a2, but is now available in both the alpha and stable Tor Browser series.
  35. https://trac.torproject.org/projects/tor/ticket/27175 [archive]
  36. 36.0 36.1 https://trac.torproject.org/projects/tor/ticket/27175#comment:12 [archive]
  37. https://blog.torproject.org/new-release-tor-browser-85a2 [archive]
  38. The default Tor Browser setting.
  39. 39.0 39.1 https://tb-manual.torproject.org/plugins/ [archive]
  40. https://support.mozilla.org/en-US/kb/find-and-install-add-ons-add-features-to-firefox [archive]
  41. For example, most videos [archive] can be viewed in HTML5 which Tor Browser supports and prefers.
  42. DoNot#Confuse_Anonymity_with_Pseudonymity
  43. https://2019.www.torproject.org/docs/torbutton/torbutton-faq.html.en [archive]
  44. https://blog.torproject.org/blog/torbutton-141-released [archive]
  45. See tbb-linkability [archive] and tbb-fingerprinting [archive].
  46. https://trac.torproject.org/projects/tor/ticket/9442 [archive]
  47. https://tails.boum.org/doc/anonymous_internet/Tor_Browser/index.en.html [archive]
  48. https://tb-manual.torproject.org/en-US/security-slider.html [archive]
  49. https://blog.torproject.org/new-release-tor-browser-85 [archive]
  50. https://trac.torproject.org/projects/tor/ticket/29825 [archive]
  51. /usr/bin/torbrowser simply navigates to the Tor Browser folder and runs ./start-tor-browser. The former has more features like reporting error conditions or the absence of a Tor Browser folder, generation of non-zero exit code failures, and more.
  52. Or manually navigate to the Tor Browser folder and then launch it in debugging mode.
    cd ~/.tb/tor-browser/Browser
    ./start-tor-browser --debug
  53. https://www.torproject.org/download/download [archive]
  54. And that website does not:
  55. https://blog.torproject.org/new-release-tor-browser-80 [archive]
  56. https://blog.torproject.org/new-release-tor-browser-90 [archive]
  57. https://www.torproject.org/download/languages/ [archive]
  58. Language packs might be another fingerprinting vector, but this issue requires further investigation.
  59. Since it uses predetermined ports on the localhost.
  60. https://trac.torproject.org/projects/tor/ticket/10419 [archive]
  61. https://trac.torproject.org/projects/tor/ticket/11493 [archive]
  62. Alternatively it is possible to remove Tor Browser's proxy settings, but this method is still vulnerable to the same fingerprinting issues as configuring an exception. There are also other factors which will worsen the user's fingerprint, such as the breaking of both stream isolation and the tab isolation by socks user name in Tor Browser.
  63. https://trac.torproject.org/projects/tor/wiki/org/doc/ListOfServicesBlockingTor#Ad-hocSolutionsforaccessingblockedcontentonTor [archive]
  64. Source: Ad-hoc Solutions for accessing blocked content on Tor [archive]
    License: Content on this site is Copyright The Tor Project, Inc.. Reproduction of content is permitted under a Creative Commons Attribution 3.0 United States License [archive].
  65. See also: hidester.com/proxy and youtubeunblocks.com/
  66. https://trac.torproject.org/projects/tor/wiki/org/doc/ListOfServicesBlockingTor#Otherrelevantservices [archive]
  67. It confines programs according to a set of rules that specify what files a given program can access, and with what privileges. This also provides some protection against zero-day attacks and exploits via unknown application flaws.
  68. If AppArmor is applied, Tor Browser can only read and write to a limited number of folders. Permission denied errors are quite common, for example when trying to download files directly to the home folder.
  69. The workaround for AppArmor denied errors is saving files from Tor Browser to the ~/Downloads folder that is located within the home folder. In order to upload files with Tor Browser, first copy them to that folder.
  70. tb-starter [archive] will enable the Tor Browser Firejail profile. development discussion [archive]
  71. The Tor Project does not currently provide a hardened / sandboxed Tor Browser build, see: Stop building and distributing sandboxed-tor-browser binaries [archive].
  72. Linux Sandboxed Tor Browser Documentation [archive]:

    WARNING: This project is no longer maintained. DO NOT EXPECT ANY FURTHER FIXES, INCLUDING SECURITY AND STOP USING THIS AS SOON AS POSSIBLE.

    WARNING: There are several unresolved issues that affect security and fingerprinting. Do not assume that this is perfect, merely "an improvement over nothing".

    WARNING: Active development is on indefinite hiatus. DO NOT EXPECT ANY SIGNIFICANT NEW FEATURES OR IMPROVEMENTS.

  73. https://forums.whonix.org/t/tor-browser-hardening-hardened-malloc-firejail-apparmor-vs-web-fingerprint/7851 [archive]
  74. This does not protect against the sudden loss of networking, which could reveal to the attacker that two activities / accounts suddenly going off-line are probably related.
  75. https://trac.torproject.org/projects/tor/ticket/25540 [archive]
  76. This does not protect against potential infection of dom0 or the Whonix-Workstation ™ DisposableVM-Template by advanced adversaries. Traces of activity may also be left on storage media or in RAM.
  77. https://blog.torproject.org/new-release-tor-browser-90a1 [archive]
  78. Selfrando [archive] (load-time memory randomization) protection is being removed from alpha Tor Browser Linux builds [archive]. Although Selfrando provides a security improvement over standard address space layout randomization (ASLR) present in Tor Browser and other browsers, Tor developers believe it is relatively easy for attackers to bypass and not worth the effort.
  79. The "hardened" Tor Browser series has been deprecated, see: https://trac.torproject.org/projects/tor/ticket/21912 [archive]
  80. Following the official release of the v8.0+ Tor Browser series (based on Firefox 60 ESR), the stable and alpha Tor Browser versions both have a native sandbox [archive].
  81. Tor Browser Update:Technical Details
  82. This does not yet notice upgrades [archive] performed by Tor Browser's Internal Updater.
  83. Since v5.0, Tor Browser is configured to update itself [archive].
  84. https://tb-manual.torproject.org/en-US/updating.html [archive]
  85. Finalize RecommendedTBBVersions format [archive]
  86. Counter downgrade / stale mirror attacks on RecommendedTBBVersions - sign / verify tbb versions file [archive]
  87. For a definition of these attacks, see the threat model [archive] of TUF [archive] (The Update Framework [archive]) (w [archive]).
  88. Adversaries capable of breaking SSL could mount these attacks by replacing RecommendedTBBVersions [archive] with invalid, frozen or outdated version information.
  89. Unfortunately, Tor Browser signatures do not yet provide expiration dates in a manner similar to Debian's valid-until [archive] field.
  90. Rollback attacks are possible because if a computer's clock is wrong, there is no solid basis for comparison.
  91. That is, a browser and not a messenger or other application.
  92. GnuPG (OpenPGP) common misconceptions.
  93. The name of the file is stored in the hash file and verified to match the downloaded file name and hash.
  94. Tor Browser Update: Technical Details
  95. It is possible to run Tor Browser Downloader by Whonix inside a DispVM as well -- probably easiest using Tor Browser Internal Updater -- and then restart Tor Browser. However, these updates will not persist due to the DispVM design.
  96. See tb-updater in Qubes Template VM for technical details.
  97. https://blog.torproject.org/blog/tor-browser-50-released [archive]

    Starting with this release, Tor Browser will now also download and apply upgrades in the background, to ensure that users upgrade quicker and with less interaction. This behavior is governed by the about:config pref app.update.auto, but we do not recommend disabling it unless you really know what you're doing.

  98. Before the introduction of Tor Browser's internal updater, manual installation was a difficult task which required the renaming (or deletion) of the old Tor Browser folder before the new version was extracted. If Tor Browser functions "under the hood" are a mystery, then unsurprisingly problems are often encountered during manual installation, particularly on the host.
  99. Whonix ™ is not a standalone package, but a complete operating system. Whonix ™ has a small team, while torproject.org has a much larger community and dedicated, paid support staff. Therefore, Whonix ™ users are expected to learn Tor Browser basics in the first instance.
  100. For example, it is unsafe to disable Tor Browser protections in order to save cookies [archive] for the sake of convenience.
  101. https://forums.whonix.org/t/should-still-recommend-against-maximizing-tor-browser-window [archive]
  102. New Release: Tor Browser 9.0 [archive]:

    Tor Browser in its default mode is starting with a content window rounded to a multiple of 200px x 100px to prevent fingerprinting the screen dimensions. The strategy here is to put all users in a couple of buckets to make it harder to single them out. That worked so far until users started to resize their windows (e.g. by maximizing them or going into fullscreen mode). Tor Browser 9 ships with a fingerprinting defense for those scenarios as well, which is called Letterboxing, a technique developed by Mozilla and presented earlier this year. It works by adding white margins to a browser window so that the window is as close as possible to the desired size while users are still in a couple of screen size buckets that prevent singling them out with the help of screen dimensions.

  103. Anonymous (not verified) said [archive]:

    Is using the default window size still recommended?

    gk said [archive]:

    Yes, the default size is still recommended. But, if users are resizing their window they should get some protection now. Before that we only had the notification bar popping up and essentially saying "Don't do that! Danger!" which was kind of lame. Now, we have something better to offer which fits more to our privacy-by-design goal.

  104. https://2019.www.torproject.org/docs/faq.html.en#AmITotallyAnonymous [archive]
  105. https://forums.whonix.org/t/tor-browser-8-5-in-whonix-no-longer-can-save-passwords-and-it-deleted-all-existing-ones/7424 [archive]
  106. Mozilla notes:

    Even though the Password Manager stores your usernames and passwords on your hard drive in an encrypted format, someone with access to your computer user profile can still see or use them. The Use a Master Password to protect stored logins and passwords article shows you how to prevent this and keep you protected in the event your computer is lost or stolen.

  107. Unless a strong master password is used to protect usernames and passwords, anyone with access to the computer (remote or physical) can easily see them; see here [archive] for further information. Due to their relatively large attack surface, security professionals suggest it is far safer to use a password manager rather than trust browsers with sensitive information.
  108. A critical security bug [archive] was found in the Password Manager in 2018: "If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible."
  109. https://trac.torproject.org/projects/tor/ticket/19652 [archive]
  110. This is so Whonix-Workstation ™ does not have access to the information about which Tor middle relay or Tor entry guard [or bridge] are in use. See also: Dev/Control_Port_Filter_Proxy#Indicator_for_current_Circuit_Status_and_Exit_IP.
  111. The default Tor Browser Bundle uses about:tor as the landing page. See: https://trac.torproject.org/projects/tor/ticket/13835 [archive]
  112. Dev/anon-ws-disable-stacked-tor
  113. In Whonix-Workstation ™, anon-ws-disable-stacked-tor [archive] listens on 127.0.0.1 9150 and 9151 (Tor Browser's default ports) and forwards them to Whonix-Gateway ™ 10.152.152.10 9150 (where a Tor SocksPort is listening) and 9151 (where Control Port Filter Proxy is listening). Tor does not get started by the tor-launcher [archive] Firefox add-on because the TOR_SKIP_LAUNCH [archive] environment variable has been set set to 1. See also: Dev/anon-ws-disable-stacked-tor.
  114. No changes have been made in Whonix ™ code to prevent such a warning.
  115. https://forums.whonix.org/t/tor-browser-error-perhaps-from-9-0-1-update/8468 [archive]
  116. https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy [archive]

License[edit]

Whonix ™ Tor Browser Basics wiki page Copyright (C) Amnesia <amnesia at boum dot org>

Whonix ™ Tor Browser Basics wiki page Copyright (C) 2012 - 2019 ENCRYPTED SUPPORT LP <adrelanos@riseup.net>

This program comes with ABSOLUTELY NO WARRANTY; for details see the wiki source code.

This is free software, and you are welcome to redistribute it under certain conditions; see the wiki source code for details.



Follow: Twitter.png Facebook.png 1280px-Gab text logo.svg.png Rss.png Matrix logo.svg.png 1024px-Telegram 2019 Logo.svg.png Discourse logo.svg

Donate: Donate Bank Wire Paypal Bitcoin accepted here Monero accepted here Contriute

Whonix donate bitcoin.png Monero donate whonix.png

Share: Twitter | Facebook

There are five different options [archive] for subscribing to Whonix source code changes.

https [archive] | (forcing) onion [archive]

This is a wiki. Want to improve this page? Help is welcome and volunteer contributions are happily considered! Read, understand and agree to Conditions for Contributions to Whonix ™, then Edit! Edits are held for moderation.

Copyright (C) 2012 - 2019 ENCRYPTED SUPPORT LP. Whonix ™ is a trademark. Whonix ™ is a licensee [archive] of the Open Invention Network [archive]. Unless otherwise noted, the content of this page is copyrighted and licensed under the same Freedom Software license as Whonix ™ itself. (Why?)

Whonix ™ is a derivative of and not affiliated with Debian [archive]. Debian is a registered trademark [archive] owned by Software in the Public Interest, Inc [archive].

Whonix ™ is produced independently from the Tor® [archive] anonymity software and carries no guarantee from The Tor Project [archive] about quality, suitability or anything else.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent. Whonix ™ is provided by ENCRYPTED SUPPORT LP. See Imprint.