← Privacy Guides

Browsing & network

Tor Browser at the Safest level, and when to step up to Whonix

Browse anonymously under a serious threat: get Tor Browser from the Tor Project, verify its signature, set the security level to Safest, avoid the behaviours that unmask you, and move to Whonix when an app compromise leaking your real IP would be unacceptable.

  • High threat
  • Time 45 minutes
  • Difficulty Advanced
  • Last verified

What this protects, and what it doesn't

Protects

  • Tor spreads trust across three relays: no single relay knows both who you are and which site you reach.
  • The Safest security level disables JavaScript and other active content on every site, shrinking what a hostile page can run against your browser.
  • Verifying the signature confirms the installer really came from the Tor Project and was not altered in transit or on a mirror.
  • Whonix routes everything through a separate gateway virtual machine, so even malware with root on the workstation has no route to your real IP address.

Does not protect

  • It does not hide you from any account you log in to. A real name, email address or logged-in session identifies you no matter how you connect.
  • It does not encrypt the last hop. Without HTTPS, data such as a username and password can be read on the connection once it leaves the Tor network.
  • It does not defend against an adversary who can watch both your connection into Tor and the traffic leaving it and match the timing. The Tor Project states plainly: "Tor does not defend against such a threat model."
  • It does not help if your own device is already compromised. A keylogger or malware on the endpoint sees everything before Tor does; Whonix limits this but does not remove it, because a compromised workstation still exposes the data it holds.
  • It is not a one-click anonymiser. Whonix says so directly: anonymity depends on your behaviour as much as the technology.

Prerequisites

  • A written threat model (see the start-here guide) that genuinely puts you at the High level: a hostile, well-resourced adversary actively interested in you.
  • GnuPG installed so you can verify the download: Gpg4win on Windows, GPGTools on macOS, usually preinstalled on GNU/Linux.
  • For the Whonix step only: a host that can run virtual machines and some comfort working with them.

Step by step

  1. Download Tor Browser from the Tor Project only

    Get Tor Browser from the Tor Project's own site over HTTPS: https://download.torproject.org/ (linked from torproject.org). Never take it from an app store listing of unknown origin, a file-sharing link or a search advert.

    If the Tor Project website is blocked where you are, the Tor Project offers two official fallbacks: its official mirrors (through the EFF or La Cebolla), or GetTor — email gettor@torproject.org with your operating system (windows, osx, linux or android) in the body, and the reply gives download links, the signature, the signing-key fingerprint and the checksum.

  2. Verify the signature before you run it

    At this threat level, verify the download so you know it is genuine. Download the installer and its matching .asc signature file from the same page, then use GnuPG.

    Import the Tor Browser Developers signing key (fingerprint EF6E286DDA85EA2A4BA7DE684E2C6E8793298290):

    gpg --auto-key-locate nodefault,wkd --locate-keys torbrowser@torproject.org

    Export it to a keyring file:

    gpg --output ./tor.keyring --export 0xEF6E286DDA85EA2A4BA7DE684E2C6E8793298290

    Then check the signature. Replace the example filename below with the exact names you downloaded:

    gpgv --keyring ./tor.keyring ~/Downloads/tor-browser-linux-x86_64-<version>.tar.xz.asc ~/Downloads/tor-browser-linux-x86_64-<version>.tar.xz

    A good result contains the line: gpgv: Good signature from "Tor Browser Developers (signing key) <torbrowser@torproject.org>". If the key import fails, the Tor Project documents a workaround that imports the public key directly. Do not install a download whose signature does not verify.

  3. Set the security level to Safest

    Tor Browser has three security levels: Standard (everything enabled, the default), Safer (JavaScript off on non-HTTPS sites, some fonts and math symbols disabled, HTML5 audio and video click-to-play) and Safest.

    At Safest, the Tor Project states that "Javascript is disabled by default on all sites"; some fonts, icons, math symbols and images are also disabled, and audio and video are click-to-play. Only the features needed for static sites and basic services remain. This is the level to use under a serious threat, because disabling scripts removes a large class of browser attacks — at the cost of breaking sites that depend on JavaScript.

    On desktop, open the shield icon next to the address bar and choose Change to open the security level settings, then select Safest.

    Do not loosen the level "just for one site". If a site will not work at Safest and you cannot accept the risk of raising it, treat that as a reason not to visit it this way.

  4. Avoid the behaviours that unmask you

    Tor Browser protects the connection; your behaviour can still give you away. Following the Tor Project's own guidance:

    • Do not log in to accounts tied to your real identity in a session meant to be anonymous. The site then knows exactly who you are, and logging in from a distant Tor exit can even trip a bank or email provider into locking the account.
    • Do not maximise or resize the window. Window dimensions are a fingerprinting signal; Tor Browser keeps a default content size and adds grey margins (letterboxing) to keep you in a shared size group. Resizing or going fullscreen works against that — leave the window as it opens.
    • Do not open documents downloaded over Tor while you are still online. The Tor Project warns under the heading "Don't open documents downloaded through Tor while online" that some files fetch resources outside Tor and can reveal your real IP. Open them on an offline machine, or sanitise PDFs with a tool such as Dangerzone.
    • Do not install add-ons or plugins "to improve privacy". The Tor Project says they "can be manipulated into revealing your IP address" and extra add-ons may bypass Tor. Use Tor Browser as shipped.
    • Keep anonymous and non-anonymous activity apart. Reusing a username, or doing identifiable things in the same session, links the two. Use New Identity to start fresh when switching contexts.
  5. Know what Tor Browser cannot do for you

    Even used perfectly, Tor has limits you must plan around:

    • The last hop is only as private as HTTPS. Tor encrypts inside the network, not from the exit to the website. Without HTTPS, data such as a username and password can be visible once the traffic leaves Tor. Check for HTTPS (and the onion icon for onion services) before sending anything sensitive.
    • Timing correlation. An adversary who can observe both your entry into Tor and the traffic leaving it can match the timing; the Tor Project says "Tor does not defend against such a threat model". Tor reduces, not eliminates, the power of a very large observer.
    • The endpoint still matters. If your operating system is already compromised, Tor cannot save you — which is exactly the gap the next step closes.
  6. Step up to Whonix when an IP leak would be catastrophic

    Plain Tor Browser runs beside everything else on your computer. If a single browser or application exploit can reach the network directly, it can leak your real IP. When that outcome is unacceptable, isolate Tor from the applications with Whonix.

    Whonix runs as two virtual machines: the Whonix-Gateway runs Tor and is the only path to the internet, and the Whonix-Workstation runs your applications on an isolated network that can reach the internet only through the Gateway. Because the Workstation has no route to your real IP, the Whonix project states that "Malware with root privileges cannot discover the user's real IP address," and that DNS/IP/UDP/ICMP leaks are prevented by design.

    Understand the boundary of that protection: Whonix's own documentation says the real IP "is never leaked since this requires a compromise of the Whonix-Gateway", but if the Workstation is compromised "the attacker has access to the data it contains" — credentials, files and anything that can identify you. Whonix also notes it "is not a one-click anonymization solution".

    Install Whonix only from the project's own site and follow its documentation; it is a larger commitment than a single browser. If you also need to leave no trace on the computer itself, compare the amnesic approach in the Tails guide.

Common mistakes

  • Logging in to a real email, social or bank account in the same Tor session you use for sensitive browsing — it ties the whole session to you.
  • Maximising or resizing the Tor Browser window; let letterboxing keep the default size instead.
  • Opening a PDF or Office file downloaded over Tor while still online — it can fetch resources outside Tor and expose your IP.
  • Installing extra add-ons or plugins "for privacy": they can be manipulated into revealing your IP or can bypass Tor.
  • Downloading from an app store of unknown origin or an unofficial mirror, or skipping signature verification.
  • Relying on plain Tor Browser for a threat where one application exploit leaking your IP would be catastrophic, instead of isolating Tor with Whonix.

Going further

Read the Tor Project's support pages and, before relying on Whonix, its own documentation — the two-VM setup is a real commitment. For the comparison between hiding your IP and spreading trust, see VPN or Tor; for an amnesic system that routes everything through Tor and leaves nothing on the computer, see Tails. None of this replaces a current threat model: revisit it whenever your situation changes.