- What it is
- An installed copy of Tor Browser on a machine you use, obtained by you, at a version number you could state out loud.
- How you get one
- You go to the source yourself, download the installer, and install it, rather than accepting a copy someone else provided.
- Where to keep it
- On the machine you actually intend to use, with the installer kept long enough to confirm what you installed.
- How it goes wrong
- It ages out of date in the background while working perfectly, so nothing tells you the build is old.
- What fails without it
- You are trusting a package whose history you cannot describe, and every later precaution rests on that package.
- Time to acquire
- One sitting for the download and install, then a recurring few minutes whenever an update is offered.
The artifact is the copy on your disk
People talk about Tor Browser as though there is one of them. There is not. There is a project that releases builds, and then there are millions of individual copies scattered across machines, each with its own version, its own history and its own origin. The one that matters to you is the one on your disk, and it is the only one you can say anything about.
So the question this entry asks is narrow. Where did your copy come from, and can you describe the answer without hedging? Most people cannot, and the reason is usually that at some point somebody else was involved.
A copy someone handed you is a different object
A build passed along on a memory stick, sent in an archive, mirrored on a file host, or bundled into something else has an extra step in its history, and that step belongs to a person rather than to you. It might be identical to the official release. You have no way to know that from looking, and looking is what people do instead of knowing.
The correction is boring. Fetch it yourself, from the project, on the machine you will use. Doing that once costs one evening at most and removes an entire category of question you would otherwise carry into the login stage, where you will already have enough to think about.
Knowing what you have installed
Two small habits make the copy describable rather than assumed.
- Note the version at the time you install it, in the same place you keep everything else. The writing surface entry covers where that place should be.
- Keep the installer file until you have used the browser once. If the installed copy behaves oddly, having the exact thing you ran is worth more than any recollection of where you got it.
- Record the source as a name you would recognise later, not as the word official, which is a word people apply to whatever they downloaded.
- When an update is offered, take it and update the version you wrote down. An old note attached to a new build is its own small trap.
What an old build costs
A stale build does not fail loudly. It starts, it connects, it renders pages, and it looks exactly like a current one. What has changed is that fixes released since your build exist in the world and are not in your copy, and the gap grows quietly the whole time you are not thinking about it.
There is a second cost that is easier to overlook. Old builds behave differently from current ones in ways that make your copy stand out from the crowd it is meant to blend into. A browser whose whole purpose is to look like every other browser of its kind stops doing that job the moment it falls a few versions behind, and nothing on screen tells you it has happened.
Signs the copy is not the one you fetched
Worth a slow look occasionally. A version number that does not match what you wrote down. An install path you do not remember choosing. Extensions present that you did not add. A start page that is not what shipped. Any of those means the object on your disk has diverged from the object in your head, and the cheapest fix is to remove it and fetch a fresh one rather than to reason about how it got that way.
The same reasoning applies to the machine holding all this, which is the subject of the next entry, and to the key material you keep in your own key. Provenance is the same question every time. Where did this come from, and who else touched it on the way.
Questions that come up
Does the operating system matter?
For this entry, only in that it changes where the copy lives and how easy it is to confirm what you installed. The point being made holds on any platform: an installed copy has a history, and you either know that history or you are guessing about it. Platforms differ in how much they help you check, and some of them help very little, which is worth knowing before you rely on the check.
Should I keep an old version around in case the new one breaks?
Keeping the previous installer is reasonable insurance for a short window. Keeping a library of old builds is not, because the collection becomes the thing you reach for when you are in a hurry, and in a hurry you will pick by filename rather than by date. If you keep one, keep exactly one, and write the date next to it so the choice is never a guess.