Front page / Before you arrive

A Tor Browser copy that is genuinely yours

Not the idea of the browser. The specific installed copy sitting on your disk, which came from somewhere you picked, at a version you can name.

Goes stale Before you arrive

Awazon market mirror addresses

Published, never tested here
awazonth6ocz5cyos63czmhtsglqr7ydkdcc4lopux7nxbauoo2qmvyd.onion
awazonvaqbgkhirejon6qnlxcjibrhkqhzh2xb2lclc6t67vxhlvjkyd.onion
awazonvjpi6bdysnad23ydgscomsku53wnfewrbbpxobvzow5xe6nyyd.onion

These are printed as published, in the order they were given. This site runs no checks against them, holds no opinion on whether any of them answers at this moment, and prints no uptime figure and no checking date. An address that loads is still not proof of anything, which is what a fingerprint you collected yourself is for.

What it is
An installed copy of Tor Browser on a machine you use, obtained by you, at a version number you could state out loud.
How you get one
You go to the source yourself, download the installer, and install it, rather than accepting a copy someone else provided.
Where to keep it
On the machine you actually intend to use, with the installer kept long enough to confirm what you installed.
How it goes wrong
It ages out of date in the background while working perfectly, so nothing tells you the build is old.
What fails without it
You are trusting a package whose history you cannot describe, and every later precaution rests on that package.
Time to acquire
One sitting for the download and install, then a recurring few minutes whenever an update is offered.

The artifact is the copy on your disk

People talk about Tor Browser as though there is one of them. There is not. There is a project that releases builds, and then there are millions of individual copies scattered across machines, each with its own version, its own history and its own origin. The one that matters to you is the one on your disk, and it is the only one you can say anything about.

So the question this entry asks is narrow. Where did your copy come from, and can you describe the answer without hedging? Most people cannot, and the reason is usually that at some point somebody else was involved.

A copy someone handed you is a different object

A build passed along on a memory stick, sent in an archive, mirrored on a file host, or bundled into something else has an extra step in its history, and that step belongs to a person rather than to you. It might be identical to the official release. You have no way to know that from looking, and looking is what people do instead of knowing.

The correction is boring. Fetch it yourself, from the project, on the machine you will use. Doing that once costs one evening at most and removes an entire category of question you would otherwise carry into the login stage, where you will already have enough to think about.

Knowing what you have installed

Two small habits make the copy describable rather than assumed.

  • Note the version at the time you install it, in the same place you keep everything else. The writing surface entry covers where that place should be.
  • Keep the installer file until you have used the browser once. If the installed copy behaves oddly, having the exact thing you ran is worth more than any recollection of where you got it.
  • Record the source as a name you would recognise later, not as the word official, which is a word people apply to whatever they downloaded.
  • When an update is offered, take it and update the version you wrote down. An old note attached to a new build is its own small trap.

What an old build costs

A stale build does not fail loudly. It starts, it connects, it renders pages, and it looks exactly like a current one. What has changed is that fixes released since your build exist in the world and are not in your copy, and the gap grows quietly the whole time you are not thinking about it.

There is a second cost that is easier to overlook. Old builds behave differently from current ones in ways that make your copy stand out from the crowd it is meant to blend into. A browser whose whole purpose is to look like every other browser of its kind stops doing that job the moment it falls a few versions behind, and nothing on screen tells you it has happened.

SCOPENothing here is advice on configuring the browser. The entry is about the provenance of the copy you hold. Settings belong to a different conversation and this site does not have it.

Signs the copy is not the one you fetched

Worth a slow look occasionally. A version number that does not match what you wrote down. An install path you do not remember choosing. Extensions present that you did not add. A start page that is not what shipped. Any of those means the object on your disk has diverged from the object in your head, and the cheapest fix is to remove it and fetch a fresh one rather than to reason about how it got that way.

The same reasoning applies to the machine holding all this, which is the subject of the next entry, and to the key material you keep in your own key. Provenance is the same question every time. Where did this come from, and who else touched it on the way.

Questions that come up

Does the operating system matter?

For this entry, only in that it changes where the copy lives and how easy it is to confirm what you installed. The point being made holds on any platform: an installed copy has a history, and you either know that history or you are guessing about it. Platforms differ in how much they help you check, and some of them help very little, which is worth knowing before you rely on the check.

Should I keep an old version around in case the new one breaks?

Keeping the previous installer is reasonable insurance for a short window. Keeping a library of old builds is not, because the collection becomes the thing you reach for when you are in a hurry, and in a hurry you will pick by filename rather than by date. If you keep one, keep exactly one, and write the date next to it so the choice is never a guess.