Introduction: Go Online Without Getting Snooped: Tor (The Onion Router)

When you go online, you leave tracks all over the place. You could be hanging out with friends on IM, checking out websites, or downloading music. If you live in a country where snoops are prying into what ordinary citizens do online (lke, um, the US) you want a way to cover those tracks.

If you're in school, though, then it's even worse. No matter what country you're in, chances are that your access to the internets is as snooped-on as any police state in the world.

So, how do we escape our little virtual prisons? In this Instructable, I'll tell you about something called Tor (The Onion Router.) I'll tell you how it works, and then offer some simple instructions on how to get your web browser hooked up. No more getting snooped!

Step 1: How Tor Works

An "onion router" is an Internet site that takes requests for web-pages and passes them onto other onion routers, and on to other onion routers, until one of them finally decides to fetch the page and pass it back through the layers of the onion until it reaches you. The traffic to the onion-routers is encrypted, which means that the school can’t see what you’re asking for, and the layers of the onion don’t know who they’re working for. There are millions of nodes—the program was set up by the US Office of Naval Research to help their people get around the censorware in countries like Syria and China, which means that it’s perfectly designed for operating in the confines of an average American high-school.

Tor works because the school has a finite blacklist of naughty addresses we aren’t to visit, and the addresses of the nodes change all the time—no way could the school keep track of them all.

There's a more complete overview, here, but let's get on to installing Tor.

Step 2: Install Tor

Tor is pretty easy to install. You can leave most of the defaults as-is. First, go to the download page to get the latest version of Vidalia (which bundles Tor and a few other good privacy apps.) Get the right one for your operating system. Then follow the instructions to install it. The "Install and Configure" guides next to every package on that page are really helpful.

A screenshot of the installed Vidalia app on OS X is below. The window shows that Tor is up and running, ready protect me!

Next, we have to set up the internet program I use the most: my web browser.

Step 3: Set Up Your Web Browser With Tor

... and when I say "web browser," I mean "Firefox." Cuz what else would you use?

Setting up TOR with Firefox is also really easy, since there's a ready-made add-on for Firefox: Torbutton. Just go to this link to download the add-on, install it, and restart Firefox to get it running.

When it's installed right, you'll see a link at the bottom right of your browser window, reading "Tor Disabled." Just click that and it will switch to "Tor Enabled." A series of screenshots are below to help you out.

Once it's running, you're protected! All of your data will be running from computer to computer and switching paths, hiding your location. Web pages will load a little more slowly because of this, but when you need to get online safely, that's a small price to pay.

BTW, when I say you're protected, I mean that you're mostly protected. Read on; my last step talks about other things you can do to improve your security even more.

Step 4: Now, Be Careful

Having Tor up and running won't help if you slip up.

The first thing to do is to remember always to enable Tor when you're online. Maybe you want to maintain a profile on a site somewhere (like Instructables!) that no one can trace to you. If you forget and log in just once without Tor enabled, your real location will be recorded in the logs. So, be careful!

Second, you can start Tor-ifying your other internet apps: IM clients, email, etc. There's more information about this here on the Tor wiki.

Computer security is a constant arms race. There are smart people all over the world (criminals, government snoops, not to mention ADULTS at your school) who are always trying to see what you're up to or block where you want to go. No security is perfect, and they'll find ways to chip away at your defenses.

Good luck, out there.

Comments

author
littledave (author)2008-05-27

I'm sorry - this is a nice article but I strongly advise against anyone considering doing this. - Using TOR is not as secure as a lot of people think:

The TOR network works by channeling your data through a chain of highly encrypted SSH proxy tunnels, a so called "proxy chain".

If you visit, for example, this link: http://www.google.com/search?hl=en&q=paris+hilton, your request will be encrypted and tunnelled to another TOR user, then another, then another and so on. Your data could be passed around 20 times. The other TOR users cannot see the link you typed in (as it is encrypted). This sounds very very secure.

However, the data has the be decrypted again before google can understand what you searched for. In order to do this, the last TOR user in a proxy chain is called an "exit node". The exit node decrypts the data, contacts google for your results, encrypts the results and sends them back through the chain to you.

Sound secure so far? Well, actually, it does.

But what happens if the exit node runs a packet sniffer (like Wireshark) on their computer to monitor outgoing network connections? The url you typed in appears in plain text on their screen. They don't know who you are, but they saw what you did.

I hear you ask; "So what? - I don't care if a random Ukranian sees that I searched for 'Paris Hilton'." True. Most random Ukranians won't care at all if you searched for Paris Hilton. In fact, they may enjoy calling up the same link you searched for. But what about if you had been reading your hotmail email instead? - They get to see what you typed and to who you sent it.

The problem gets even worse if you start channeling E-Mail and Instant messenger programs through TOR. The POP3 E-Mail protocol sends usernames and passwords in PLAIN TEXT to the mail server. This means, that an exit node could sniff outgoing traffic and steal your email account. - They could then probably go to Paypal.com and request that your password be sent to your registered email address. The would then steal your Paypal information directly from your email account. - Is it sounding very secure now? Bye bye money.

But that isn't all... Some exit nodes act as bridges between you and the website you want to access, altering the data before it is send back to you. e.g. They could change all references to the name, "Paris Hilton" into "Bill Gates". - All of a sudden, you aren't looking at the innocent pictures you intended.

Even worse: It is possible for exit nodes to dynamically swap out SSL certificates of secure websites. If you called up https://www.myreallysecurebank.com over TOR, you might be sent back an SSL certificate which doesn't actually belong to your bank. - This would mean that your login details for your online banking are also visible to the exit node. - Bye bye money, again.

Sorry to rant on, but this should really be known before anyone tries to use the TOR network.

I am not saying TOR is bad - but don't ever consider sending anything personal over it or you might end up with less security than you bargained for.

Thanks

Dave from Germany.

author

Hi Dave,

I am a random Ukrainian (in US) but I will snoop your packets, no doubt, no doubt at all.

TOR users - you have been warned.

Sincerely,
Random Ukrainian - Thorax Impailor

author

Unless you run an exit node have fun looking at pages of encrypted text and webpages.

author
shahbazs3 (author)littledave2016-04-01

Thanks a lot for sharing this. it clear my concepts about overall flow of Onion Router.
it was nice article.

author

Another thing; some school security filters are programmed to detect proxy servers, and content, not specific sites

author

Tor is used in war zones and countries were people aren't allowed to share their ideas or think for themselves. I'm sure those situations have filters design a lot better than those put in place by your schools system admins. If the connection is in fact blocked tor has an option for networks were tor would be blocked.

author
jedi_knight (author)littledave2010-04-28

I get what you are trying to say but for things non email and IM would it be safe to use?

author
JohnJY (author)littledave2009-11-25

Please explain in simpler terms, I'm afraid I don't understand.

author
harley_rly (author)JohnJY2009-12-27

the last computer it goes through is the one that decrypts it, and therefore can see in plain text what it is you put in i.e. google search, personnel information

author
anonymouse2 (author)littledave2008-05-27

Tor doesn't claim to solve all your Internet security problems.

It does protect you against determination of your location by the Internet sites you visit, and against traffic analysis -- inspection of your destinations by a person looking at your computer's link. It can get your communications through a hostile filter or firewall, because it encrypts the links from your computer to the Tor entry node, and at all points between there and the exit (3 hops, if you haven't changed configuration).

If you want to communicate securely, you should still use encryption direct to your destination (https), and you should heed browser warnings if the SSL security certificates don't match.

author
Batryn (author)anonymouse22009-03-16

How does it do this, and when I tried it, I typed in https://google.com, and it just switched back to http://google.com, am I doing it wrong?

author
Batryn (author)anonymouse22009-03-16

https?

author
tinkerC (author)Batryn2009-03-16

Secure sites. Uses encryption.

author
fwjs28 (author)littledave2009-03-16

higly informative and very,very true...

author
dsngsp (author)littledave2008-10-20

Very good point...though I doubt someone would need to use TOR to use the bank...

author
53rp3nt (author)littledave2008-10-19

Tanzst auf dein computer, Dave from Deutschland!

author
bgugi (author)littledave2008-05-27

if that is the case, what alternatives do we have?

author
laminterious (author)littledave2008-05-27

Thank you for that.

author
whatsisface (author)littledave2008-05-27

Thanks for writing that, very informative.

author
JungleD1 (author)2016-03-17

hello... after 13 plus years of a work comp injury I am in dire need of information and do not wish to be followed in the research of a corrupt adjustor. how can I begin a "safe.." meeting with a talented researcher (quiet,safe,secure) who is interested in uncovering a severely corrupted system that is plunging injured state workers of Hawaii into an abyss of hopelessness. I do NOT want to give in to them and will be forever grateful for anyone who can help me with the questions I would like answered about a state audited corrupt adjustor work comp program. guidance is my last hope. This is the link to the "Audit.." they have been hiding in plainview that has destroyed my family, my life, my future and even my sanity, If it sounds bad you are only imagining the depth of this case. blessings to freedom fighters, we are in your debt for your willingness to help if possible. primal13yearswc .....

author
pirata12 (author)2016-02-04

thank you for sharing, its very imporatn to hide our identity when we surf online

author
DEX155 (author)2015-12-03

Dave i know but its worth it since your interpretative you should know

author
ChickenJo (author)2015-02-05

great 'Ible. I am planning to make a tails bootable USB fpr secure everything cuz it uses tor and other stuff

author
PeterH6 (author)2014-11-30

All I wanted to do is visit the dark web sight "The silk road" Is this fine?

author
MindSlapp (author)2012-08-30

So I'm at school right now, could anyone please upload the browser into a comment so it can be downloaded directly?

author
athlete_freak (author)2010-01-22

i have the same question as sandshock. the security system im trying to get past is the K9 web protection. and all i really want is to download music and get on facebook. however when i installed the firefox add thing. and then i clicked it so it was saying it was activated, it froze the page. i was unable to click on any links to go to another page. and it wasnt letting me go to sites. it was saying the proxy wasnt allowing it. how do i fix this problem?

author

download tor browser bundle

author
devicemodder (author)2012-04-02

use Tor to go on DEEP WEB for some fun

author

This is the link for the HIDDEN WIKI ===> http://7jguhsfwruviatqe.onion/index.php/Main_Page
you have to use TOR to view this

or in a regular browser do this https://7jguhsfwruviatqe.onion.to/index.php/Main_Page

this is through a proxy. whatever you do on the wiki please be careful with what you click on because there is a lot of CP on deepweb

author
cturner2 (author)2012-04-03

this as been around since years back but only juz now are you reading about it in the news i think people would be dumb to use everything on your pc is saved in temp files if one of these links get shared with nearly all are,when you clean your browser remove apps install and uninstall browsers the info iis passed to micro-soft to help improve performances this is also being used to share and sell things like child porn which needs to be stopped as its a encouragement to these sickos ide advise that any download links to these sites or browsers should be removed from the normal internet full stop

author
mwoodcock (author)2011-05-24

I agree, I use Opera, I for some reason never took a liking to Firefox.

author
Kyky Rocks1 (author)2011-02-05

Awesome it works

author
M1K3A5H13Y (author)2010-05-12

I dont see why you cant install this on a flashdrive and then use it on any computer.

author

Actually, you can. They have a bundle you can download that's designed for exactly that.

author
daltonjcw (author)2010-09-03

Very nice. Like the last step. But, If I'm on a school computer that isn't a SchoolBook, and it runs explorer, do I install Firefox? What if I like chrome better? Is there a tor set up for chrome? Please post tor instructions for other browsers. Djcw (Your friendly neighborhood Sort of, not really kind of anti-over-governmental libertarian)

author
53rp3nt (author)2008-10-18

This is great. Is there a how-to on setting up a pirate party email?

author
M4industries (author)53rp3nt2010-08-10

I saw the same thing in Little Brother. I am not quite sure.

author
sandshock (author)2009-11-25

two questions.  1) do you have to install this, even if you do the firefox thing?  2) do you have to have administrator access to install this?

author
Badassman828 (author)2009-02-10

I know I made a instructable on this to, but isnt this a word for word copy of the book little brother. Its great and all, but I'm wondering if you should state that its from the book, and that you didnt write it yourself. uness your the author of course. If you are, thought that book was great.

author
keiya (author)Badassman8282009-11-03

 Note the author's name...

And it's linked from the ebook version straight from Doctorow's site, so I think he knows and is cool with it.

author
fafnir665 (author)2009-08-25

Why are so many of the featured software instructables just people copying the how-to? Why are we rewarding people for unoriginal work?

author
Yoda12999 (author)2009-05-22

Don't quote me on this, but I heard that this was made by the United States Navy. Any one know if that is true?

author
sunset1 (author)2008-05-30

While this will give you some protection you might want to ask questions like hrm what happens if my box is the server sending information that some unknown person is looking for and they grab my ip instead? Annotherwords if you are running this as a server sooner or later you will be sending data that someone else requested. If that data is suspect it can be traced to the wrong party and has in the past. be aware. Sunset1

author
Badassman828 (author)sunset12009-02-10

One of the great things about Tor is, that this guy forgot, is that its encrypted. If someone runs something that comes off your computer, you cant see it, but nobody else can see it came from you (unless your the only german person running tor at the time and google comes up in german) Also, you have to agree to be a volunteer to let other people use your computer as a bounce off point. Finally, the request and webpage is bounced off so many different IP addresses that it is impossible for anyone to tell where exactly it came from, so anyone who uses Tor is well protected from false accusations.

author
z199y (author)sunset12008-07-29

good point ill be carefull.

author
Fasteners (author)2009-01-19

not for secure transmission, but a good way to screw with your big brother overlords.

author
Dvanex (author)2008-06-15

Well this sounds really cool but it wouldn't be any good at my school. First of all the program files and such are all stored on a network so basically you can't install anything without access to it. My school has Firefox that works on some computers but on the majority it will not work. Of coarse I could always make a precice copy of my schools whole system stick it on a usb and boot from that lol.

author
53rp3nt (author)Dvanex2008-10-19

I am currently running the same version of Tor on A U3 drive that would typically be used non-portably. There is no need for a portable version. Just save it in the downloads folder.

author
arch_angel07 (author)2008-07-08

I would be wary of using tor button, if you look at the comments a lot of people are complaining that it leaks information to alexa, which pretty much kills the point of using it. (I haven't personally checked the validity of those claims, but just a quick heads up for anyone who cares)

About This Instructable

293,227views

197favorites

License:

Bio: Taking back the world, one hacked game console at a time ... Have you ever felt like the technology you love could be used against you ... More »
More by m1k3y:Go Online without Getting Snooped: Tor (The Onion Router)How to blend in with crowds.How to lie to authority figures
Add instructable to: