Instructables

Go Online without Getting Snooped: Tor (The Onion Router)

Featured
Picture of Go Online without Getting Snooped: Tor (The Onion Router)
When you go online, you leave tracks all over the place. You could be hanging out with friends on IM, checking out websites, or downloading music. If you live in a country where snoops are prying into what ordinary citizens do online (lke, um, the US) you want a way to cover those tracks.

If you're in school, though, then it's even worse. No matter what country you're in, chances are that your access to the internets is as snooped-on as any police state in the world.

So, how do we escape our little virtual prisons? In this Instructable, I'll tell you about something called Tor (The Onion Router.) I'll tell you how it works, and then offer some simple instructions on how to get your web browser hooked up. No more getting snooped!
 
Remove these adsRemove these ads by Signing Up

Step 1: How Tor Works

Picture of How Tor Works
An "onion router" is an Internet site that takes requests for web-pages and passes them onto other onion routers, and on to other onion routers, until one of them finally decides to fetch the page and pass it back through the layers of the onion until it reaches you. The traffic to the onion-routers is encrypted, which means that the school can’t see what you’re asking for, and the layers of the onion don’t know who they’re working for. There are millions of nodes—the program was set up by the US Office of Naval Research to help their people get around the censorware in countries like Syria and China, which means that it’s perfectly designed for operating in the confines of an average American high-school.

Tor works because the school has a finite blacklist of naughty addresses we aren’t to visit, and the addresses of the nodes change all the time—no way could the school keep track of them all.

There's a more complete overview, here, but let's get on to installing Tor.
1-40 of 94Next »
littledave6 years ago
I'm sorry - this is a nice article but I strongly advise against anyone considering doing this. - Using TOR is not as secure as a lot of people think:

The TOR network works by channeling your data through a chain of highly encrypted SSH proxy tunnels, a so called "proxy chain".

If you visit, for example, this link: http://www.google.com/search?hl=en&q=paris+hilton, your request will be encrypted and tunnelled to another TOR user, then another, then another and so on. Your data could be passed around 20 times. The other TOR users cannot see the link you typed in (as it is encrypted). This sounds very very secure.

However, the data has the be decrypted again before google can understand what you searched for. In order to do this, the last TOR user in a proxy chain is called an "exit node". The exit node decrypts the data, contacts google for your results, encrypts the results and sends them back through the chain to you.

Sound secure so far? Well, actually, it does.

But what happens if the exit node runs a packet sniffer (like Wireshark) on their computer to monitor outgoing network connections? The url you typed in appears in plain text on their screen. They don't know who you are, but they saw what you did.

I hear you ask; "So what? - I don't care if a random Ukranian sees that I searched for 'Paris Hilton'." True. Most random Ukranians won't care at all if you searched for Paris Hilton. In fact, they may enjoy calling up the same link you searched for. But what about if you had been reading your hotmail email instead? - They get to see what you typed and to who you sent it.

The problem gets even worse if you start channeling E-Mail and Instant messenger programs through TOR. The POP3 E-Mail protocol sends usernames and passwords in PLAIN TEXT to the mail server. This means, that an exit node could sniff outgoing traffic and steal your email account. - They could then probably go to Paypal.com and request that your password be sent to your registered email address. The would then steal your Paypal information directly from your email account. - Is it sounding very secure now? Bye bye money.

But that isn't all... Some exit nodes act as bridges between you and the website you want to access, altering the data before it is send back to you. e.g. They could change all references to the name, "Paris Hilton" into "Bill Gates". - All of a sudden, you aren't looking at the innocent pictures you intended.

Even worse: It is possible for exit nodes to dynamically swap out SSL certificates of secure websites. If you called up https://www.myreallysecurebank.com over TOR, you might be sent back an SSL certificate which doesn't actually belong to your bank. - This would mean that your login details for your online banking are also visible to the exit node. - Bye bye money, again.

Sorry to rant on, but this should really be known before anyone tries to use the TOR network.

I am not saying TOR is bad - but don't ever consider sending anything personal over it or you might end up with less security than you bargained for.

Thanks

Dave from Germany.
Another thing; some school security filters are programmed to detect proxy servers, and content, not specific sites
I get what you are trying to say but for things non email and IM would it be safe to use?
Hi Dave,

I am a random Ukrainian (in US) but I will snoop your packets, no doubt, no doubt at all.

TOR users - you have been warned.

Sincerely,
Random Ukrainian - Thorax Impailor
Please explain in simpler terms, I'm afraid I don't understand.
the last computer it goes through is the one that decrypts it, and therefore can see in plain text what it is you put in i.e. google search, personnel information
Tor doesn't claim to solve all your Internet security problems.

It does protect you against determination of your location by the Internet sites you visit, and against traffic analysis -- inspection of your destinations by a person looking at your computer's link. It can get your communications through a hostile filter or firewall, because it encrypts the links from your computer to the Tor entry node, and at all points between there and the exit (3 hops, if you haven't changed configuration).

If you want to communicate securely, you should still use encryption direct to your destination (https), and you should heed browser warnings if the SSL security certificates don't match.
How does it do this, and when I tried it, I typed in https://google.com, and it just switched back to http://google.com, am I doing it wrong?
https?
tinkerC Batryn5 years ago
Secure sites. Uses encryption.
higly informative and very,very true...
Very good point...though I doubt someone would need to use TOR to use the bank...
Tanzst auf dein computer, Dave from Deutschland!
if that is the case, what alternatives do we have?
Thank you for that.
Thanks for writing that, very informative.
MindSlapp1 year ago
So I'm at school right now, could anyone please upload the browser into a comment so it can be downloaded directly?
i have the same question as sandshock. the security system im trying to get past is the K9 web protection. and all i really want is to download music and get on facebook. however when i installed the firefox add thing. and then i clicked it so it was saying it was activated, it froze the page. i was unable to click on any links to go to another page. and it wasnt letting me go to sites. it was saying the proxy wasnt allowing it. how do i fix this problem?
download tor browser bundle
use Tor to go on DEEP WEB for some fun
This is the link for the HIDDEN WIKI ===> http://7jguhsfwruviatqe.onion/index.php/Main_Page
you have to use TOR to view this

or in a regular browser do this https://7jguhsfwruviatqe.onion.to/index.php/Main_Page

this is through a proxy. whatever you do on the wiki please be careful with what you click on because there is a lot of CP on deepweb
cturner22 years ago
this as been around since years back but only juz now are you reading about it in the news i think people would be dumb to use everything on your pc is saved in temp files if one of these links get shared with nearly all are,when you clean your browser remove apps install and uninstall browsers the info iis passed to micro-soft to help improve performances this is also being used to share and sell things like child porn which needs to be stopped as its a encouragement to these sickos ide advise that any download links to these sites or browsers should be removed from the normal internet full stop
mwoodcock3 years ago
I agree, I use Opera, I for some reason never took a liking to Firefox.
Kyky Rocks13 years ago
Awesome it works
M1K3A5H13Y4 years ago
I dont see why you cant install this on a flashdrive and then use it on any computer.
Actually, you can. They have a bundle you can download that's designed for exactly that.
daltonjcw3 years ago
Very nice. Like the last step. But, If I'm on a school computer that isn't a SchoolBook, and it runs explorer, do I install Firefox? What if I like chrome better? Is there a tor set up for chrome? Please post tor instructions for other browsers. Djcw (Your friendly neighborhood Sort of, not really kind of anti-over-governmental libertarian)
53rp3nt5 years ago
This is great. Is there a how-to on setting up a pirate party email?
I saw the same thing in Little Brother. I am not quite sure.
sandshock4 years ago
two questions.  1) do you have to install this, even if you do the firefox thing?  2) do you have to have administrator access to install this?
I know I made a instructable on this to, but isnt this a word for word copy of the book little brother. Its great and all, but I'm wondering if you should state that its from the book, and that you didnt write it yourself. uness your the author of course. If you are, thought that book was great.
 Note the author's name...

And it's linked from the ebook version straight from Doctorow's site, so I think he knows and is cool with it.
fafnir6655 years ago
Why are so many of the featured software instructables just people copying the how-to? Why are we rewarding people for unoriginal work?
Yoda129995 years ago
Don't quote me on this, but I heard that this was made by the United States Navy. Any one know if that is true?
sunset16 years ago
While this will give you some protection you might want to ask questions like hrm what happens if my box is the server sending information that some unknown person is looking for and they grab my ip instead? Annotherwords if you are running this as a server sooner or later you will be sending data that someone else requested. If that data is suspect it can be traced to the wrong party and has in the past. be aware. Sunset1
One of the great things about Tor is, that this guy forgot, is that its encrypted. If someone runs something that comes off your computer, you cant see it, but nobody else can see it came from you (unless your the only german person running tor at the time and google comes up in german) Also, you have to agree to be a volunteer to let other people use your computer as a bounce off point. Finally, the request and webpage is bounced off so many different IP addresses that it is impossible for anyone to tell where exactly it came from, so anyone who uses Tor is well protected from false accusations.
z199y sunset16 years ago
good point ill be carefull.
Fasteners5 years ago
not for secure transmission, but a good way to screw with your big brother overlords.
Dvanex6 years ago
Well this sounds really cool but it wouldn't be any good at my school. First of all the program files and such are all stored on a network so basically you can't install anything without access to it. My school has Firefox that works on some computers but on the majority it will not work. Of coarse I could always make a precice copy of my schools whole system stick it on a usb and boot from that lol.
53rp3nt Dvanex5 years ago
I am currently running the same version of Tor on A U3 drive that would typically be used non-portably. There is no need for a portable version. Just save it in the downloads folder.
1-40 of 94Next »