Last checked October 9, 2026 · 3 of 3 mirrors responding PGP 6383E112811BA4F7147057FB98105DD4940CBC22
Omega Market Omega Market

Installing Tor Browser Safely

Download Tor Browser only from torproject.org. Third-party installers often bundle tracking software, and a single misclick can compromise your privacy.

The only safe source is https://www.torproject.org/download/. Type the URL manually. Do not click Tor Browser from search results. Ad networks pay publishers to place sponsored links above organic ones. Those links redirect through tracking pixels. By the time you land, your device ID is already logged.

The Installation Steps

  • Select your operating system from the dropdown menu. Windows users get a zip archive. macOS gets a dmg disk image. Linux users choose between AppImage, tar.bz2, or Flatpak depending on distribution support.
  • Verify the signature. Right click the downloaded file and check the SHA256 hash against the value posted on the download page. Mismatched hashes mean tampering occurred during transfer.
  • Extract the files to any folder you remember easily. Drag the executable to your desktop or applications folder.
  • Launch the program. Accept the default configuration on the first run unless you have specific technical needs.

First Change After Launch

Before browsing anything else, go to Settings. Under Connections, locate the Onion Services section. Add your own entry if you maintain a service, or simply ensure the built in bridge option remains enabled for restrictive networks. Then open the Help menu and select About. Confirm the build number matches what was announced within the last 90 days. Older builds contain known vulnerabilities patched in recent releases.

Do not enable extensions yet. Every extension introduces code execution paths that can leak data. Start clean. Browse five pages. Close the window. Restart. Repeat until you trust the consistency. Only then add one necessary plugin, test it for three days, and monitor memory usage closely.

Updates come via automatic prompt when new versions release. Ignore update available notifications from other sources. The internal updater contacts the project server directly over TLS. External update notices often arrive by email and may carry phishing risks. Stick to the app itself for version management.