Most people know very little about the Tor Browser. Six out of ten people I ask say they have heard of something that doesn’t exist: A “search” app that connects directly to the Internet’s lower floor. That is simply not true. This misperception leads many new users to install the wrong program, then panic when their first webpage takes too long to load, and finally quit.
As of August 2026, here is the truth about Tor Browser:
Tor Browser is a custom-built version of Firefox ESR. That is all. It routes your browser requests through three volunteer relays before they reach their final destination. Additionally, the Tor Browser modifies the Firefox browser to prevent websites from identifying you via browser fingerprinting during transmission. As of today, the latest stable release of Tor Browser is 15.0.19 (July 21), based on Firefox 140 ESR. The next stable version of Tor Browser is in Alpha (16.0a9). For now, the Tor Project has stated that Alphas should only be used by testers and not individuals requiring anonymity.
For a detailed description of what is going on inside the Tor Browser (versioning, security settings and what each setting does), please visit our Tor Browser reference article.
The Rust Rewrite Is Just Starting To Get Fun
The big news in 2026 for Tor is not the graphical interface. It is what is happening beneath it.
Tor’s source code is written in C and was created in 2002. Over twenty-five years of C programming has resulted in countless memory management errors; those errors have been patched multiple times. The Tor Project has been working to migrate Tor’s source code from C to Rust under the name “Arti.” In 2026 Arti is officially no longer just a research project. Arti 2.5.0 was released on June 30 with Counter Galois Onion marked as stable (how circuit traffic gets encrypted); and congestion control was enabled by default (the “boring” sounding change that ultimately results in faster loading of pages). Two days later (August 4), Arti 2.5.1 was also released. The updates mainly included internal changes, plus early support for running Arti as a relay and/or directory authority.
What really matters here is not that Arti supports running client-side Rust. Rather, that Arti supports running relay-side Rust. Eventually this will mean that the Tor Network will stop using C and instead use Rust. We’re getting closer to that day – we are no longer talking about speculation.
In addition to providing early support for relay-side Rust, the Arti 2.5.0 update contained patches for two DoS bug disclosures (TROVE-2026-024 and -027).
It’s worth mentioning these bugs were disclosed and fixed in the same 2.5.0 update. Normally disclosure of vulnerabilities are separate from listing new features added to a software package.
So What Is a “Dark Web App,” Anyway?
This is where things start to get confusing, and unfortunately where people tend to burn themselves.
The Tor Project doesn’t provide a single application that indexes .onion services. Instead, several mobile clients provide access to .onion services from your smartphone:
- Tor Browser for Android: This is the official version, same codebase as desktop version, maintained by the Tor Project.
- Onion Browser for iOS: Another popular alternative for accessing .onion services on iOS devices. Currently, it uses Apple’s WebKit engine due to Apple’s strict policy regarding third-party browsers.
- Orbot: Orbot provides routing for other applications via Tor – it is a proxy application, not a browser application.
All other applications claiming to be a “dark web browser” in either app store are either repackaged versions with advertisements loaded onto them or credential-harvesting tools. Both the Google Play Store and Apple App Store continue to suffer from fake versions of legitimate applications – specifically look-alike listings containing the onion symbol and identical descriptions. Be sure to check the developer names – the Tor Project develops under its actual name and Onion Browser developers list Mike Tigas/Guardian Project ancestry. If the developer name contains something like “OnionVPN Pro Studio”, close the tab immediately.
To help break down exactly how each mobile client works – including which ones are fakes – please refer to our mobile dark web app comparison article.
The Snowflake Tool Is Pretty Cool
On August 3rd, the Tor Project announced Snowflake Volunteer -an open-source Android application developed by Bloco, a development company located in Portugal. While the Snowflake application has existed as a browser extension for years – allowing you to utilize your unused connection to temporarily act as a bridge for someone trying to connect to Tor within a region where access is blocked – the Android application allows you to perform similar tasks utilizing your idle android connection.
When you run the Snowflake application, you aren’t browsing anything. You install it, and it silently acts as a proxy server for someone in Iran or Turkmenistan unable to obtain connectivity to access the global internet.
What Tor Does Not Do
We believe that honesty about limitations is the quickest method to identify who really understands this subject matter.
Tor conceals where your browser traffic originates from. However, Tor does NOT conceal what you do once you arrive at your intended location. Logging into your genuine Gmail account while connected via Tor identifies YOU — the network performed its task and you undid it. An exit node may observe your unencrypted communications – therefore HTTPS continues to be necessary even though you are connected via Tor. Your ability to protect against browser fingerprinting relies upon you refraining from resampling windows sizes, refraining from adding add-ons, and refraining from scaling the application window larger than anybody else would ever have utilized.
The Security Slider is probably the single-most configuration item that nobody has ever touched. Standard enables JavaScript across ALL websites — safer disables JavaScript on non-HTTPS sites – safest completely disables JavaScript – effectively disabling about fifty percent of the entire Internet.
Many of the cases that went to trial involving de-anonymizing Tor users involved an individual operating at standard on an already-compromised website.
The Practical Edition
Download from torproject.org. DO NOT download from a mirror site, or any other website describing itself as a “download hub”. Make sure you verify the digital signature if you verify digital signatures – The Tor Project posts checksums for every release along with each release.
Configure your security level BEFORE you begin surfing — not AFTER you have started surfing. Keep the window sized as it originally appeared. Avoid logging into ANY service associated with your real identity. Reboot when prompted — most releases contain back-ported security fixes to Firefox and failing to reboot will essentially defeat the purpose of using Tor altogether.
Additionally, if you remember one thing about this post: The browser is merely a tool; the network is merely an infrastructure; Any product advertising itself as a “one-tap dark web app” is attempting to sell you something.