TOR
Dark Web, TOR
TOR stands for The Onion Router due to it's multiple layers.
TOR was developed by the US Government under DARPA to provide itself and at-risk social activists from their own authoritarian governments. It is now an open source project no longer under government control.
All web sites on the TOR network are also known as the "dark web" or "deep web" because they cannot be accessed via the normal internet web browser. There is no DNS system as is used with typical web traffic.
The TOR network runs on thousands of relay nodes, a portion of which serve as exit nodes, operating at any given time. The actual number varies but is growing all the time. Anyone can apply to provide a node which will be available to the network whenever your computer is online. Nodes come and go.
TOR provides anonymity. VPN provides encryption. Use them together for the best of both worlds. You can surf any sites on TOR you can over the Clearnet unless the site publisher has placed restrictions on access via TOR. If you jsut connect to TOR your ISP can tell only that. If you use a VPN your ISP cannot even tell your also on TOR network.
TOR can often be much slower than your normal ISP internet connection both because of the numerous hops from node to node as well as the fact that individual nodes may be on smaller individual computers along the way. your connection will be only as fast as the slowest node between you and your destination.
Data between you and each node is encrypted so no one along the way can see your data.
What each node in the chain can actually see
A typical TOR connection passes through three nodes, and the entire design hinges on this: no single one of them ever sees both who you are and where you're going. Each hop only peels off one layer of encryption - just enough to learn the next hop, nothing more.
- Entry (guard) node - sees your real IP address, since that's who you're directly connecting to. It does NOT see your final destination - it only sees encrypted traffic addressed to the middle relay.
- Middle (relay) node - sees neither your IP nor your final destination. It only knows "this encrypted data came from the entry node, forward it to the exit node." This is the node with the least information of the three, by design. If you're ever considering volunteering a computer to the TOR network, running a middle node is the safest role to take on - since your IP is never the one directly associated with someone's destination traffic, you avoid the legal exposure that comes with running an exit node, where traffic appears to law enforcement and site owners to be coming from you.
- Exit node - sees your final destination (the site you're reaching), since it's the one that unwraps the last layer and sends the request onward. It does NOT see your real IP - it only sees that traffic arrived from the middle relay.
That split is the whole point: entry knows who, not where; exit knows where, not who; the middle knows neither. Two honest caveats worth knowing:
- If a single adversary controls or is monitoring both your entry and exit node for the same circuit, they can potentially correlate the timing/volume of traffic on both ends and de-anonymize you, even without either node individually knowing both pieces. This is a real, documented technique - mainly a concern against a well-resourced adversary capable of watching a large slice of the network, not routine surveillance.
- The exit node sees your traffic in the clear if the destination site itself isn't using HTTPS - TOR encrypts your traffic hop-to-hop within its own network, but that protection ends at the exit node. A malicious exit node operator can potentially read or even tamper with unencrypted traffic on its way out. Always check for HTTPS, same as you would outside of TOR.
Here are some relevant links.
TOR Wiki to learn about TOR
TOR Project for official information and downloads (FREE)