Help & Answers

Frequently Asked Questions

Concise, technically grounded answers to common questions about anonymous networks, cryptographic tools, and privacy-preserving practices. Each entry is intended as a starting point; follow the linked guides for deeper treatment.


Access & Setup

Connecting to the Tor network and configuring the browser correctly.

What is Tor Browser and why do I need it?

Tor Browser is a modified version of Firefox maintained by the Tor Project that routes all traffic through the Tor network, a series of volunteer-operated relays that separate your identity from your destination. It also standardizes browser characteristics to reduce fingerprinting and is the only supported way to reach onion services. Using it rather than a standard browser with a proxy avoids common leaks such as DNS requests and WebRTC exposure.

How do I verify I am connected to Tor?

The most reliable check is to visit the Tor Project's connection test page at check.torproject.org, which reports whether your request arrived through a Tor exit relay. Within Tor Browser itself, the circuit display in the address bar shows the relays currently in use for the site you are viewing. If either indicates a direct connection, stop and review your network settings before continuing.

What security level should I use in Tor Browser?

Tor Browser offers three levels: Standard, Safer, and Safest, selectable from the shield icon in the toolbar. Safer disables JavaScript on non-HTTPS sites and blocks some media and fonts, while Safest disables JavaScript everywhere and removes most dynamic content. For sensitive browsing, Safer is a reasonable baseline and Safest is preferable when a site functions without scripts.

Can I use a VPN with Tor?

You can, but the benefit depends on the threat you are addressing. Connecting to a VPN first and then Tor hides Tor usage from your local network or ISP, at the cost of trusting the VPN provider with knowledge that you use Tor. Running Tor first and a VPN afterward is generally discouraged because it fixes your exit point and reintroduces a single party that can observe your traffic.

Why is my connection slow on Tor?

Every Tor connection passes through at least three relays operated by volunteers with varying bandwidth, and each hop adds latency and encryption overhead. Onion services add further hops because both sides build circuits to a rendezvous point. Some slowdown is inherent to the design; requesting a new circuit for the site or waiting for congestion to ease often helps, whereas disabling relays or reducing hops would undermine anonymity.


Security & Privacy

Encryption keys, operational discipline, and the data you leave behind.

What is a PGP key and why do I need one?

PGP (Pretty Good Privacy, implemented today mainly through the OpenPGP standard and GnuPG) uses a pair of mathematically linked keys: a public key you share and a private key you keep secret. Anyone can encrypt a message with your public key, but only your private key can decrypt it, and you can sign messages to prove they came from you. It is the standard tool for end-to-end encrypted correspondence and for verifying that a file or announcement is authentic.

How do I generate a PGP key pair?

With GnuPG installed, run gpg --full-generate-key in a terminal and follow the prompts to choose a key type, key size or curve, expiration date, and a strong passphrase. Modern defaults such as RSA 4096 or Ed25519 with an expiration of one to two years are sensible choices. Export your public key with gpg --armor --export and store an encrypted backup of the private key offline.

What is operational security (OPSEC)?

Operational security is the practice of identifying what information an adversary could use against you and then controlling how that information is exposed through your behavior, tools, and habits. It covers matters such as separating identities, avoiding reuse of usernames or writing patterns, and not mixing anonymous activity with personal accounts. Technical tools like Tor and PGP are only effective when paired with consistent operational discipline.

Should I use my real email address?

No; any account tied to an anonymous identity should use an address created specifically for that purpose and never linked to your real name, phone number, or existing accounts. Register it over Tor with a provider that does not require identifying information, and do not access it from your everyday browser. Keeping each identity's communications in its own compartment prevents a single leak from connecting them.

What metadata should I be aware of?

Metadata is information about a communication or file rather than its content: timestamps, IP addresses, message sizes, file properties, and EXIF data in images such as camera model and GPS coordinates. Encryption protects content but typically leaves metadata visible, and patterns in metadata alone can identify a person. Strip document and image metadata before sharing, and be mindful of timing and frequency patterns in your activity.


Payments & Monero

How a privacy-focused cryptocurrency works and how to verify its transactions.

Why is Monero recommended for privacy?

Unlike Bitcoin, where every transaction and balance is publicly visible on the blockchain, Monero applies privacy by default through ring signatures, stealth addresses, and confidential transactions (RingCT). Together these hide the sender, the receiver, and the amount from outside observers. Because privacy is not optional, users cannot weaken it by mistake, and no transaction stands out as unusual for being private.

How do I get Monero?

Monero is listed on many cryptocurrency exchanges, where it can be obtained in the same way as other digital assets, and it can also be acquired through peer-to-peer atomic swaps that exchange it directly for another cryptocurrency without an intermediary. Exchanges generally require identity verification, whereas atomic swaps do not. This is descriptive information only and not a recommendation to acquire any asset.

What is a subaddress?

A subaddress is an additional receiving address derived from your main Monero wallet, distinguishable by its "8" prefix rather than "4". Funds sent to any subaddress arrive in the same wallet, but the addresses cannot be linked to each other or to the primary address by an outside observer. Using a fresh subaddress for each counterparty prevents anyone from correlating separate payments to you.

How do I verify a Monero transaction?

Your wallet software confirms incoming and outgoing transactions automatically by scanning the blockchain with your view key, and a transaction is considered final after ten network confirmations. To prove a payment to a third party, the sender can generate a transaction key or proof from their wallet, which the recipient or a block explorer can check against the transaction ID. Only the parties holding the relevant keys can see the details; the public blockchain alone does not reveal them.