Reference Guide

Complete Security & Anonymity Guide

An educational overview of how anonymity networks, operational security, privacy-preserving payments, and device hardening fit together into a coherent defensive posture.


Tor Network Fundamentals

How onion routing separates who you are from what you do.

Tor (The Onion Router) is a volunteer-operated overlay network designed to decouple a user's network identity from their activity. Rather than sending traffic directly to a destination, a Tor client builds a circuit through three relays selected from the public relay directory. Each relay is responsible for a single hop, and the design ensures that no single relay can observe both the origin and the destination of a connection.

The three positions in a circuit have distinct roles. The guard (entry) relay sees the client's real IP address but only encrypted data destined for the next hop. The middle relay knows only the guard and the exit, and carries no information about either endpoint. The exit relay decrypts the final layer and forwards traffic to the destination, so it sees the destination and the plaintext of any unencrypted protocol, but not the client's address. Guards are kept stable for months to limit the number of relays that ever learn a client's IP; middle and exit relays rotate as circuits change.

The term "onion" refers to layered encryption. Before transmission, the client negotiates a separate symmetric key with each relay in the circuit and wraps each packet (called a cell) in three layers of encryption. The guard removes the outermost layer, the middle relay the next, and the exit the last. Because keys are established through an incremental handshake, each relay can only decrypt its own layer, and each learns only the identity of its immediate neighbours in the path.

Relay information is distributed by a small set of directory authorities that jointly publish a signed consensus document listing all relays, their keys, flags, and bandwidth weights. Clients download this consensus and use it to build circuits locally, so relay selection is not controlled by any single party. Circuits are short-lived by design: Tor Browser uses a fresh circuit per first-party site and rotates circuits periodically, which limits the window in which correlation between separate activities is possible.

Tor is not the only design in this space. The table below contrasts it with two commonly compared alternatives: commercial VPNs and the Invisible Internet Project (I2P).

Property VPN Tor I2P
Trust model Single provider Distributed relays Distributed peers
Anonymity Low to moderate High High
Typical use General traffic Browsing and hidden services Internal eepsites and services
Exit to clearnet Yes Yes, via exit nodes Limited
Speed Fast Moderate Moderate

OPSEC Principles

Tools protect traffic; habits protect people.

Operational security (OPSEC) originated as a military discipline for identifying which pieces of information an adversary could assemble into a useful picture, and then denying them those pieces. Applied to personal privacy, it is the recognition that anonymity networks and encryption address only the transport layer. Most deanonymization in practice results not from cryptographic failure but from human error: a reused username, a forgotten metadata field, a distinctive turn of phrase. The following principles form a general framework for reasoning about such risks.

  1. Compartmentalization. Divide activities into isolated compartments so that a compromise in one does not propagate to others. This applies to accounts, devices, virtual machines, and even physical locations. The goal is to ensure that the information available in any single compartment is insufficient to reconstruct the whole.
  2. Minimize the data footprint. Every piece of data shared is data that can later be correlated, leaked, or subpoenaed. Provide only what a service strictly requires, avoid optional fields, and prefer services that do not demand personal information at all. Data that was never created cannot be exposed.
  3. Separate identities. Personas should never be linked, directly or indirectly. This means distinct credentials, distinct email addresses, distinct payment methods, and no cross-references in content. A single shared identifier, such as a recovery phone number or an avatar image, is enough to collapse two identities into one.
  4. Consistency of behaviour. Patterns leak information even when content does not. Timing of activity reveals time zones; writing style reveals native language and education; habitual typographical errors can act as a fingerprint. Stylometric analysis and traffic timing analysis are both established research fields, and defending against them requires deliberate, consistent behaviour within each compartment.
  5. Trust no single tool. No application, network, or protocol is a complete solution. Tor does not encrypt exit traffic; encryption does not hide metadata; a VPN merely relocates trust. Effective privacy is layered so that the failure of any one component is contained rather than catastrophic.
  6. Keep systems updated and minimal. Unpatched software is the most common technical entry point. Apply updates promptly, remove software that is not needed, and reduce the attack surface to the minimum required for the task. A smaller system is easier to audit and harder to exploit.
  7. Assume a capable adversary and plan for failure. Threat modelling should assume the adversary has substantial resources, patience, and access to large datasets. Design procedures so that a mistake is recoverable: use disposable environments, avoid persistent state where it is not needed, and decide in advance what a compromise would look like and how to respond to it.
Anonymity is a property of a system over time, not of a single connection. It is lost cumulatively and rarely regained.

Monero for Privacy

Privacy as a default property of the ledger rather than an optional layer.

Most public blockchains, including Bitcoin, are transparent by design: every transaction, address, and balance is permanently visible to anyone who inspects the ledger. Pseudonymous addresses offer little protection in practice, because chain-analysis techniques can cluster addresses, trace flows through exchanges, and link on-chain activity to real-world identities. Monero (XMR) is a cryptocurrency that takes the opposite approach, applying privacy protections to every transaction by default rather than as an opt-in feature.

A consequence of mandatory privacy is fungibility, the property that every unit of a currency is interchangeable with every other. On a transparent chain, coins carry a visible history, and units previously associated with disputed activity may be treated differently by exchanges or merchants. Because Monero's ledger does not reveal transaction histories, no unit can be distinguished from another, which restores the fungibility that physical cash possesses and that transparent ledgers lack.

These properties are achieved through a combination of cryptographic techniques, each addressing a different piece of information that a transparent ledger would otherwise expose. This section describes the mechanisms from a technical perspective only; it does not constitute financial guidance of any kind.

  • Ring signatures obscure the sender. Each transaction input is signed on behalf of a group (a "ring") of possible outputs drawn from the chain, only one of which is actually being spent. An observer can verify that the signature is valid for one member of the ring but cannot determine which, so the true origin is hidden among decoys.
  • Stealth addresses obscure the recipient. For every payment, the sender derives a unique one-time destination address from the recipient's public keys. Only the recipient can recognise and spend outputs sent to it, and no two payments to the same person share an address on the ledger.
  • RingCT (Ring Confidential Transactions) obscures the amount. Transaction values are replaced by cryptographic commitments, and range proofs demonstrate that inputs equal outputs and that no negative values were created, without revealing the actual sums.
  • Dandelion++ addresses network-level metadata. When a transaction is first broadcast, it is passed along a random path of peers (the "stem") before being flooded to the network (the "fluff"), making it difficult to link a transaction to the IP address that originated it. An earlier initiative, Kovri, aimed to route Monero traffic over I2P; that project was discontinued, and current work focuses on Dandelion++ together with optional use of Tor or I2P at the node level.

Device Security

The endpoint is the boundary of every other protection.

Network-level anonymity is only as strong as the device that uses it. A compromised or poorly configured endpoint can leak identifying information before traffic ever reaches Tor, or expose stored data regardless of how it was transmitted. Device security is therefore best understood in four layers, each covering a distinct class of risk.

OS Security

Purpose-built systems such as Tails (amnesic, routes all traffic through Tor) and Qubes OS (security through virtualization-based compartmentalization) reduce reliance on a general-purpose desktop. Full-disk encryption protects data at rest, and timely updates close known vulnerabilities before they can be exploited.

Browser Hardening

Tor Browser is configured so that all users present a uniform fingerprint; changing settings, resizing the window, or installing add-ons makes a user more distinguishable, not less. The "Safest" security level disables JavaScript and other features that account for most browser exploits.

Network Security

A host firewall should block all traffic that does not pass through the anonymity layer. DNS requests are a common leak path and must be resolved through Tor rather than the system resolver. Gateway designs such as Whonix enforce this with a transparent proxy: the workstation has no route to the internet except through the Tor gateway.

Physical Security

Encryption does not protect a device that is unlocked and unattended. Keys held in memory can be recovered by cold-boot attacks shortly after power-off, so shutting down fully matters. Tamper-evident measures and limiting physical access to hardware address adversaries who can reach the device itself.