I can't in good conscience allow the U.S. government to destroy privacy, internet freedom, and basic liberties for people around the world with this massive surveillance machine they're secretly building.
Edward Snowden.
There is a lot of information on the web about Tor and even more information about VPNs. But not everyone knows that for maximum privacy, you need to use the two technologies together.
In this article, I will share my over 10 years of experience of setting up secure networks using Tor over VPN.
You will learn how to properly configure the onion browser;
How to choose an effective Tor VPN;
What important options need to be activated in the VPN app;
What is known about Tor in 2021?
The Tor browser (The onion router), launched in 2002, is an advanced tool for accessing a free and inaccessible network built on the existing Internet. Tor is also used to anonymously access the regular internet due to its multiple exit points. It has an official website torproject.org.
Most often, the internal Tor network is called the “darknet” or “dark-web”.
As part of this article, I will not delve into the darknet device and what can be found in it, since there is more than enough such information on the Internet (for example, here).
I would like to share my opinion on the security and safety of Tor.
Throughout the existence of the Onion browser, there have been endless discussions about whether Tor technology really protects the user 100% from any attempts to determine the user's real location.
There are messages about some computing power of the FBI, which, according to a certain algorithm, can calculate the real IP address. There are even conspiracy theories that part of the network or even all of its servers are supported by US intelligence services.
As a rule, all theories and assumptions have no direct evidence. But at the same time, there are no reliable refutations.
Thus, the Tor network must be viewed as a risky means of anonymization, and access to its internal sites in the virtual domain zone.onion as insecure.
Moreover, every year there are more and more cases when the special services or the police gain access to sites on the darknet, collect information, and go to their users.
But there is three good pieces of news:
1. All methods of deanonymization in Tor are at least very laborious.
2. As a rule, they are all based on incorrect user behavoir.
3. There is an additional way to protect yourself with Tor much stronger - using a VPN.
In this chapter, I will share my experience with Tor and tell you what points to consider for maximum privacy and security.
Before going to a .onion site or hiding your IP using Tor, it is important to know some weak points that can lead to loss of privacy:
Based on this, I will list the precautions that will prevent you from giving your location out.
Items 3 and 4 can be done later through the menu item "Settings".
Congratulations! You've taken the first step towards nearly 100% privacy. Now it is important to install the VPN (you can do this before installing the Tor browser).
Along the way, I want to note that the IP addresses of the Tor network are widely known, and even free public services define them as an anonymizer (information from whoer.net in the screenshot):
For an example of using a VPN with Tor, I chose NordVPN, since I actively use it myself. You can also use ExpressVPN.
It is slightly faster in US locations and is more convenient to install on multiple devices. The ExpressVPN setup process is very similar to NordVPN.
After you install the VPN and The Onion router browser, you need to re-check the functionality of the entire protection system.
To do this, check your IP address in a regular web browser with the VPN enabled (check your IP). It must belong to the country selected when connecting.
Then open this link in your Tor browser and make sure that the displayed address is different from your real one and the virtual one.
If everything works, then the setup is complete.
If the page in the Tor browser does not open with the VPN, then change or disable the bridge mode.
I already talked about using NordVPN, and I mentioned ExpressVPN. I also recommend using Surfshark if you want to save money on a long subscription.
Next, I'll talk about each of these services, their strengths and weaknesses.
Comparison of the main features of VPN services for Tor
Service | Ranking (out of 10) |
Speed, Mbps | Obfuscaion | Price (monthly) |
ExpressVPN | 10 | >100 | - | $6.67-12.95 |
NordVPN | 10 | >60 | + | $3.71-11.95 |
Surfshark | 10 | >50 | + | $1.99-11.95 |
ExpressVPN is by far the fastest VPN service with the highest level of privacy, Tor support, and a wide range of locations across multiple subnets.
The provider has not only been tested but passes it at least 3-4 times a year on all OSs.
Why I think ExpressVPN is the best:
ExpressVPN is based in the British Virgin Islands. This is the safest jurisdiction possible.
The table lists the ExpressVPN * plans:
1 month | 6 months | 1 year | |
Monthly cost | $12.95 | $9.99 | $6.67 |
Money-back guarantee, days | 30 | 30 | 30 |
* Prices are indicated taking into account the discount that is provided when using this link.
I believe that ExpressVPN's level of quality is in line with its price tag.
Also read:
I can tell the most about NordVPN since I use it myself at work and home. As for working with Tor, what I like most about the provider is that its VPN apps 100% protect traffic, the addresses of the sites visited and the real IP address, even with the Kill Switch turned off.
Also, the user has access not only to the selection of countries and cities in the list of locations, but can, if desired, select a specific server. This is especially useful if you need to connect to the same IP address several times.
For the most careful, there is the possibility of using VPN-over-VPN (double VPN). This is the highest level of location protection I know of.
Excellent connection stability, high speed, support for the cutting-edge WireGuard (NordLynx) protocol, which makes VPN virtually invisible to the user, even on mobile devices. This is due to the minimal power consumption of this protocol.
NordVPN is based in Panama. This is a safe jurisdiction.
The table lists the NordVPN * plans:
1 month | 6 months | 1 year | 2 years | |
Monthly cost | $11.95 | $9.00 | $5.75 | $3.71 |
Money-back guarantee, days | 30 | 30 | 30 | 30 |
* As of the time of this writing, NordVPN has a 68% discount on its 2-years plan.
NordVPN offers significant savings when you sign up for over a year. To minimize risks, there is a 30-day money-back guarantee.
Also read:
If you don't need top performance or a choice of 90 countries, Surfshark is a great budget VPN service for Tor.
Despite the low price, it has strong features that are practically not inferior to competitors.
For example, Surfshark offers over 10 locations for double protection (MultiHop). In this case, you choose the input and output servers.
For those who are in countries with censorship on the Internet, the function of the obfuscation of the OpenVPN protocol improved in 2020 is useful.
Testing has confirmed the complete security of apps for all OSs.
Surfshark, like ExpressVPN, is based on the BVI.
The table lists the plans of Surfshark VPN:
1 month | 1 year | 2 years | |
Monthly cost | $11.95 | $5.99 | $1.99 |
Money-back guarantee, days | 30 | 30 | 30 |
As you can see, with a 2-year subscription, Surfshark is significantly cheaper than the competition. A one-year subscription is also affordable.
The provider also offers additional services that increase the security of email correspondence and web surfing for $0.99 per month.
Also read:
I do not recommend using the free Tor security enhancements, as most of them will not increase Tor security, but expose the user to additional risks.
Nevertheless, I will discuss two main free methods for additional protection of a Tor connection.
The Tor browser supports proxy connections. This is an encrypted connection between the browser itself and the Tor gateway server.
There are a large number of free proxy lists on the Internet. But besides the fact that they are free, they have significant disadvantages:
So, a free proxy can be used in conjunction with Tor, but this will add inconvenience and significantly reduce security.
I want to say right away that completely free VPN services have practically disappeared. In 2021, free VPN means a free plan of a regular service. Naturally, such a plan has significant limitations. The strongest of these is the ban on use with Tor.
There is also a group of so-called free VPN apps distributed through the Google Play Store, Huawei AppGallery, and the Apple App Store. But in practice, these are services with a free trial subscription. Usually it lasts up to 7 days. Besides, there is no way to ensure that these apps do not provide users' data to third parties.
Of the verified players, I can only offer the following free VPNs:
ProtonVPN
Windscribe
Hide.me
TunnelBear
Hotspot Shield
TurboVPN
VPN Gate
Leave a comment