🌍 Browser Security Guide
Secure your Tor Browser configuration for safe darknet browsing.
Security Settings
Set the security level to Safest (Settings → Privacy & Security → Security Level) before you visit anything, not after something goes wrong. This disables JavaScript entirely, blocks remote fonts and most media playback, and closes off the single largest attack surface that's actually been exploited against real Tor users in documented deanonymization cases — JavaScript engines are complex enough that they've repeatedly been the entry point, not a theoretical risk. Some market pages render more plainly or lose interactive features in Safest mode; that's the cost, and it's a small one next to what it closes off. If one specific trusted page genuinely needs a script to function, the NoScript icon lets you allow it for that domain only, temporarily — never drop the global default below Safest to work around an inconvenience, since that reintroduces the exact risk the setting exists to remove, site-wide, for every page you visit afterward.
Extensions
Don't install extensions in Tor Browser — not even ones you trust and use everywhere else. Every browser you and everyone else runs has a slightly different set of installed extensions, screen size, and settings; that combination is what makes browser fingerprinting work at all, and Tor Browser's entire anonymity model depends on as many users as possible looking as close to identical as possible. One additional extension can be enough to make your browser instance uniquely identifiable among the Tor user population, which defeats anonymity in a way no amount of careful Tor configuration elsewhere can fix. The two extensions shipped by default, NoScript and HTTPS-Everywhere, are already the complete set you need — anything from a third-party source adds not just a fingerprinting risk but a direct malware and data-exfiltration risk, since an extension has broad access to everything you do inside the browser. Run Tor Browser exactly as it ships, with nothing added.
Fingerprinting
Tor Browser's anti-fingerprinting design works by making everyone report the same generic values — screen resolution, timezone, user agent — so that no single browser instance stands out from the crowd it's hiding in. That protection is a shared resource: it only holds as well as the crowd stays uniform, which means every deviation you introduce weakens it a little, for you specifically. Resizing the browser window is a common unconscious habit that changes your reported viewport dimensions; maximizing it or leaving it at the default size avoids that entirely. Changing the default language settings does the same thing from a different angle — it's one more value that most other Tor users leave untouched, so touching it moves you further from the average. None of these individually feels significant, which is exactly why they're easy to overlook; the model only works if you resist the urge to customize anything.
⚠️ Important Warnings
- 🔌 Never install extensions beyond the two Tor Browser ships with — even trusted ones make you fingerprintable
- 🔧 Never drop the global security level below Safest to work around one inconvenient page
- 🖼️ Avoid resizing the browser window — it changes your reported viewport and stands out from the default
- 🌐 Leave language and locale settings on default — every customization moves you further from the crowd you're blending into