
When users download TBB, Tor Project provides a GnuPG signature of the package, but roughly 0% of users, including the elitest of hackers, actually verify that signature to be sure they weren’t MitM’d during the download. People often use Tor Browser infrequently enough to not bother with updating when they just want to quickly look something up anonymously, which compromises their security. It warns you when you’re using an out-of-date version but you have to repeat the download and extract process manually. You can’t easily add it to your Ubuntu Unity launcher, favorite it in GNOME 3, or stick it on a panel in Cinnamon or MATE (not to mention add it to your quick launch bar in Windows). If you want to install TBB for regular use on your computer, you don’t get a Tor Browser entry in your desktop environment’s menu system. Your browser is configured to use Tor.” page.ĭespite these advancements, Tor could still be more user-friendly. Then you extract it (normally to somewhere in your home directory, or to a USB stick) and run start-tor-browser, and wait to connect to the Tor network and for your anonymous browser to pop up with the friendly green “Congratulations. Now all you have to do is head to, click the large “Download Tor” button, and then download the Tor Browser Bundle (TBB). Eventually, this got easier when you could install the TorButton Firefox add-on, but even then you had to keep manually separate your own identity and your anonymous browsing. You had to make sure that you didn’t have browser plugins like Flash or Java enabled that would compromise your anonymity. In the past if you wanted anonymity you had to download and install Tor, maybe hand-edit your torrc file, and configure your browser to use a proxy server. Over the years, Tor Project has done an amazing job at making Tor more user-friendly. I’d like help finding bugs before the initial release. TL DR: I wrote a piece of software called Tor Browser Launcher that downloads and auto-updates Tor Browser Bundle for you, in your language and for your architecture, and verifies signatures.
