Skip to content
  • Sign In
    Sign in

    Activate subscription >

    Add devices or upgrade >

    Renew subscription >

    Secure Hub >

    Don't have an account?
    Sign up >

    Sign In

  • Products

    < Products

    Solutions
    • Premium security antivirus
    • Privacy VPN
    • Identity Theft Protection
    • Personal Data Remover
    • Mobile security for iOS and Android
    • Looking for small business protection? Visit Teams
    Free device cleaners
    • Malware and virus remover
    • AdwCleaner
    • Antivirus trial
    Free identity and personal data scanners
    • Digital footprint scanner
    • Personal data scanner
    Free scam and ad blockers
    • Scam Guard
    • Scam number checker
    • Browser Guard
    See all free tools

  • Pricing
  • Partners
  • About
    Company
    • About Malwarebytes
    • Why Malwarebytes?
    • Jobs
    Newsroom
  • Resources

    < Resources

    Cybersecurity News
    • Malwarebytes Blog
    • Threat Center
    • Lock & Code podcast
    Cybersecurity Basics
    • What is Malware?
    • What is Antivirus?
    • What is Phishing?
    • See all topics
    Research reports
    • Modern Love in the Digital Age
    • Mobile Scam Report
    • How AI is reshaping trust, identity, and scams
    Small Business Learning Hub
    • Small business news
    • Upcoming Webinars
    See all resources
  • Help

    < Help

    Malwarebytes Help Center
    Community Forums
Free Download
  • Sign In
    Sign in

    Activate subscription >

    Add devices or upgrade >

    Renew subscription >

    Secure Hub >

    Don't have an account?
    Sign up >

    Sign In

News, Privacy

Tor anonymity compromised by law enforcement. Is it still safe to use?

by Pieter Arntz | September 19, 2024
The Tor logo
Add as a Preferred Source on Google

Despite people generally considering the Tor network as an essential tool for anonymous browsing, german law enforcement agencies have managed to de-anonymize Tor users after putting surveillance on Tor servers for months.

Before we go into the what the agencies did, let’s take a look at some basics of Tor.

How Tor works

On a daily basis, millions of people use the Tor network to browse privately and visit websites on the dark web. Tor enhances privacy by directing internet traffic through a minimum of three randomly chosen routers, or nodes. During this process user data is encrypted before it reaches the destination via the exit node, ensuring a user’s activities and IP address remain confidential and secure.

Here’s a closer look at how this mechanism works:

  • Entry node: When you start browsing with Tor, your connection is first directed to an entry node, also known as a guard node. This is where your internet traffic enters the Tor network, with your IP address only visible to this node.
  • Middle nodes: After entering the Tor network, your traffic passes through one or more middle nodes. These nodes are randomly selected, and each one knows only the IP address of the previous relay and the next relay. This prevents any single relay from knowing the complete path of your internet activity.
  • Exit node: The last relay in the chain is the exit node. It decrypts the information from the middle relays and sends it out to the destination. Importantly, the exit node strips away layers of encryption to communicate with the target server but does not know the origin of the traffic, ensuring that your IP address remains hidden.

This layered security model, like peeling an onion, is where Tor gets its name. Tor is an acronym for The Onion Router. Each layer ensures that none of the nodes in the path knows where the traffic came from and where it is going, significantly increasing the user’s anonymity and making it exceedingly difficult for anyone to trace the full path of the data.

Although many researchers theoretically considered that de-anonymization was possible, in general it was thought practically unfeasible if a user followed all the necessary security measures.

How did the de-anonymization work?

German news outlet NDR reports that law enforcement agencies got hold of data while performing server surveillance which was processed in such a way that it completely cancelled Tor anonymity. The reporters saw documents that showed four successful measures in just one investigation.

After following up on a post on Reddit and two years of investigation, the reporters came to the conclusion that Tor users can be de-anonymized by correlating the timing patterns of network traffic entering and exiting the Tor network, combined with broad and long-term monitoring of Tor nodes in data centers.

If you can monitor the traffic at both the entry and the exit points of the Tor network, you may be able to correlate the timing of a user’s true IP address to the destination of their traffic. To do this, one typically needs to control or observe both the entry node and the exit node used in a Tor circuit. This does not work when connecting to onion sites however, because the traffic would never leave the Tor network in such a case.

The timing analysis uses the size of the data packets that are exchanged to link them to a user. You can imagine that with access to a middle node, you can tie the incoming and outgoing data packets to one user. While this doesn’t reveal any of the content of the messages, this could help in establishing who’s communicating with who.

Tor is still safe, says Tor

The problem that Tor faces lies in the fact that it was designed with hundreds of thousands of different nodes all over the world in mind. In reality, there are about 7,000 to 8,000 active nodes, and many of them are in data centers. As a consequence, the “minimum of three” often means “only three” which increases the potential effectiveness of timing attacks.

The Tor Project said:

“The Tor Project has not been granted access to supporting documents and has not been able to independently verify if this claim is true, if the attack took place, how it was carried out, and who was involved.”

Based on the information provided, the Tor Project concluded that one user of the long-retired application Ricochet was de-anonymized through a guard discovery attack. This was possible, at the time, because the user was using a version of the software that neither had Vanguards-lite, nor the Vanguards add on, which were introduced to protect users from this type of attack

Which means they feel confident to claim that Tor is still safe to use. However, we would like to add that users should be aware that several law enforcement agencies–and cybercriminals–run Tor nodes, which can pose risks.

If you use Tor, here are some basic rules to stay as anonymous as possible:

  • Always download Tor Browser from the official Tor Project website.
  • Keep Tor Browser updated to the latest version for security patches.
  • Use the default Tor Browser settings – don’t install add-ons or change the settings unless you know what you are doing and what the implications are.
  • Enable the “Safest” security level in Tor Browser settings.
  • Only visit HTTPS-encrypted websites.
  • Avoid logging into personal accounts or entering personal information. If you post your personal information somewhere that undermines the whole idea of staying anonymous.
  • Be extremely cautious about downloading files or clicking links, even more so on the Dark Web.
  • Disable JavaScript if possible although this may break some sites.
  • Clear cookies and local site data after each browsing session.
  • Use a reputable VPN in addition to Tor for an extra layer of encryption.
  • Run up-to-date antivirus/anti-malware software on your device.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

SHARE THIS ARTICLE

X
Add as a Preferred Source on Google

About the author

Pieter Arntz

Pieter Arntz Social icon

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.

LATEST ARTICLES

News
A young man sat down with his head in one hand and holding a phone in the other.

Sextortion scammers are exploiting ShinyHunters data leaks

July 27, 2026

Scammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible.

Podcast
An illustrated padlock is mounted into a microphone stand with sound waves emitting from the device.

What’s your data worth on the dark web? (Lock and Code S07E15)

July 27, 2026

This week on the Lock and Code podcast, we discuss just exactly why it is that hackers and scammers want your data—and how you're at risk.

News
week in security

A week in security (July 20 – July 26)

July 27, 2026

A list of topics we covered in the week of July 20 to July 26 of 2026

Add as a Preferred Source on Google

Related articles

  • A young man sat down with his head in one hand and holding a phone in the other.

    Sextortion scammers are exploiting ShinyHunters data leaks

    July 27, 2026
  • A week in security (July 20 – July 26)

    July 27, 2026
  • Don’t get fooled by TikTok resin art scams

    July 24, 2026

Thank you for signing up!

Keep an eye on your email inbox for the latest newsletter

Sign up for our newsletter to get the latest cybersecurity news to your inbox

Sign Up

By submitting this form, you consent to Malwarebytes contacting you regarding products and services and using your personal data as described in our Terms of Service and Privacy Policy.

Contributors icon

Contributors

Threat Center icon

Threat Center

Podcasts icon

Podcast

Glossary icon

Glossary

Scams icon

Scams

Malwarebytes - all-in-one cybersecurity protection always by your side.

COMPUTER SECURITY

  • Rootkit Scanner
  • Trojan Scanner
  • Free Antivirus
  • Free Virus Scan
  • Premium protection

MOBILE SECURITY

google play store
  • iOS Security and Spam Blocker
apple store icon

PRIVACY PROTECTION

  • Digital Footprint Scan
  • Dark Web Monitoring
  • Adware Removal
  • Ad Blocker

IDENTITY PROTECTION

  • Identity Monitoring & Alerts
  • Credit Monitoring & Reporting
  • Identity Recovery & Resolution
  • ID Theft Insurance
  • Personal Data Remover
Threatdown powered by Malwarebytes logo
  • Business Endpoint Security Solutions
  • Managed Service Provider (MSP) Program

LEARN ABOUT CYBERSECURITY

  • Blog
  • Social Engineering
  • Phishing
  • Ransomware
  • Malware
  • Antivirus
  • What is a VPN?
  • Doxxing

PARTNER WITH MALWAREBYTES

  • Computer Repair
  • Affiliates
  • Strategic Business Partnerships
  • Resellers

ADDRESS

One Albert Quay
2nd Floor
Cork T12 X8N6
Ireland

2445 Augustine Drive
Suite 550
Santa Clara, CA
USA, 95054

ABOUT MALWAREBYTES

  • Careers
  • News and Press
  • Vulnerability Disclosure
  • Report a False Positive
  • Territory Notice
  • Special Offers

WHY US

  • Malwarebytes vs. Bitdefender
  • Malwarebytes vs. McAfee
  • Malwarebytes vs. Norton
  • Malwarebytes vs. Windows Defender

GET HELP

  • Forums
  • Sign in to MyAccount
  • Help Center
  • Twitter icon X
  • Icon facebook Facebook
  • Icon Linkedin LinkedIn
  • Icon youtube Youtube
  • Icon instagram Instagram
  • Reddit Social Icon Reddit

Cybersecurity info you can’t live without

Want to stay informed on the latest news in cybersecurity? Sign up for our newsletter and learn how to protect your computer from threats.

By submitting this form, you consent to Malwarebytes contacting you regarding products and services and using your personal data as described in our Terms of Service and Privacy Policy.

  • 日本語
  • Português Brasileiro
  • Deutsch
  • Español
  • Français
  • Italiano
  • Nederlands
  • Polski
  • Português
  • Русский
  • Your Privacy ChoicesCalifornia Consumer Privacy Act (CCPA) Opt-Out Icon
  • Legal
  • Privacy
  • Terms of Service
  • Accessibility

© 2026 All Rights Reserved