The mechanism
What the software actually does
Tor is short for “The Onion Router.” It is free, open-source software, maintained by a nonprofit, that runs on a network of thousands of relays operated by volunteers around the world.
When you use it, your traffic is wrapped in several layers of encryption and passed through — by default — three of those relays before it reaches wherever it is going. Each relay can peel off exactly one layer, so each one sees only the step before it and the step after it. That is the entire idea, and it is the same idea the Navy researchers started with three decades ago.
The entry relay sees you, not your destination
Your connection enters at a “guard” relay, which can see your real IP address. Because the inner layers are still encrypted, it cannot tell where the traffic is ultimately headed.
The middle relay sees neither end
The guard hands the traffic to a middle relay, which knows only the relay before it and the relay after it. It never learns who you are or what you are reaching.
The exit relay sees the destination, not you
The last relay strips the final layer and connects to the site you asked for. It can see the destination, but not the address you started from. No single relay ever sees both ends at once — that separation is the whole design.
The misconception
The dark web is a slice of a slice
The “dark web” people picture — hidden marketplaces, sites you cannot reach with a normal browser — refers to onion services: sites that live only inside the Tor network and end in .onion. Those are real. Two facts tend to get lost.
First, onion services are a small fraction of what Tor carries. The Tor Project’s own 2015 measurement put onion-service traffic at roughly 3.4% of the total — meaning about 96.6% of the network was ordinary web traffic, people reaching the same sites anyone else reaches. A peer-reviewed 2018 study by researchers at Georgetown and the U.S. Naval Research Lab found a similar figure, around 3.9%, and noted something telling: more than nine in ten attempts to look up an onion address failed, a pattern that points to automated bots and crawlers rather than people actually visiting.
Second, even inside that small slice, the content is mixed. Illegal markets are the visible corner, not the whole. The same .onion technology carries newsrooms, secure inboxes, and mirror sites, as the next sections show.
Who uses it
The people on the network
The Tor Project describes a deliberately broad set of users. The breadth is not a footnote — it is the security model, as the note at the end of this section explains.
Keeping internet providers, advertisers, and the sites they visit from logging what they read, buy, and search for.
Communicating and receiving documents without exposing who is talking to whom. SecureDrop, covered in the next section, runs on this.
Reaching news and services their government blocks. Tor’s “bridges” exist for exactly this, and use tends to spike in places like Iran and Russia during crackdowns.
Using support forums and staying in contact without revealing their location to someone who may be monitoring them.
Connecting to a home organization from a hostile country without broadcasting that affiliation to everyone on the local network.
Protecting sensitive research from competitors, and studying censorship and the network itself.
Running online investigations and sting operations without a police IP address turning up in a suspect’s logs, and operating anonymous tip lines.
The institution that built it. A branch of the U.S. Navy has used Tor for open-source intelligence gathering.
Onion services
Who else runs a .onion
The technology behind the “dark web” is content-agnostic. Mainstream institutions run onion addresses openly — usually to reach readers whose governments block the normal site, or to keep the connection inside Tor from end to end instead of passing through an exit relay.
October 2014
Launched facebookcorewwwi.onion so people in censored places could reach it without their network flagging the connection. The Tor Project said hundreds of thousands used it, including from Iran and China.
2016–2017
Published onion versions of their newsrooms. The Times’ launch in October 2017 was led by its information-security director, Runa Sandvik, so readers behind national firewalls could reach its reporting.
October 2019
Put its international news site on Tor specifically for readers in China, Iran, and Vietnam, where BBC News is blocked or restricted.
2016
Moved services onto onion addresses — not to hide their location, but for the end-to-end integrity and confidentiality that onion services provide.
2022
Added an onion service days after Russia blocked the platform following the invasion of Ukraine.
The channel newsrooms use to receive leaks runs on the same technology. SecureDrop, maintained by the Freedom of the Press Foundation, operates as an onion service at more than twenty major outlets — among them the Times, the Washington Post, The Guardian, and ProPublica — precisely because the design means the newsroom never learns a source’s identity, and so cannot be compelled to hand it over.
The limits
What Tor doesn’t do
Being accurate about Tor means being accurate about its ceiling. It is a strong tool, not a magic one, and treating it as either extreme gets people into trouble.
It hides where you are, not always that you are using it. Tor conceals your location and which site you are reaching from anyone watching your local connection. It does not necessarily hide the fact that you are on Tor: a network operator or internet provider can often see that a connection is going to the Tor network, even if not what travels inside. In some places that alone can draw attention — leaked 2014 rules from the NSA’s XKEYSCORE system flagged people who merely visited or searched for Tor and the Tails operating system, and the code described Tails as a tool advocated by extremists.
It protects the connection, not the person at the keyboard. Tor cannot undo a login, a real name typed into a form, tracking you carry in with you, malware on your device, or identifying metadata buried in a file — and those, not broken encryption, are how people are usually identified. When the 2013 Snowden disclosures were examined, they indicated that the NSA had not, at that point, been able to crack Tor itself.
And the illegal markets are real — and get taken down. The Silk Road marketplace was seized in 2013. In 2017, AlphaBay, a Tor onion service roughly ten times its size, was shut down in a multinational operation and its operator arrested. Anonymity for the network has never meant immunity for someone running a crime on it.
Where we come in
Why this is on our site
“That’s just for the dark web” is a label that does real work.
It steers ordinary people away from protections that were built for them, and it flattens a tool that the U.S. government still helps fund and that mainstream newsrooms still run. We cover Tor as what it is — one privacy tool among several, with specific uses and specific limits — not as a verdict on anyone who opens it. If you want to try it, our Tools and Guides pages are the place to start.
Sources
Primary sources referenced on this page
Every factual claim on this page traces to one of the following. Links go to the Tor Project’s own pages, peer-reviewed research, government records, or original reporting. The label on each source indicates the document category.
-
History — from onion routing at the U.S. Naval Research Lab to the Tor Project https://www.torproject.org/about/history/ Confirms the origin at NRL in 1995 (Goldschlag, Reed, Syverson); Roger Dingledine naming the project Tor; the network’s open-source deployment in October 2002; EFF funding in 2004; the 501(c)(3) founded in 2006; bridges added in 2007; and that the 2013 Snowden documents indicated Tor could not be cracked at that time.
-
Tor: Overview — how onion routing works and why a diverse user base matters https://2019.www.torproject.org/about/overview.html.en Source for the mechanism (traffic routed through multiple relays, each seeing only its neighbors) and for the point that the variety of Tor’s users is part of what keeps any one of them anonymous.
-
Who uses Tor? — the user categories cited in this page https://2019.www.torproject.org/about/torusers.html.en Enumerates normal people, journalists, activists, NGOs, abuse survivors, law enforcement (surveillance without government IP addresses, sting operations, anonymous tip lines), and a branch of the U.S. Navy using Tor for open-source intelligence.
-
Some statistics about onions https://blog.torproject.org/some-statistics-about-onions/ The Tor Project’s own estimate that onion-service traffic was about 3.4% of total Tor traffic, i.e. roughly 96.6% was not onion services.
-
Mani, Wilson-Brown, Jansen, Johnson & Sherr — Understanding Tor Usage with Privacy-Preserving Measurement https://arxiv.org/pdf/1809.08481 Measured about 3.9% of Tor traffic going to onion services, and found more than 90% of onion-service lookups failed — consistent with automated bots and crawlers rather than human visits.
-
Tor cofounder Roger Dingledine rebuts the “dark web” framing at DEF CON https://www.theregister.com/2017/07/29/tor_dark_web/ Reports Dingledine pushing back on coverage of Tor as a criminals’ haven, and the figure that only around 3% of users connect to onion services.
-
“Dark Web” Version of Facebook Shows a New Way to Secure the Web https://www.technologyreview.com/2014/11/03/170540/dark-web-version-of-facebook-shows-a-new-way-to-secure-the-web/ Facebook’s October 2014 launch of an onion address (built by Alec Muffett), and the Tor Project’s note that hundreds of thousands reached it, including from Iran and China.
-
The New York Times is now a Tor onion service https://boingboing.net/2017/10/27/routing-around-censorship.html The Times’ onion launch, announced by information-security director Runa Sandvik, and a note that ProPublica and Facebook had done the same.
-
BBC Launches Tor Mirror Site To Thwart Media Censorship https://www.npr.org/2019/10/24/773060596/bbc-launches-tor-mirror-site-to-thwart-media-censorship The BBC’s onion mirror for readers in China, Iran, and Vietnam, and Alec Muffett (who set up the Facebook, NYT, and BBC onions) describing “dark web” as a pejorative label.
-
Debian and Tor Services available as Onion Services https://blog.torproject.org/debian-and-tor-services-available-onion-services Debian and the Tor Project adopting onion services for end-to-end integrity and confidentiality, stating explicitly that concealing the servers’ location was not the goal.
-
Twitter has launched a Tor version https://www.techradar.com/news/twitter-has-launched-a-tor-version Twitter’s 2022 onion service, launched days after Russia blocked the platform, also built by Alec Muffett.
-
NSA Targets the Privacy-Conscious for Surveillance https://www.schneier.com/blog/archives/2014/07/nsa_targets_pri.html On the leaked XKEYSCORE rules (reported by German broadcasters Das Erste / NDR / WDR) that flagged people who visited or searched for Tor and Tails, and labeled Tails a tool advocated by extremists.
-
AlphaBay, the Largest Online “Dark Market,” Shut Down https://www.dea.gov/press-releases/2017/07/20/alphabay-largest-online-dark-market-shut-down Confirms AlphaBay operated as a Tor onion service, was roughly ten times the size of Silk Road (seized 2013), and was taken down in July 2017 with its operator arrested.
Get involved
It’s free, open to everyone at Pitt, and joining takes about a minute.
No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.