How it works

What using Tor was like in 2013, and what actually improved

Twelve years of changes: what got genuinely better, what quietly got worse, and which problems are exactly where they were.

I started using Tor in 2013, which turned out to be an interesting year to pick. Some of the experience has improved beyond recognition since. Some of it has got worse. And a few problems are sitting precisely where they were, for reasons suggesting they’ll still be there in another twelve years.

This is a retrospective rather than a guide. It’s here because a lot of the advice you’ll find online has aged badly, and almost none of it is dated, so there’s no way to tell which parts to ignore.

What it was like

You downloaded something called the Tor Browser Bundle. Running it opened a separate control panel showing your connection status and a map of relays, and then launched a browser alongside it. Two windows, two things to understand, and an overall impression that you were operating machinery rather than using software.

Slow in a way that’s hard to convey now. Pages took many seconds. The network had a fraction of today’s capacity and far fewer people running relays.

No security level control. You either knew which browser features were risky and turned them off by hand, or you didn’t.

Nothing official on mobile. Getting Tor onto a phone meant a chain of third-party apps and some optimism.

And it was a strange year to be paying attention. The Snowden disclosures put Tor in every newspaper. A botnet quietly enrolled its machines as Tor clients, making the user count appear to jump several-fold, which the network took months to absorb. A hosting provider carrying a large share of onion sites was seized, and visitors to those sites were served an exploit aimed at a browser flaw. A great deal of what people still believe about Tor was formed in those few months.

What genuinely got better

The browser became one thing. The separate control panel was retired and folded in. Installing Tor Browser is now indistinguishable from installing any other browser, which sounds trivial and isn’t — the setup step was where most people used to give up.

Security levels arrived. The shield menu turned an expert-only judgement into three choices with explanations attached. Probably the single biggest safety improvement for ordinary users in the whole period.

Addresses got real cryptography. The old sixteen-character format was retired in 2021 for fifty-six-character addresses built on modern maths, which also closed a design flaw letting anyone in the right position enumerate services.

Getting past censorship became possible for normal people. In 2013, working around a national firewall meant obtaining bridge addresses by hand and configuring them yourself. The browser now requests one for you, and newer transports disguise the traffic well enough to slip past filters that block anything obvious.

Mobile became official. Tor Browser for Android is maintained by the Tor Project rather than assembled from parts.

The web encrypted itself. In 2013 a large share of sites ran unencrypted, which made the exit relay a serious everyday exposure. That’s now the exception, and it quietly removed a whole category of risk without anyone in the Tor world having to do anything.

What got worse

Discussed less often, and true anyway.

The ordinary web treats Tor users like suspects. In 2013 you could browse most sites with no friction. Now you’re solving puzzles constantly and a meaningful number of sites refuse you outright. That’s a consequence of centralised anti-abuse infrastructure treating shared exit addresses as inherently dodgy, and it’s made routine use noticeably more annoying than it was.

Fraud went professional. The scams in 2013 were crude. Today’s impersonation sites are live mirrors with matching address prefixes, safety warnings, and last-verified dates. The people running them have got a great deal better at it.

Everything published before 2021 broke simultaneously. The address retirement was correct and I’d defend it, but it invalidated a decade of accumulated references in one go, and the resulting demand for replacements is what the current phishing economy was built on.

What hasn’t shifted at all

The exit relay is still a stranger. Anyone can run one, you don’t get to choose, and encryption has made that matter less rather than making it go away.

People still identify themselves. Logging into an ordinary account undid anonymity in 2013 and undoes it now. Still the most common failure by a wide margin, and no software change has touched it.

Traffic correlation is unsolved. Someone able to watch both ends at once may still connect them. Defences are better, the problem is open.

Downloads still betray people. Open a file outside the browser and it connects on your real address. Same trap, same victims.

What that pattern suggests

Everything on the improved list is a change to software. Everything on the unchanged list is either a property of the design or a matter of what people do.

That isn’t a coincidence, and it’s worth carrying into how you read anything you find online. Tools have improved enormously and will keep improving. The failures that actually cost people are the ones no release will fix, and they’re almost all decisions rather than defects.

Which also means the old tutorials aged unevenly. Anything about installation, configuration, or which buttons to press is probably wrong now. Anything about not logging into your own accounts is exactly as true as it was in 2013.

If you want to see the network’s growth for yourself rather than take my word for any of this, Tor Metrics publishes the numbers — relay counts, user estimates, performance over time — going back years.

Next

What Tor hides and what it doesn’t covers the unchanged list in detail. The address retirement has its own article, because it’s still breaking bookmarks today.

Leave a note