Tor Blog | The Tor Project [Unofficial]

@blog.torproject.org.web.brid.gy

🌉 bridged from 🌐 https://blog.torproject.org/: https://fed.brid.gy/web/blog.torproject.org

New Release: Tails 7.10.1

This release is an emergency release to fix critical security vulnerabilities in the _Linux_ kernel and the _expat_ XML library. ## Changes and updates * Update the _Linux_ kernel to 6.12.100, which fixes CVE-2026-64560, a vulnerability that could allow _Tor Browser_ in Tails to gain administrator privileges. For example, if a malicious website that you visit is able to exploit CVE-2026-64560, they might take full control of your Tails and deanonymize you. This attack is very unlikely but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this attack being used in practice until now. * Update the _expat_ XML library to 2.8.2, which fixes DSA-6404-1, a set of vulnerabilities that could allow different applications in Tails to gain administrator privileges. For example, if an attacker tricks you into opening a malicious file in an application that uses _expat_ , such as _LibreOffice_ , _Audacity_ , or _Git_ , they might then use one of these vulnerabilities to take full control of your Tails and deanonymize you. This attack is very unlikely but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this attack being used in practice until now. * Compress automatic upgrades with `zstd` for a faster startup, as we already did for the USB image in Tails 7.0. * Make USB images and automatic upgrades 70 MB smaller by removing unused firmware. For more details, read our changelog. ## Get Tails 7.10.1 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.10.1. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.10.1 on a new USB stick Follow our installation instructions. The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.10.1 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

Snowflake Volunteer, an Android app to help people bypass censorship

Bypassing censorship comes down to two challenges: disguising internet traffic from censors while making an open network easy to reach. Snowflake is particularly effective at tackling both of these challenges. It disguises a user's traffic to look like a video call and routes it through volunteer-run proxies using short-lived connections, making the traffic harder to detect and block. **That's why it's important to have a large and healthy pool of volunteers always available. To achieve that, Snowflake has to be easy to use and deploy, ideally on the devices and with the services they already use.** Up until this point, volunteers could use browser extensions, a website embed, a command-line tool for desktop, and on Android they can use Orbot's _Kindness Mode_. During the first half of 2026, the Snowflake broker saw an average of approximately 146,000 unique volunteer proxy IP addresses checking in each day1. Roughly a third of those were associated with Orbot's Kindness Mode. Kindness Mode also makes volunteering tangible by showing users how many connections their proxy has supported. Seeing how much capacity that feature contributed, Bloco, an Android app studio in Portugal became curious if a standalone app, focused just on volunteering proxies, could reach even more helpers. They reached out to Tor's anti-censorship team which had plans to work on a similar project, but had not yet had the capacity to develop it, yet. So, Bloco took on the task of building such an app. The motivation grew out of the team's work with OONI (Open Observatory of Network Interference), where they saw how NGOs and activists rely on anti-censorship tools to stay safe and connected. After discovering how easy it was to volunteer a Snowflake proxy, the team members wanted to contribute their skills and expertise to an open-source project they cared about. ## A dedicated app for Snowflake volunteers The Bloco team built on the foundations already developed by the Guardian Project for the mobile Tor ecosystem, including IPtProxy. It's an easy-to-use library that brings together the tools and ongoing pluggable transport work needed to integrate Tor into mobile apps, making it easier to keep censorship-circumvention technology current and reuse it across new apps. With these libraries already in place, that make it easy to build Tor apps for mobile, Bloco was able to focus their effort on: * Making sure the app runs successfully in the background for as long as possible, while using as little battery as possible. * Getting the user experience right, so everyone understands what the app is for, and can configure it correctly and according to their internet setup and capabilities. * Keep volunteers motivated by showing statistics of how much they're helping across time. The result is Snowflake Volunteer, a single-purpose app that gives volunteers control over when and how they contribute. Users can allow it to run in the background, restrict it to unmetered networks such as Wi-Fi, choose to run it only while the device is charging, and set a limit on how many people it can help simultaneously. Once enabled, the app automatically connects with people seeking a Snowflake proxy and helps route their connection to the Tor network. After an initial round of testing and feedback with the Tor community, Snowflake Volunteer was launched publicly in April. In May, we saw an average of approximately 1,300 daily unique proxy IP addresses. By June that had risen to approximately 1,700 per day–an increase of 29% in one month. During this initial period, activity reached a high of more than 2,100 daily proxies. This suggests that a dedicated app can bring additional volunteers into the Snowflake community. ## Become a Snowflake volunteer by downloading Snowflake Volunteer Snowflake Volunteer is available on F-Droid and Google Play. For those who want to tinker with the app, you can also build it from the source code. Helping people bypass internet censorship takes a global community. Tell a friend about this new tool or share this post so more people can learn about this app and provide feedback. We also would like to thank our community of localizers. Thanks to their efforts, the app is already available in 8 languages (Chinese, English, French, German, Japanese, Portuguese, Turkish and Vietnamese). If you want to expand access to Snowflake Volunteer, consider contributing translations into more languages. Localization is how we reach this global community. Learn more about the process, and get started. * * * 1. We analyzed 180 available daily Snowflake broker reports covering January 1 through June 30, 2026. Snowflake broker statistics are published as aggregated snowflake-stats descriptors through Tor Metrics’ CollecTor archive↩

blog.torproject.org

New Alpha Release: Tor Browser 16.0a9

Tor Browser 16.0a9 is now available from the Tor Browser download page and also from our distribution directory. This version includes important security updates to Firefox. ⚠️ **Reminder** : The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy. Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the Future of Tor Browser Alpha blog post. If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel. ## It's ESR transition season again! Well actually, it has been ESR transition season throughout this entire release cycle! As described in the aforementioned Future of Tor Browser Alpha blog post, we have been incrementally rebasing our Alpha channel on Firefox betas since December of last year. As a result, we now stand before you with Tor Browser 16.0a9 which is based on Firefox ESR 153. We will continue rebasing Tor Browser 17.0 Alpha branches on Firefox betas throughout the remainder of the Tor Browser 16.0 release cycle. However, new feature-work for now must be put on hold for a few reasons: * We must focus our attention on resolving our Bugzilla Audit issues to ensure the features we have inherited from upstream comply Tor Browser's threat model and to patch any changes which do not. * Feature work targeting 16.0 stable would need to be cherry-pick'd onto our 17.0 Alpha branches to ensure we don't lose any work. The more invasive a feature patch is, the harder it will be to port to newer versions. This would also be a potentially error-prone process and there is some risk we would lose patches along the way. * We need to finish stabilizing as soon as possible as we have hard external deadlines which cannot be moved: the end-of-life of Firefox ESR 140 on October 13th and the Google Play Minimum Target API Level requirement on November 1st ## Challenges and Triumphs ### 💍 Sharing the Load Rebasing the hundreds of Tor Browser patches onto newer versions of Firefox is a challenging task. It is like maintaining the structural stability of sand-castle at high-tide with the waves crashing all around you. As such, it quickly become clear early in this new process that we would need to do something if we wanted to avoid burning out the few developers typically involved in this work. To mitigate this, we shared the knowledge internally and spread the work out across all eight members of the team. This way, each developer was only responsible for at most two or three rebases throughout the entire release cycle. ### 🎨 UI Code Churn Over the past year, Firefox has developed and integrated two major changes to the UI in Firefox: a redesign of about:preferences in Firefox Desktop and a migration from Material 2 to Material 3 in Firefox Android. Adapting to these types of changes to the frontend are typically rather time-consuming for us, as many (if not the majority) of our patches modify Firefox's UI in some way. For example, we have an entire preferences page on Tor Browser desktop dedicated to configuring how the browser connects to the Tor Network. On Android, we similarly have various additions to the menus, configuration options, and custom UI. Whenever Mozilla modifies their design systems and Firefox's user interface, we necessarily have to adapt our own custom additions to match. Otherwise, our Tor Browser-specific UI elements would look completely out of place and potentially confuse users (as well as simply looking unprofessional). Therefore, each of these upstream changes requires collaboration with the Tor Project's UX team to update our features' designs and of course development time to implement. In addition to the time-cost associated with the extra engineering and UX collaboration, very often our old patches simply do not apply cleanly due to the amount of code which has changed. For example, the about:preferences changes on Firefox Desktop are essentially a complete re-write which means we also have to completely re-write our own settings changes without regressing in functionality. On the plus side, one benefit of our new processes is that we have been able to spread out this work over the entire release cycle. In the past way of doing things, we would have discovered all UX elements which needed to be fixed, updated our designs, and re-implemented in the course of a few months during the old ESR transition season. Under this new way of working, we have been able to incrementally fix things throughout the development cycle. The benefits of working this way does not just apply to UX of course. It is much easier to find regressions across the entire stack when rebasing between one major Firefox version at a time instead of across 12 or 13. It is also _much_ easier for developers to fix individual regressions one at a time compared to diagnosing, disentangling, and fixing multiple bugs concurrently (divide et impera!). ### ⚙️ Pending Google Target API Level Requirements Every year, Google requires new Android app releases to target an updated minimum API level. This means, we would not be able to upload new versions of Tor Browser Stable past a certain date (usually August 1st with an extension to November 1st typically possible) without first updating the app to support the new minimum target API level. Fortunately, we inherit most of the required changes from Mozilla when rebasing to the next major ESR. However, this requirement does impose a hard deadline for the absolute latest we can responsibly stabilize Tor Browser Alpha and promote it to Stable. We've been fortunate in the past few years to make the deadline with a few days to spare (October 28th for Tor Browser 15, October 22nd for Tor Browser 14, etc). Given how far ahead of the curve we are this year, we are hoping to release about a month earlier in September (fingers crossed!). ### 🤖 Android APKs too big The Google Play Store has a strict size limit of about 100 megabytes for Android applications. New functionality added to Firefox Android over the past year means a larger application which results in new headaches for Tor Browser developers. This release cycle was no exception to this rule and we have had to get _creative_ with our size reductions. In the past, we have been able reduce our package size though various methods including: * Using custom size-reducing compiler flags * Compiling multiple pluggable-transports into a single unified binary to de-duplicate shared dependencies * Removing unused Firefox assets from the build * Replacing unused (but still linked) libraries with no-op stubs * and countless other methods over there years Our most recent effort has been the most invasive yet! For some background, the Firefox application consists of (among other things): various shared libraries, the Firefox executable, a library known as 'xul' which contains most of Firefox's natively compiled functionality, and finally a file known as `omni.ja`. This `omni.ja` file is a `zip` archive which contains the JavaScript, HTML, images, and other assets used in Firefox. This time around, to reduce the size of our Android package we havechanged how this archive is compressed. We modified the Firefox build system to compress this archive with `xz` and we modified Firefox itself to decompress this archive at runtime. This work did require a few iterations to get right. In the end, we got back about 3 megabytes with these changes and got us once again under Google's imposed size budget. ### 📉 Even Less Telemetry Over the years, we have worked to incrementally remove dependencies from Tor Browser Android as part of the aforementioned size reduction work. We of course inherit most of these dependencies from Firefox Android and unfortunately some of them can be labeled as 'trackers'. While we do disable telemetry by default at runtime, the code which implements it remains in the codebase. We're happy to report that as of Tor Browser 16.0a8, are down to only 1 'tracker' library in the Tor Browser Android codebase: `Mozilla Telemetry`. Again, this telemetry _is_ disabled at runtime, but this is one more unused dependency which we can hopefully remove in the future (and maybe get some more bytes back!). ## Current Status We have: * incrementally rebased Tor Browser and Tor Browser for Android to Firefox ESR 153 from Firefox ESR 140 * updated the build systems with the latest dependencies and fixed a few reproducibility issues * triaged _most_ of the upstream changes from the past year and flagged over 250 issues for further review (triaging of Firefox 153 is in progress) * resolved about half of these triaged issues For the remainder of this release cycle, we will be focusing on auditing these issues and fixing bugs until the 16.0 alpha series is ready to become Tor Browser Stable 16.0. We are optimistically targeting a September release, which would put us one month ahead of schedule compared to last year. ## Known Issues ### 🦊 Firefox Branding In some places in the browser there may be Firefox branding (e.g. logos, cute little foxes, etc) instead of Tor Browser branding. We're currently tracking one known instance in tor-browser#44998. If you discover any other instances lurking about, please open an issue! ### 🌐 All websites marked 'insecure' on Tor Browser Android Currently, the identity block in the URL bar on Tor Browser Android will always report insecure (e.g. a shield icon with a slash through it). For now, you can tap this icon and verify the certificate manually. This issue is being tracked in tor-browser#45115 ## Send us your feedback Now is a great time to become an alpha tester! If you find a bug or have a suggestion for how we could improve this release, please let us know. ## Full changelog The full changelog since Tor Browser 16.0a8 is: * All Platforms * Updated NoScript to 13.6.30.90201984 * Bug tor-browser#43819: Show custom security level on android * Bug tor-browser#44748: Revert Funding the Commons Implementations * Bug tor-browser#44811: Remove the lock on pdfjs.disable. * Bug tor-browser#45101: Rebase Tor Browser onto 153.0esr * Bug tor-browser#45131: Security level is using an unsafe getBoolPref * Bug tor-browser-build#41831: Update libevent to 2.1.13 * Windows + macOS + Linux * Updated Firefox to 153.0esr * Bug tor-browser#44439: Remove translate action from urlbar * Bug tor-browser#44883: Remove urlbar quick action for labs * Bug tor-browser#45029: Convert connection status settings to new design and config approach * Bug tor-browser#45055: Rename --color-gray-05 to --color-gray-0 * Bug tor-browser#45081: Use the new "Acorn" icons on desktop * Bug tor-browser#45110: Disable the settings redesign until ready for us * Bug tor-browser#45112: Missing CSS border tokens in 153 * Bug tor-browser#45132: nsAppFileLocationProvider.cpp: use of undeclared identifier 'XRE_EXECUTABLE_FILE' * Bug tor-browser-build#41800: Create a script that adapts the Tor Browser manual HTMLs to work in Tor Browser * macOS * Bug tor-browser#45108: Artifact generation fails due to missing .DS_Store in the branding directories * Android * Updated GeckoView to 153.0esr * Bug tor-browser#43820: Use SecurityLevel integration on android * Bug tor-browser#44157: Remove secret setting toggle for Tab Management Redesign * Bug tor-browser#45045: Remove moz asset in Downloads screen * Bug tor-browser#45103: Disable broken "tab management" * Bug tor-browser#45109: No value passed for parameter 'jsEnabled' * Bug tor-browser#45118: Audit and disable Mozilla VPN promo * Bug tor-browser#45130: Clean up TorHomePage padding * Build System * All Platforms * Bug tor-browser-build#41838: Update personal_access_tokens URL in tools/fetch_changelogs.py * Windows + Linux + Android * Updated Go to 1.26.5 * Windows * Bug tor-browser-build#41819: Fix windows-rs URL in projects/firefox/config * applications * releases

blog.torproject.org

New Release: Tails 7.10

## New features ### New shutdown procedure Tails now uses the standard shutdown procedure from GNOME. The standard shutdown procedure is a bit slower, but better prevents data loss. For example, the **Power Off** confirmation dialog informs you if an application needs to be closed or an open document needs to be saved before shutting down. Even without confirming or saving the open documents, Tails will shut down after 60 seconds. You can still use the faster emergency shutdown as before. ### _Celluloid_ video player We replaced _GNOME Videos_ with _Celluloid_ , a more modern and reliable video player. For added security, _Celluloid_ cannot access the network. You can either: * Open online videos, like MP4 and AVI files, in _Tor Browser_. * Open online streaming addresses, like IPTV and HLS addresses, in _VLC_ , installed as additional software. _Celluloid_ doesn't work on some computer from 2011 or earlier. You can use _VLC_ instead, installed as additional software. ## Changes and updates * Update _Tor Browser_ to 15.0.19. * Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on. For more details, read our changelog. ## Get Tails 7.10 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.10. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.10 on a new USB stick Follow our installation instructions. The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.10 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

New Alpha Release: Tor Browser 16.0a8

Tor Browser 16.0a8 is now available from the Tor Browser download page and also from our distribution directory. This version includes important security updates to Firefox. ⚠️ **Reminder** : The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy. Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the Future of Tor Browser Alpha blog post. If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel. ## Send us your feedback If you find a bug or have a suggestion for how we could improve this release, please let us know. ## Full changelog The full changelog since Tor Browser 16.0a7 is: * All Platforms * Updated NoScript to 13.6.25.90301984 * Updated Tor to 0.4.9.11 * Updated OpenSSL to 3.5.7 * Bug tor-browser#44857: Drop `browser.display.use_system_colors` from our preference list * Bug tor-browser#44896: Review Mozilla 2030929: Remove unused pref privacy.partition.network_state * Bug tor-browser#45018: resistfingerprinting not available in appearance.mjs in 152 * Bug tor-browser#45019: ReportBrokenSite startup error in 152 * Bug tor-browser#45047: Cross-site oracle via worklet rejection error in Safer Mode * Bug tor-browser#45072: Disable XSLT already for 16.0 * Windows + macOS + Linux * Updated Firefox to 152.0a1 * Bug tor-browser#44528: Make sure desktop IP Protection is disabled on desktop * Bug tor-browser#44795: Revert BB 27604 patch as not needed anymore * Bug tor-browser#44844: Use new urlbar CSS variables * Bug tor-browser#44888: Use `--button-opacity-disabled` for disabled styling. * Bug tor-browser#44955: Use `context-fill` for `about-wordmark.svg` * Bug tor-browser#44956: Switch colours in letterboxing setting icons to match the tab-alignment icons * Bug tor-browser#45016: Several errors about EngineProcess.sys.mjs in 152 * Bug tor-browser#45017: Wrong letterboxing background in 152 * Bug tor-browser#45037: Potential runtime errors in the search service when changing JS status * Bug tor-browser#45043: Re-add missing changes to settings after 151/152 rebase * Bug tor-browser#45083: Error in about:preferences due to ipprotection missing * macOS * Bug tor-browser#44728: Bundled fonts are broken on macOS when the GPU process is enabled * Linux * Bug @ libfontconfig.so.1#45048: Backport Bugzilla 2041887: Crash in after users upgraded to fontconfig 2.18.0 [tor-browser] * Android * Updated GeckoView to 152.0a1 * Bug tor-browser#43856: Fix onBackPressed() deprecation * Bug tor-browser#44091: Add frequent regions to tor connection assist for android * Bug tor-browser#44175: Remove all default browser functionality (Android) * Bug tor-browser#44769: TBA crash screen has firefox asset as well as a "Send crash report" button * Bug tor-browser#45052: Initialise Tor modules on android in the same order as desktop * Build System * All Platforms * Bug tor-browser-build#41802: Remove the tor daemon requirement for signing * Bug tor-browser-build#41809: Update toolchains for Firefox 152 * Bug tor-browser-build#41813: Disable build artifacts in `make generate_gradle_dependencies_list-geckoview` * Bug tor-browser-build#41821: Update gpg subkeys for boklm * Bug tor-browser-build#41823: Add versions information to the toolchain list update * Bug tor-browser-build#41827: Update morgan's keychain with renewed key * Windows + Linux + Android * Updated Go to 1.26.4 * Windows * Bug tor-browser-build#41810: Define GetAddrInfoExCancel on mingw * Android * Bug tor-browser#45086: Compress omni.ja with xz on Android * Bug tor-browser-build#41830: Update the browser project to change omni.ja.xz * applications * releases

blog.torproject.org

New Release: Tails 7.9.1

## Changes and updates * Update _Tor Browser_ to 15.0.17. * Update the _Tor_ client to 0.4.9.11. * Update the _Linux_ kernel to 6.12.94, which fixes CVE-2026-43503 (_DirtyClone_) and CVE-2026-46331 (_PACKET_EDIT_MEME_), vulnerabilities that could allow an application in Tails to gain administration privileges. For example, if an attacker was able to exploit other unknown security vulnerabilities in an application included in Tails, they might then use CVE-2026-46331 to take full control of your Tails and deanonymize you. This attack is unlikely, but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this vulnerability being used in practice until now. ## Fixed problems For more details, read our changelog. ## Get Tails 7.9.1 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.9.1. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.9.1 on a new USB stick Follow our installation instructions. The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.9.1 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

Arti 2.5.0 released: Stable Counter Galois Onion

Arti is our ongoing project to create a next-generation Tor implementation in Rust. We're happy to announce the latest release, Arti 2.5.0. This release marks Counter Galois Onion as a stable feature and includes it in full feature builds. Likewise, Congestion Control is now enabled in default builds of Arti, increasing the overall speed without any further configuration. Unfortunately, this release also comes with the disclosure of two medium-severity DoS security issues, TROVE-2026-024 as well as TROVE-2026-027, whose fixes are of course included within the release. Additionally, this release continues our ongoing development towards using Arti as a relay and as a directory authority. Another noteworthy change is that we've increased our minimum supported Rust version to Rust 1.91, released in October 2025. Of course, this release also contains a number of bugfixes, cleanups, and improvements throughout various parts of the code base. For full details on what we've done, including API changes, and for information about many more minor and less-visible changes, please see the CHANGELOG. For more information on using Arti, see our top-level README, and the documentation for the arti binary. Thanks to everybody who's contributed to this release, including 5225225, Neel Chauhan, hjrgrn, moumenalaoui, pryty26. Also, our deep thanks to our sponsors for funding the development of Arti! * announcements * releases

blog.torproject.org

Sunsetting Tor 0.4.8 – Please update to 0.4.9 by September

Hello Tor Community! As you know, different teams inside the Tor Project are working on the Arti Relay project where we hope to be able to begin the upgrade of the network towards our Rust implementation of Tor in the near future. To support this work, we would like to announce that we intend to actively stop compatibility for 0.4.8 and earlier C Tor versions soon. This means that these versions will _no longer work on the network at all_ after our target date, which is currently September 1st, 2026. If you’re a Tor Browser user running an up-to-date version of Tor Browser, this won't impact you. If you're running an older, perhaps not-so-well-maintained, Onion Service somewhere, or you’re building an app that integrates C Tor, you may want to read along here. Tor 0.4.8 reached End of Life on the 1st of June, and there will not be any more updates to this release series. We highly encourage people to upgrade to the Tor 0.4.9 series (or later). Usually, we try not to break existing releases, even if they are unsupported, unless we have a pretty good reason. In this case, we have several reasons. With the work towards Arti on both the client and relay, the Network Team has identified a couple of features we would like to remove from the Tor ecosystem. Removing support for 0.4.8 will help us facilitate a smooth transition, and reduce effort associated with difficult to maintain features that provide very little value. Unfortunately, because Tor’s Directory Protocol layer works the way it does, we cannot remove these features without affecting older clients. The most important reason is this: in 0.4.9, we have made some former fields in our directory data obsolete -- specifically, TAP onion keys and family lines. Removing these fields will let us save a great deal of client directory bandwidth for everyone. This, in turn, will make all Tor clients bootstrap a little faster, especially those on slow connections. But when we remove these fields, clients and relays running earlier versions of Tor will no longer work, since they expect the TAP onion keys to be present. Therefore, in order to deliver improved performance faster, we need to accelerate the date on which 0.4.8 will stop working. The secondary reason for sunsetting 0.4.8: Our Arti directory authority implementation needs network integration soon, and it will be easier to write if it doesn’t support deprecated fields. With this blog post out, we will begin reaching out to the downstreams of Tor we identified as shipping older versions and try to get them to upgrade. We appreciate community help here, too. If you identify that your favorite project that bundles Tor uses an outdated version of Tor, please reach out to them and (politely!) encourage them to upgrade. We are tracking some of this outreach in network-health/team#460. If you have a very good reason for needing a longer time with 0.4.8 support than 1 September 2026, please let us know by leaving a comment on that ticket. Thank you! * tor

blog.torproject.org

Paskoocheh: When you need a tool to reach the tool

_**++ This guest post is part of a spotlight series on the organizations defending the free Internet.++**_ Due to heavy information controls, people in Iran face significant barriers to accessing the Internet. Authorities have actively blocked numerous websites and apps, including conventional circumvention and digital security tools such as VPNs, social media platforms, and the app stores themselves. This creates a "chicken-and-egg" problem: users need a VPN to download a VPN. Launched in 2016, Paskoocheh, Persian for "alleyway," is an open source alternative app store, community hub, and one-stop-shop for users to access information and tools to circumvent censorship, enhance their privacy, securely communicate, and express themselves freely online. Developed and maintained by ASL19, a technology and exiled media organization named after Article 19 of the Universal Declaration of Human Rights, Paskoocheh restores access and allows people to reach trusted tools through four censorship-resilient channels: the Paskoocheh website, Android App, Email bot, and Telegram bot. Users are also able to reach our Persian-speaking support team through the Paskoocheh Helpdesk, which handles over 200 tickets daily. In addition, ASL19 translates and publishes accessible user guides, blog posts, and multimedia content to help users navigate online privacy and digital security best practices. Paskoocheh serves as more than an alternative app store; it is also a bridge between tool developers and in-country users. Our support team relays user feedback to tool developers, helping improve tools and overall experience in Iran. We also conduct in-country testing with developers and user communities to evaluate new features and strengthen censorship-resilient technologies. ## Paskoocheh's impact so far This combination of access, user support, and education has turned Paskoocheh into a critical lifeline for users in Iran. * **# of tool downloads since 2016:** 17,634,852 * **# of community members in Iran supporting testing and localization efforts:** 2,000+ * **# of monthly active users on web and app:** ~200K During periods of internet disruption and nationwide protests in Iran, these tools became critical communication lifelines. One longtime user wrote to us: > _"I've been using this free app for several years now. It's free, unique, and unlike others, it has no equal." Reflecting on the broader digital environment in the country, they added that "in these difficult economic conditions, people are struggling just to survive, while many apps either empty people's pockets, deceive and lie to them, or serve as tools for spying and propaganda."_ Messages like these highlight the importance of privacy-preserving technologies in environments where surveillance, censorship, and disinformation shape everyday life online. In moments of crisis, internet freedom tools become part of how people maintain relationships, exchange trusted information, and stay connected to the outside world. For some users, these tools also made it possible to continue reporting on events on the ground, verify information during periods of state-backed disinformation, and safely communicate evidence of abuses despite widespread surveillance and connectivity disruptions. ## The future of Paskoocheh: Scaling a community-first approach to internet freedom As internet censorship tactics evolve rapidly, internet shutdowns are becoming more frequent and more sophisticated, cutting communities off from information, communication, and one another. What we have learned through this work is that access alone is not enough. Technology is only useful if people trust it, understand how to use it safely, and can rely on support networks when digital spaces become unstable or dangerous. That is why our work extends beyond technical development. Alongside building secure access technologies, ASL19 invests heavily in user education, digital security guidance, and community capacity building. Every support ticket answered, training delivered, and piece of digital safety guidance shared helps people stay connected under pressure. This human-centered approach is becoming increasingly important as authoritarian tactics evolve globally. During internet shutdowns and heightened censorship, local helper communities often become the first line of assistance for journalists, activists, students, and ordinary citizens. With additional support, ASL19 aims to continue expanding Paskoocheh beyond its current capacity into a broader resilience ecosystem that combines technical innovation with stronger on-the-ground support systems. This includes improving access to trusted circumvention and privacy tools during shutdowns, expanding multilingual user support and educational resources, and deepening collaboration with communities operating under digital authoritarianism. This work is not solely about technology products. At a moment when most people's understanding of the internet is shaped by the little squares in their pockets, it is important to acknowledge and support the broader ecosystems that make access possible. Civil society, independent media, and grassroots communities all play a part in helping people survive under pressure. This is why partnerships within the internet freedom ecosystem matter. Living under digital authoritarianism means that these are not abstract protections against hypothetical risks, but practical tools that make journalism, organizing, education, and communication possible in the first place. ### About ASL19 Named after Article 19 of the Universal Declaration of Human Rights, ASL19 is a technology and exiled media organization working to counter digital authoritarianism. For more than a decade, we have partnered with civil society groups, journalists, researchers, activists, and internet users living under some of the world's most restrictive online environments. Guided by the belief that privacy and internet freedom are essential to safe communication, access to information, and civic participation, ASL19 develops technologies and support systems that help people navigate censorship, surveillance, internet shutdowns, and information manipulation. In countries such as Iran, Russia, and China, these tools serve as critical lifelines, enabling people to communicate securely, access information, document human rights abuses, and stay connected to the outside world. * community * human rights * partners * fundraising

blog.torproject.org

New Alpha Release: Tor Browser 16.0a7

Tor Browser 16.0a7 is now available from the Tor Browser download page and also from our distribution directory. This version includes important security updates to Firefox. ⚠️ **Reminder** : The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy. Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the Future of Tor Browser Alpha blog post. If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel. ## Send us your feedback If you find a bug or have a suggestion for how we could improve this release, please let us know. ## Full changelog The full changelog since Tor Browser 16.0a6 is: * All Platforms * Updated NoScript to 13.6.19.90401984 * Updated Tor to 0.4.9.9 * Bug tor-browser#42436: Allow for multiple configured (front, reflector) domain fronting pairs in Moat module * Bug tor-browser#44869: Rebase alpha onto 151 * Bug tor-browser#44952: TOR_PROVIDER=none throws an error at launch * Bug tor-browser#44989: Backport Bug 2040704: Fix date format leak in Firefox 151 * Bug tor-browser#44990: CI failing due to dubious ownership of cached repo * Bug tor-browser#44999: Privacy settings are broken in 151 * Bug tor-browser-build#41686: Copy more build artifacts to the artifacts directory * Windows + macOS + Linux * Updated Firefox to 151.0a1 * Bug tor-browser#44903: Use the `support-page` instead of `tor-manual-page` in `moz-support-link` * Bug tor-browser#44904: Use settings config for onion site settings * Bug tor-browser#44991: Improve the no-authentication handling on the control port * Bug tor-browser#44997: Captcha doesn't work in TB desktop * Bug tor-browser#45005: Rename arrowpanel CSS variable * Windows * Bug tor-browser#44745: Change how we hide SSO setting for windows * Android * Updated GeckoView to 151.0a1 * Bug tor-browser#43543: Make the dev icon distinct from the nightly one * Bug tor-browser#44211: Disable "Shake it up. Skip the scroll." * Bug tor-browser#44323: Audit Android Settings changes from 128 to 140 * Bug tor-browser#44917: Disable Ads client for all channels * Bug tor-browser#45031: Disable AI features for Android * Build System * All Platforms * Bug tor-browser-build#41779: Update toolchains for Firefox 151 * Bug tor-browser-build#41781: Fix clean section in rbm.local.conf.example * Bug tor-browser-build#41792: Switch from ftp.gnu.org to ftpmirror.gnu.org * Bug tor-browser-build#41798: Update the URL to versions.ini in relprep.py * Bug tor-browser-build#41806: `make list_toolchain_updates` should check var/firefox_platform_version * Bug tor-browser-build#41807: Incorrectly generated Bugzilla query link in generate-bugzilla-triage-csv.py * Windows + Linux + Android * Updated Go to 1.26.3 * macOS * Bug tor-browser-build#41793: Stop copying permissions from .mar in dmg2mar * Android * Bug tor-browser-build#41801: Hardlink artifacts in fix_gradle_deps.py * applications * releases

blog.torproject.org

New Release: Tails 7.8.1

This release is an emergency release to fix a serious security vulnerability in the Linux kernel, as well as security vulnerabilities in the _Tor_ client. ## Changes and updates * Update the _Tor_ client to 0.4.9.9, which fixes several security vulnerabilities. * Update the _Linux_ kernel to 6.12.90-2, which fixes CVE-2026-43503, a vulnerability that could allow an application in Tails to gain administration privileges. For example, if an attacker was able to exploit other unknown security vulnerabilities in an application included in Tails, they might then use this vulnerability to take full control of your Tails and deanonymize you. This attack is very unlikely, but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this vulnerability being used in practice until now. ## Get Tails 7.8.1 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.8.1. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.8.1 on a new USB stick Follow our installation instructions. The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.8.1 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

Supporting those who speak out

_**++ This guest post is part of a spotlight series on the organizations defending the free Internet.++**_ Fear of digital surveillance breeds silence. In the words of a youth activist in Zambia who took part in a research study tracking digital security threats: > _We are all fearful. It makes you constantly paranoid. It also undermines our work. It discourages us. It's very disheartening. It's difficult to keep the fire going. I've sort of stepped back from the front line._ Silencing of whistleblowers, journalists and human rights defenders deprives citizens of the credible information they need to participate meaningfully in public life. It undermines democracy, enabling corruption and human rights abuses to flourish. Blueprint for Free Speech is a non-profit committed above all to upholding the right to freedom of opinion and expression for all people, as enshrined by Article 19 of the Universal Declaration of Human Rights. We work internationally to promote protections for a free and independent media, the free flow of information, institutional transparency and support for whistleblowers. Industrial-scale surveillance with military-grade spyware is having a chilling effect on investigative journalism and human rights advocacy work, with profound implications for access to truth about power. ## Killer corporations Free access to reliable information has never mattered more. Some of the world's biggest corporations are manipulating scientific data, controlling narratives and capturing regulators to sell products they know will kill us. That's not an overstatement: it's the conclusion of the New England Journal of Medicine. Their latest research shows fossil fuels, tobacco, alcohol, ultra-processed foods, chemicals and pesticides, and drugs such as opioids cause 20 million deaths a year. Blueprint works closely with activists, journalists and whistleblowers in many of these fields, exposing or highlighting a range of public interest issues, from data privacy violations in the EU, organ trafficking in East Africa and deaths squads in West Africa and South Africa, the collapse of quality control at Boeing in the US, and the dirty tricks deployed by big tobacco in Asia and Africa. We provide them with support, public recognition, guidance, referrals and training, legal assessments, as well as arming them with actionable research. More recently, with the rise of unaccountable tech oligarchs raising the spectre of a dystopian cybernetic authoritarianism, we are increasingly supporting AI whistleblowers and have added artificial intelligence safety to our arsenal of offerings through a new European project. A common thread is the need to guard against intrusive surveillance. For anonymous whistleblowers, this translates into the difference between coming forward with public interest disclosures that could save lives, or staying silent. For journalists and activists, it means being able to continue the work of speaking truth to power. ## Ricochet Refresh Blueprint develops and maintains software that allows people to reach out to the media, NGOs and anti-corruption agencies anonymously. Ricochet Refresh is a peer-to-peer, instant messaging application by Blueprint that prioritizes user privacy and user control by design. The application and protocol are completely decentralized, and do not depend on any third-party infrastructure apart from the Tor network itself. Best of all, the project is community-driven, so we listen to what people need when using it and translate that into action. Ricochet Refresh is free and open-source software that works by creating a Tor onion service on your computer, which serves as your anonymous identity and endpoint on the network. When you communicate with a contact, a Tor circuit is established between your machine, routing data through multiple nodes so that no single node knows both the origin and destination. This strengthens anonymity. All communications are end-to-end encrypted, so message contents are only visible to the parties in a conversation. The architecture makes it particularly valuable for protecting freedom of expression among civil society groups worldwide who face surveillance risks. The Ricochet Refresh package also bundles in the Tor Project's censorship-circumvention tools to enable connectivity even in constrained network environments. It is one of the only free, open-source applications that allows unlimited file size transfer on a fully anonymized basis. This is incredibly important if you're a journalist, activist or whistleblower who wants to transfer large files, such as videos. ## Cybersecurity training Since 2024, Blueprint has conducted a series of cybersecurity training sessions in over a dozen lower- and middle-income countries in Africa, the Middle East and Asia, where the need for technical support to guard against digital surveillance is the greatest. We support journalists, researchers, community advocacy workers and others who face threats to their digital and often personal safety. These sessions apply foundational and more advanced digital security precautions with expert facilitators on-hand to help participants make practical changes to their device set-ups during the sessions. They walk out at the end of the day more cybersecure than when they arrived in the morning. As part of this, we introduce them to metadata-resistant communications platforms -- including Ricochet Refresh -- to make it safer to receive whistleblower disclosures. Whistleblowers often face vicious retaliation attacks. Anonymity gives them some protection -- and it does something else important: it shifts the public conversation from "let's blame the whistleblower!" to "let's focus on finding out about the wrongdoing". The impact of this work, made possible thanks to the time and energy invested by many people and organizations who ensure the internet is kept open and secure, is tangible and profound. As this journalist in North Africa put it: > _This session made me realise, in a very concrete way, that cybersecurity isn't just an IT department's responsibility, but also concerns my daily actions, my digital reflexes, and how I protect my professional identity online. As a journalist, this pragmatic approach was particularly useful: it gave me concrete tools, but also a new framework for analysing the risks I face._ **The digital threats faced by defenders of truth and democracy are multiplying. So should our capacity to respond to them. The free internet is at the frontline of this battle, and Blueprint's digital protection tools make a difference where it counts.** * community * human rights * partners * fundraising

blog.torproject.org

New Release: Tails 7.8

## Changes and updates * Update _Tor Browser_ to 15.0.14. * Remove _Thunderbird_. You can still install Thunderbird as additional software. If you have both the **Thunderbird Email Client** and **Additional Software** features of the Persistent Storage turned on, Tails automatically adds _Thunderbird_ to your list of additional software. A new version of _Thunderbird_ is released in Debian shortly after each Tails releases, because both _Tails_ and _Thunderbird_ follow the release calendar of Firefox. As a consequence, until Tails 7.5 (February 2026), the version of _Thunderbird_ in Tails was almost always outdated, with known security vulnerabilities. By installing _Thunderbird_ as additional software, the latest version of _Thunderbird_ is installed automatically from your Persistent Storage each time you start Tails. ## Fixed problems * Fix multiple security vulnerabilities in the Linux kernel and haveged, that could allow an application in Tails to gain administration privileges. For example, if an attacker was able to exploit other unknown security vulnerabilities in an application included in Tails, they might then use one of these vulnerabilities to take full control of your Tails and deanonymize you. For more details, read our changelog. ## Get Tails 7.8 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.8. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.8 on a new USB stick Follow our installation instructions: * Install from Windows * Install from macOS * Install from Linux * Install from Debian or Ubuntu using the command line and GnuPG The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.8 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

A new way to fund internet freedom

**A coalition of privacy, internet freedom, cryptocurrency and open-source ecosystems, led by the Tor Project and Funding the Commons, today announced a new participatory funding campaign designed to support critical digital infrastructure at a moment of systemic funding instability.** Launching today at internetfreedom.torproject.org and as an Onion Service, the campaign is the first-ever Web3-native crowdfunding initiative dedicated to the internet freedom ecosystem. The campaign accepts contributions in Bitcoin (BTC), Ethereum (ETH), Zcash (ZEC), Monero (XMR), and Golem (GLM), and benefits 10 nonprofit projects working across privacy, censorship circumvention, secure communications, and public-interest digital infrastructure. An initial $115,000 USD matching pool supported by Cake Wallet, Zcash Community Grants, Logos, and Octant -- with additional ecosystem participation expected throughout the campaign -- will amplify donations made through June 18th, 2026, using a participatory matching model designed to reward broad community participation. ## Internet freedom in peril Internet freedom has declined for 15 consecutive years. As censorship and surveillance become increasingly sophisticated and pervasive, many of the tools people rely on to communicate and organize safely, access information freely, and protect their privacy are facing financial pressure and funding cuts. Some organizations were forced to reduce staffing, scale back technical infrastructure, delay development work, and stop support for the communities that depend on them. This strain threatens the long-term sustainability of critical public-interest infrastructure. Today, the Tor Project and Funding the Commons, are launching a new experiment: a community-driven crowdfunding campaign exploring how internet freedom services and infrastructure can be funded more sustainably, transparently, and collectively. The campaign benefits organizations and tools supporting secure journalism, private communications, anti-censorship technologies, and privacy-preserving infrastructure used by millions of people worldwide. * SecureDrop: Secure whistleblower submission system used by journalists and newsrooms * OpenArchive: Privacy-first archiving tools for human rights defenders and journalists * OnionShare: Open-source tool for secure, anonymous file sharing and hosting * Ricochet Refresh: Metadata-resistant instant messaging over Tor * Onion Browser: Tor-powered web browser for iOS * Open Observatory of Network Interference (OONI): Global observatory documenting internet censorship and shutdowns * Paskoocheh, by ASL19: Anti-censorship technology and digital security support * Unredacted: Infrastructure supporting censorship circumvention and resilient communications * Digital Security Help Desk, by Miaan Group: Internet freedom technologies supporting users in Iran * Osservatorio Nessuno: Protecting activists, journalists, and civil society organizations with tech support and traceless software Tor cannot be resilient alone. Its resilience depends on the resilience of the ecosystem around it, especially smaller projects that may not have the same access to institutional funding or donor networks. This campaign is one way to bring more people into the shared responsibility of sustaining public-interest technology. ## A participatory funding model The campaign uses a participatory matching fund model called quadratic funding designed to amplify the impact of many small contributions. Rather than prioritizing only large donations, the model increases support for projects backed by broader community participation, giving more people a meaningful voice in how funds are distributed. In practice, a project supported by many smaller contributors may receive more matching funds than one supported by only a few large donors. The campaign's matching pool is supported by a coalition of organizations aligned around privacy, open infrastructure, and public goods funding, including: Cake Wallet, Zcash Community Grants, Logos, and Octant. Contributions can be made using ETH, BTC, ZEC, XMR, and GLM. > _"Privacy and internet freedom drive everything we build at Cake Wallet. We are proud to support Tor and the broader internet freedom ecosystem through this campaign, helping keep essential privacy tools accessible to everyone. Beyond supporting the mission, we are also users, advocates, and builders who have helped bring Tor's protections to over two million users worldwide."_ _- Vik Sharma, CEO, Cake Wallet_ > > _"Tor and Zcash protect complementary layers of privacy: Tor protects network privacy, while Zcash protects financial privacy. By supporting this campaign, Zcash Community Grants (ZCG) is helping sustain critical public-interest infrastructure for people who rely on privacy and internet freedom."_ _- ZCG's members_ Internet freedom tools are digital public infrastructure, and they face many of the same funding challenges as other public goods: they are widely relied on, difficult to monetize ethically, and often invisible until they are under threat. Funding the Commons has spent years working with builders, funders, researchers, and public institutions to test new ways of sustaining public goods. Partnering with Funding the Commons gives us a way to bring internet freedom organizations into a broader conversation about how public-interest infrastructure is funded, and to test a model that can be reused, improved, and expanded over time: > _"Quadratic funding is one of web3's answers to how critical infrastructure gets funded: Institutional money follows community signals, not the other way around," said David Casey, Director of Funding the Commons. "Any donation moves the match pool, no matter the size, putting weight behind the projects Tor users rely on every day."_ **The campaign launches today at: internetfreedom.torproject.org and http://swvbwbtmajvfrnz4wztx6ovshilm23ntigi73fz5wczj3aqdquq5icad.onion, and accepts donations through June 18th, 2026.** * announcements * partners * advocacy * human rights

blog.torproject.org

Preserving evidence: How OpenArchive fosters accountability and media sovereignty

_This post is part of a spotlight series on the organizations defending the free Internet._ **A picture may be worth a thousand words, but only if it survives. Behind every image or video is someone making a choice in real time: to document what they are seeing, preserve what others may try to deny, and take on the risks and responsibilities that come with creating archival records.** Now that technology outpaces regulation and social media is the dominant platform for news, communities sharing documentation of world events face exploitation and repression through targeting, surveillance, and media erasure or manipulation. Mobile media can disappear as quickly as it was captured because, for example, a phone gets confiscated, a platform removes it, or a company changes its content moderation policies. This media can become impossible to verify if or when metadata is stripped, potentially leading to unchecked mis- and disinformation due to media manipulation. Additionally, it can become dangerous when the wrong person can see who captured it or where it was stored. Eyewitnesses and the media they document and preserve, often depicting potential human rights violations, are increasingly at risk of being targets of surveillance, censorship, media manipulation, doxxing, and worse. In response to these growing threats, OpenArchive first created the FLOSS Save app in 2015. Following their mission to offer people access to ethical, secure, decentralized backends, they then created their novel, custom DWeb Storage to further help communities safely preserve their documentation without having to depend on -- at best, unreliable, and, at worst, weaponized -- centralized platforms that can remove, lose, or expose sensitive data at a moment's notice. Their vision is a future where our histories are easily preserved, securely owned, and freely accessible. OpenArchive builds towards that future through human rights-centered co-research, education/training, and tool development dedicated to the ethical collection and long-term preservation of mobile media. To achieve this, we equally prioritize privacy, usability, archival integrity, and decentralized technology to equip human rights defenders, at-risk communities, journalists, and movements worldwide with tools to preserve, verify, and act on evidence of abuses, challenging extractive technology and amplifying marginalized voices. The premise is straightforward: people should be able to easily preserve their histories safely and on their own terms. ## Built for conditions documenters actually face For over a decade, OpenArchive has maintained Save, their free, open source flagship mobile app that helps people securely archive, verify, and encrypt their mobile media while working under real-world constraints. Co-created with and for its users, it supports authentication via SHA256 hashes and ProofMode, encrypted transit via TLS and Tor, long-term preservation to destinations like the Internet Archive, Nextcloud, their novel DWeb P2P Storage backend (in beta), and redundancy through multi-server backup. In practice, this work responds to urgent risks. For example, in conditions of conflict, they expedite local deployments of Save and run trainings for local archivist communities. Documenters on the ground had named phone confiscation, arrest, and internet outages as their primary risks, exactly the conditions Save is designed for. Additionally, in one case, human rights defenders facing corporate environmental abuse had a different challenge: none of the documenters they had surveyed were using encrypted tools in their workflows, leaving them vulnerable to tracking and surveillance. In other contexts, human rights defenders also named privacy and inconsistent internet access as major barriers, underscoring how easily documentation can become vulnerable before it ever reaches an archive. OpenArchive's work grounds those realities. Guided by the human rights-centered design methodology (co-created by OpenArchive's Executive Director, Natalie Cadranel and leading human rights experts), the team works with documenters, archivists, journalists, and advocates to understand their threats, constraints, workflows, and safety needs before designing tools around them. Most social media platforms are optimized for attention and monetization, not for archival preservation, provenance, or community control. A centralized platform presents a single point of failure, an easy access point for censorship, targeting, link rot, or account / company shutdowns. ## From camera roll to decentralized archives Responding to this specific need, OpenArchive has built a novel p2p DWeb Storage backend for Save, now in beta. In addition to Nextcloud and the Internet Archive, it gives communities an alternative to centralized platforms, one designed around privacy, verifiability, and resilience rather than someone else's business model. Under the hood, it uses two open source protocols: Veilid for encrypted peer-to-peer networking and anonymous connections, and Iroh for data storage, retrieval, replication, and verification. Save users can create groups, share files into repositories, and replicate media across peers, with encrypted communication and data integrity preserved throughout. "Decentralized storage" can sound abstract. But it actually means no single company, server, or account holds the records. Copies are distributed. Access is shared among trusted peers. If one node goes down (or gets shut down), the archive survives on the others. OpenArchive's role in the internet freedom ecosystem is protecting the chain of trust around media: who captured it, how it was handled, whether it remained intact, and whether the people behind it were put at additional risk. That chain is what makes documentation usable for journalism, legal evidence, historical memory, and accountability. Much of this work is quiet by necessity. The communities most in need of secure archiving are often the least able to publicize their use of it. By offering diverse and decentralized backends, Save is built for exactly that reality. When the platform shuts down the account, when the server goes offline, or when the border is closed, the record doesn't have to disappear with it. * community * human rights * partners

blog.torproject.org

Keeping the doors open

_This guest post is part of a spotlight series on the organizations defending the free internet._ A user in China once said this about our work: > _"You have helped many many people to overcome the great firewall. Without your help, I would be in the totally darkness trap and being brain-washed."_ **We don't hear from the people who use our services very often. Most of them can't or don't feel that they can safely send a message. When one comes through, it's a reminder of what's actually at stake.** We're Unredacted, a US-based 501(c)(3) non-profit. We build and operate Internet infrastructure that helps people reach the open Internet and protect their right to privacy. We do this by operating a network of over 300 servers around the world. We're a way through when the front door is locked, and a place to communicate when the public square isn't safe. Most of the work is invisible: datacenter work, hardware, automation, open source software, bandwidth, abuse queues, monitoring alerts, and the late nights spent keeping all of it online. What we do falls into three areas. Censorship Evasion is where Unredacted Door lives, our umbrella for the services designed to route around blocking. Secure Infrastructure is where we run things like XMPP.is and our Matrix homeserver, and other free services built with security and privacy in mind. Unredacted Education is the writing and documentation side: guides and explainers for the people who want to understand the work and replicate it. Alongside those, Unredacted Labs is where we experiment with infrastructure ideas that aren't quite production-ready. GreenWare is one of those, our effort to run real network capacity on hardware that doesn't burn a lot of power. ## Unredacted Door The name is literal. When the entrance to the open Internet gets walled off, people need another way in. Unredacted Door brings together several of our circumvention services: FreeSocks, messaging proxies for Signal and Telegram, Tor bridges, and Snowflake proxies. In a recent 30-day window, these services carried nearly 300 TiB of traffic for tens of thousands of people routing around censorship in their countries. That's roughly the equivalent of bandwidth to stream tens of thousands of hours of 4K video. Demand isn't slowing, and we need to continue building more. Every new filter, every new law, every "for your safety" rollout sends more people looking for a route the censors haven't found yet. The largest piece of Unredacted Door is FreeSocks: free proxies for people in places where censorship is severe. If you've never run into one, a proxy is a relay point. Your app doesn't talk directly to the blocked service. It talks to a server that carries the connection past whatever filters are sitting between you and the wider Internet. FreeSocks is built to make that relay quietly unremarkable, which is exactly the trait a standard VPN tends to lack. A VPN advertises itself. There's a known endpoint, a known handshake, an obvious shape on the wire. Censors are very good at blocking things they can recognize. No single tool covers every situation. Tor Browser gives you strong privacy and anonymity for browsing. Snowflake helps people reach Tor when access to the network itself is blocked. FreeSocks proxies push specific traffic through a route that's harder to spot. People living under censorship usually need a few of these on hand, because no single door stays open forever. That's why we're putting serious work into the next version of FreeSocks (v2). It uses Xray - a powerful and versatile traffic-routing engine, which can make proxy traffic look more like ordinary web traffic bundled with our open source control plane that allows us to rotate endpoints automatically when censors find and block a server. The less a user has to fiddle with their setup while they're already under pressure, the better. ## GreenWare: sustainable infrastructure, literally Tor relays, bridges, proxies, and more. They run on hardware in datacenters, and that hardware has a real footprint: financial, operational, and environmental. If we want privacy infrastructure to last, we have to ask what's actually sustainable to operate. GreenWare is our attempt to shrink that footprint without shrinking what we can carry on it. The premise is straightforward: most Tor relay traffic doesn't need a server that draws power like a space heater. A relay needs a steady network, predictable CPU, and enough memory to hold its state. That's a workload a single-board computer can handle, if the chassis around it is built to take it seriously. We started with Raspberry Pi 5 boards powered over PoE, fed entirely through their network cables. The idea worked. A typical server in a datacenter draws as much power as a small space heater. A Pi draws less than a lightbulb. But the first generation had ceilings. Density wasn't where we wanted it, and a few of the supporting components weren't built for the hours we were putting on them. So we run two deployments in parallel now. The first is a 1U chassis with 20 ComputeBlade modules stacked into it. We deployed all 20 in our datacenter and moved a chunk of our Tor exit relays onto them. That chassis pulls a little over 100W under load, roughly what an old incandescent bulb burns. The second is a custom Raspberry Pi chassis we designed after the ComputeBlade work taught us what we actually wanted in the field. Both are live, and as of writing all 123 of our Tor exit relays run on this combined infrastructure, drawing roughly 400W in total. As time goes on, we'll have more to say about the chassis design and the project as it matures. The Tor network runs on people and organizations willing to operate infrastructure for it. Exits are the hardest part of that job. They need bandwidth, maintenance, abuse handling, legal nerve, and money. If we can drop the cost and the power required to run real exit capacity, more people can take on a piece of the work and diversify and grow the network. Our longer-term ambition is to keep pushing on efficient hardware, carbon tracking, and eventually renewable-powered micro points of presence. We'd be more than glad to partner with organizations and companies that want to see this grow. The open Internet is kept open by many people and organizations investing energy, time, and effort: The researchers measuring censorship, the relay operators providing bandwidth, and the communities that refuse to leave one another behind. At Unredacted, our part is building and maintaining the routes people may need when the obvious ones disappear. * community * partners * human rights

blog.torproject.org

Defending the public's right to know

_This post is part of a spotlight series on the organizations defending the free internet._ Internet freedom has declined for 15 consecutive years. Beyond surveillance, the erosion of privacy and anonymity, and information manipulation, governments are targeting specific sites and services, or attacking infrastructure itself, causing shutdowns and deliberate disruptions for internet users. But how do we know when the internet is censored and how? OONI, the Open Observatory for Network Interference, born out of the Tor Project, exists to answer that question. Through free software tools and open data OONI makes censorship measurable, verifiable, and actionable. This post is about what that looks like in practice. ## Protecting the public record OONI data is the world's largest open dataset on internet censorship: billions of measurements collected across tens of thousands of networks from 245 countries and territories since 2012. OONI's data exists because people around the world run OONI Probe and contribute measurements from the networks that they are connected to. Every new measurement adds to a shared public record. Both its scale and methodology contribute to OONI's impact. Internet censorship often works by making interference hard to see. It can make a blocked website look broken, a throttled app look unreliable, or a shutdown look like a technical failure. OONI helps expose these tactics through open measurement methodologies, peer review, expert feedback, and comparison against control measurements, so that censorship claims can be tested, challenged, and verified. To make this dataset user-friendly, OONI launched thematic pages in OONI Explorer focusing on the areas most frequently targeted: social media and messaging apps, news media, and circumvention tools. Each page includes short reports, longer research reports, and charts with the latest OONI data. In 2025, a dedicated "Blocking of News Media" page helped surface findings that would otherwise require sifting through billions or raw measurements: the blocking of the independent media outlet Zawia3 in Egypt, the blocking of 12 news media websites in Jordan, and the blocking of The Wire in India during the military conflict with Pakistan. Think about when censorship events tend to happen: elections, protests, armed conflict, national exams, and periods of political unrest. The moment when access to information matters most. OONI gives affected communities a shared factual basis at those moments to make accountability possible. ## How journalists and media organizations use OONI In 2025, Meduza, one of the most prominent Russian media outlets in exile published an article introducing OONI tools and encouraging readers to use them. It's just one example how a newsroom can effectively use censorship measurement not just to report a story, but as an act of public education: helping audiences understand how network interference works, how it can be documented, and how they can contribute to that evidence base themselves. When a news website is blocked, that's not just a technical event. It's the public losing access to reporting, communities losing access to timely information, and journalists losing access to their audiences. Documentation that can be cited and analyzed is what turns that event into something actionable. The most concrete example of that chain in action is Kenya. OONI data served as evidence in a public-interest case challenging the unlawful disruption of internet access. The case was filed by a coalition that included BAKE, ICJ Kenya, Paradigm Initiative, the Kenya Union of Journalists, Katiba Institute, the Law Society of Kenya, and CIPESA. To support the petition before the High Court of Kenya, OONI produced a detailed research report, in the form of an expert opinion, documenting the blocking of Telegram during Kenya's 2023 and 2024 KCSE national exams. This is a case where a journalists' union, digital rights organizations, legal advocates, and technical researchers were able to work from the same datasets to elevate internet disruption to a public-interest issue. And this case also helped set an important regional precedent: lawyers in Tanzania subsequently reached out to OONI for data to support legal efforts challenging the blocking of Twitter/X there, prompting OONI to publish a research report documenting the block. ## Collective action for a collective internet The Kenya-to-Tanzania ripple effect illustrates how internet censorship works across geographies. But also how we can fight it. A block on messaging apps isn't a standalone event. Journalists may lose access to sources. Activists may lose organizing channels. Circumvention tool developers may need to adapt. Researchers may need to verify what happened. Lawyers may need evidence. But everyone needs documentation. OONI's open data model is built for exactly these moments. Protecting the free internet requires documenting censorship, sharing evidence, and building the collective capacity to respond. * community * partners * human rights

blog.torproject.org

New Release: Tails 7.7.3

This release is an emergency release to fix a critical security vulnerability in the Linux kernel, as well as security vulnerabilities in _Tor Browser_ and in the _Tor_ client. ## Changes and updates * Update the _Linux_ kernel to 6.12.86, which fixes Dirty Frag, a vulnerability that could allow an application in Tails to gain administration privileges. For example, if an attacker was able to exploit other unknown security vulnerabilities in an application included in Tails, they might then use Copy Fail to take full control of your Tails and deanonymize you. We are not aware of this vulnerability being used in practice until now. * Update _Tor Browser_ to 15.0.12. * Update the _Tor_ client to 0.4.9.8. * Update _Thunderbird_ to 140.10.1. ## Fixed problems For more details, read our changelog. ## Get Tails 7.7.3 ### To upgrade your Tails USB stick and keep your Persistent Storage * Automatic upgrades are available from Tails 7.0 or later to 7.7.3. * If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade. ### To install Tails 7.7.3 on a new USB stick Follow our installation instructions. The Persistent Storage on the USB stick will be lost if you install instead of upgrading. ### To download only If you don't need installation or upgrade instructions, you can download Tails 7.7.3 directly: * For USB sticks (USB image) * For DVDs and virtual machines (ISO image) ## Support and feedback For support and feedback, visit the Support section on the Tails website. * tails * releases

blog.torproject.org

Arti 2.3.0 released: Logging, Relay, Directory authority, and RPC development.

Arti is our ongoing project to create a next-generation Tor implementation in Rust. We're happy to announce the latest release, Arti 2.3.0. This release bumps the minimum MacOS version supported by Arti to 10.14, up from 10.12. Despite being supported on a technical level, we do not recommend the use of MacOS versions that old, as they are no longer receiving updates from Apple and may have unpatched security issues. This release continues our ongoing development towards using Arti as a relay and as a directory authority. It also continues development on RPC, including adding a new RPC API for inspecting tunnel paths. Additionally, there are a couple new logging related features. Arti now supports logging to syslog when the `syslog` feature is enabled and the `logging.syslog` config option is enabled. We've also added a new `logging.protocol_warnings` option to log protocol violations as warnings. Developers who use the `arti-client` crate should note that in the release after this one, we plan to change `TorClient` to be wrapped in an `Arc` explicitly, rather than implicitly having `Arc`-like semantics. Be prepared for this breaking change, and if you have any thoughts about it, please speak up in #2469. As usual, there is also a signigicant amount of cleanup, improvements to testing, infrastructure, and documentation, and many small bugfixes. For full details on what we've done, including API changes, and for information about many more minor and less-visible changes, please see the CHANGELOG. For more information on using Arti, see our top-level README, and the documentation for the arti binary. Thanks to everybody who's contributed to this release, including Andrew Kloet, hjrgrn, and moumenalaoui. Also, our deep thanks to our sponsors for funding the development of Arti! * announcements * releases

blog.torproject.org