UPDATE: Don't upgrade to these bundles. The version of OpenSSL in these bundles -- even though it fixes some bugs -- introduces new bugs that will prevent Tor from working on many computers. See the following links for more information:

Please continue using the old bundles. All of the download links have been downgraded to the previous version. We will release updated bundles in a few days. Thanks.

All of the bundles have been updated. The alpha bundles contain the latest Tor and all of the bundles have received an OpenSSL update (1.0.1d for everything except the PPC Vidalia bundles which have 0.9.8y). The regular obfsproxy bundles have been discontinued but pyobfsproxy/flashproxy bundles are available from the obfsproxy page. We plan to begin shipping these as part of the regular release cycle within the next month or two.

Tor Browser Bundle (2.3.25-3)

  • Update OpenSSL to 1.0.1d
  • Update HTTPS Everywhere to 3.1.3
  • Update NoScript to

Tor Browser Bundle (2.4.10-alpha-1)

  • Update Tor to
  • Update OpenSSL to 1.0.1d
  • Update NoScript to
  • Add PDF Viewer (PDF.js) to README

Hi just a quick out-of-context question:

Is it OK to use the windows tor bundle along with the normal installed firefox simultaneously?

Yes. Just don't get confused into thinking that browsing with your normal Firefox is made safer in any way.

They both run completely separately from each other and will happily do so at the same time, the downside to this is getting the two browsers mixed up if you have them both running at the same time and then accidentally using firefox to post something that you meant to post using tor, easily done if you keep switching back and forth between the two and you are tired.

Seperate issue:

Why the fsck does Tails 0.16 use an ancient version of OpenSSL? And has it been modified somehow? I see this every boot:

Look at this:

[notice] No AES engine found; using AES_* functions.
[notice] This version of OpenSSL has a slow implementation of counter mode; not using it.
[notice] OpenSSL OpenSSL 0.9.8o 01 Jun 2010 looks like version 0.9.8m or later; I will try SSL_OP to enable renegotiation
[notice] We weren't able to find support for all of the TLS ciphersuites that we wanted to advertise. This won't hurt security, but it might make your Tor (if run as a client) more easy for censors to block.
[notice] To correct this, use a more recent OpenSSL, built without disabling any secure ciphers or features.

You've GOT to be kidding me! Someone explain this please.

This is a normal, and expected, version of openssl from the version of debian that tails is using. Nothing to see here.

More importantly, though, this is totally the wrong place to ask tails questions. See and related links.

Also, the TBB makes numerous security and privacy changes in prefs.js or about:config.

Boosting the TOR Network speed and security by multiplexing requests.

The TOR network has hundreds of nodes if not thousands today, could they be used more effitiently by sending a request for only some packets through one node, then the next, then the next making 2 or 3 connections at a time?

Would this make statistical analisis harder? and speed up delivery of data? of course if possible.

Also NoScript on the Linux x86-64 rpm version comes out of the box set to "allow all scripts".

Sorry, the bug tracker wants me to sign in, I don't have an account.

Thank you all for your work.

Just to let you know guys, Firefox 17.0.3esr is coming out this week/month !

I'm not sure where else to post this so I will post it here.
I'm getting the message that "There is a security update available for the Tor Browser Bundle."

yet when I click on the link to go to the download page I find that I am running the same version available for download, being the Tor Browser Bundle for Windows Version 2.3.25-2

Is this an error? or is the site slow on updating the new bundle links?.
I can see that you advised people not to update to the last available bundles on February 8th but it is February the 19th today and I only just started getting the update messages today.

Has "Tor Browser Bundle for Windows Version 2.3.25-2" been changed in the past 24 hours?

Why is the Tor Check page, seen when starting TorBundle Firefox, suggesting that Tor needs a security update? "Tor Browser Bundle for Windows
Version 2.3.25-2" was installed in the first week of January. If there has been an update why has the version number not changed?

Has there been a mistake or a security breach?

Please remove the warning from if there are no new updates (or the old ones were revoked).

How do we know what version we have? the "hyphen number" part is not shown in Vidalia --> About Vidalia.

Also, I have consistently been updating and continuing to receive the "There is a security update" after updating for several days. There seems to be some sort of bug. This has happened over several sequential updates for me.

Me too, but it looks like we finally squashed the bug for now.

To see what version you are running, just click on the "i"(About) icon in the Vidalia Control Panel. Voila! There's your info!

Since you keep getting a "nag" that there is a security update, you can bet that something about YOUR configuration is not configured right. If all else fails do what I do. Delete virtually everything about TOR on your computer then reinstall it. (Works every time and only takes about two minutes if you are running any kind of Linux OS. I can't speak for WIndows as I don't use it ....never have).


PLEASE! fix the crashing in this release: tor-browser-2.3.25-5_en-US.exe

Running Fedora 17 here.

Is there a guide for getting OpenSSL without ciphers disabled? Does it require building from source? If so what are the command line options necessary to enable all ciphers? Or does the version of OpenSSL currently compiled have an option to enable all ciphers -- maybe from the command line?

[notice] We weren't able to find support for all of the TLS ciphersuites that we wanted to advertise. This won't hurt security, but it might make your Tor (if run as a client) more easy for censors to block.
[notice] To correct this, use a version of OpenSSL built with none of its ciphers disabled.

Here is full output of tor:

Mar 25 14:49:00.444 [notice] Tor v0.2.3.25 (git-17c24b3118224d65) running on Linux.
Mar 25 14:49:00.444 [notice] Tor can't help you if you use it wrong! Learn how to be safe at
Mar 25 14:49:00.444 [notice] Read configuration file "/etc/tor/torrc".
Mar 25 14:49:00.449 [notice] Initialized libevent version 2.0.18-stable using method epoll (with changelist). Good.
Mar 25 14:49:00.449 [notice] Opening Socks listener on
Mar 25 14:49:00.000 [notice] Parsing GEOIP file /usr/share/tor/geoip.
Mar 25 14:49:00.000 [notice] No AES engine found; using AES_* functions.
Mar 25 14:49:00.000 [notice] This OpenSSL has a good implementation of counter mode; using it.
Mar 25 14:49:00.000 [notice] OpenSSL OpenSSL 1.0.0k-fips 5 Feb 2013 looks like version 0.9.8m or later; I will try SSL_OP to enable renegotiation
Mar 25 14:49:01.000 [notice] Reloaded microdescriptor cache. Found 9547 descriptors.
Mar 25 14:49:03.000 [notice] We now have enough directory information to build circuits.
Mar 25 14:49:03.000 [notice] Bootstrapped 80%: Connecting to the Tor network.
Mar 25 14:49:03.000 [warn] Your application (using socks5 to port 80) is giving Tor only an IP address. Applications that do DNS resolves themselves may leak information. Consider using Socks4A (e.g. via privoxy or socat) instead. For more information, please see
Mar 25 14:49:03.000 [notice] Bootstrapped 85%: Finishing handshake with first hop.
Mar 25 14:49:03.000 [notice] We weren't able to find support for all of the TLS ciphersuites that we wanted to advertise. This won't hurt security, but it might make your Tor (if run as a client) more easy for censors to block.
Mar 25 14:49:03.000 [notice] To correct this, use a version of OpenSSL built with none of its ciphers disabled.
Mar 25 14:49:03.000 [notice] Bootstrapped 90%: Establishing a Tor circuit.
Mar 25 14:49:04.000 [notice] Heartbeat: Tor's uptime is 0:00 hours, with 3 circuits open. I've sent 1 kB and received 2 kB.
Mar 25 14:49:05.000 [notice] Tor has successfully opened a circuit. Looks like client functionality is working.
Mar 25 14:49:05.000 [notice] Bootstrapped 100%: Done.

