Tor strongly resists tracking because no single relay knows both your identity and destination. The main theoretical attack, traffic correlation, requires watching both ends of the network and is generally viable only for a state actor targeting a specific person. In practice, people are deanonymised through their own mistakes — reused identities, browser exploits, or downloads — not by breaking Tor.
- The three-relay design resists tracking by dividing knowledge
- Traffic correlation is real but needs a state-level adversary
- Real deanonymisation comes from user mistakes, not broken Tor
- Raise the security level and use HTTPS or onion services
- For ordinary users, tracking resistance is strong
This is the technical companion to can you be tracked on the dark web: a closer look at the specific ways Tor's anonymity can, in principle, be attacked — and why almost none of them matter for an ordinary user.
Why the design resists tracking
Tor's three-relay circuit means no single relay sees both your identity and your destination. To link the two, an attacker would need to observe or control multiple specific relays simultaneously — a high bar that the volunteer-run, globally distributed network is designed to keep high.
Traffic-correlation attacks
The most discussed theoretical attack is traffic correlation (or confirmation): an adversary who can watch traffic entering the network near you and leaving it near your destination can match the timing and volume to link the two. This is real and openly discussed by the Tor Project — but it requires observing both ends, which generally means a well-resourced state actor targeting a specific person already under suspicion. It is not a dragnet.
The real weak points
In practice, tracking almost never involves the network at all. People are deanonymised by reusing identities, revealing personal details, browser exploits (which raising the security level mitigates), malicious exit relays seeing unencrypted traffic, or downloads that connect outside Tor. The maths holds; the habits leak.
How to minimise the risk
- Raise the security level to Safer or Safest to disable exploitable features.
- Use HTTPS or onion services so a malicious exit can't read your traffic.
- Never reuse identities or reveal anything that links to the real you.
- Never download and run files that could connect outside Tor.
- Use a bridge if even the fact of using Tor is a risk where you are.
The verdict
For anyone not individually targeted by a major state actor, Tor's tracking resistance is strong and holds up well. The realistic threat isn't traffic correlation — it's the user handing over a thread to pull.
Frequently asked questions
Can you be tracked on Tor?
Tor strongly resists tracking because no single relay knows both your identity and destination. In practice, people are deanonymised through their own mistakes — not by breaking the network. The main theoretical attack needs a state-level adversary watching both ends.
What is a traffic-correlation attack?
When an adversary who can watch traffic entering the network near you and leaving near your destination matches the timing and volume to link the two. It's real but requires observing both ends, generally viable only for a well-resourced state against a specific target.
How are Tor users actually deanonymised?
Almost always through their own mistakes: reusing identities, revealing personal details, browser exploits, malicious exit relays seeing unencrypted traffic, or downloads that connect outside Tor. The network itself is rarely the weak point.
Can the NSA or FBI break Tor?
They can target specific individuals with significant resources, usually by exploiting mistakes or, rarely, traffic correlation — not by breaking Tor's core cryptography en masse. For anyone not individually targeted, the network holds up well.
How do you avoid being tracked on Tor?
Raise the security level, use HTTPS or onion services, never reuse identities or reveal personal details, never download and run files, and use a bridge if even using Tor is risky where you are.