From c3e1984cbd1ae9a90cfa99cc5abaee4310e0d196 Mon Sep 17 00:00:00 2001 From: Daniel Nathan Gray Date: Wed, 30 Sep 2026 16:56:04 +0000 Subject: [PATCH] update: Wording in Tor Overview (#3279) Signed-off-by: fria <138676274+friadev@users.noreply.github.com> Co-authored-by: fria <138676274+friadev@users.noreply.github.com> --- docs/advanced/tor-overview.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/docs/advanced/tor-overview.md b/docs/advanced/tor-overview.md index 2787a7bd..d9a8a429 100644 --- a/docs/advanced/tor-overview.md +++ b/docs/advanced/tor-overview.md @@ -92,7 +92,11 @@ It is critical to understand the difference between bypassing censorship and eva ### Tor Browser is not the most *secure* browser -Anonymity can often be at odds with security. Tor achieves anonymity by ensuring every user appears identical, creating a digital monoculture where the same vulnerabilities exist across all installations. In cybersecurity, monocultures are generally considered a risk. Security through diversity provides natural segmentation by limiting the impact of an exploit to a smaller segment of users. While such diversity is structurally desirable for security, it inherently compromises user anonymity by making individuals trackable. +Anonymity can often be at odds with security. Tor achieves anonymity by ensuring more users appear [similar](https://support.torproject.org/tor-browser/features/fingerprinting-protections/#:~:text=Tor%20Browser%20is,individual%20users%20effectively.): + +>Tor Browser is specifically engineered to minimize the uniqueness of each user's fingerprint across various metrics. While it is practically impossible to make all Tor Browser users identical, the goal is to reduce the number of distinguishable "buckets" for each metric. This approach makes it harder to track individual users effectively. + + While this is effective at preserving anonymity, it also creates a digital monoculture where the same vulnerabilities exist across many installations. In cybersecurity, monocultures are generally considered a risk. Security through diversity provides natural segmentation by limiting the impact of an exploit to a smaller segment of users. While such diversity is structurally desirable for security, it inherently compromises user anonymity by making individuals trackable. Additionally, Tor Browser is based on Firefox's Extended Support Release builds, which only receives patches for vulnerabilities considered *Critical* and *High* (not *Medium* and *Low*). This means that attackers could (for example):