Tor Browser Security Settings Explained
Tor Browser Security Settings are designed to help users balance privacy, security, and website usability while browsing through the Tor network. Tor Browser already includes strong privacy protections by default, but its security levels allow users to reduce exposure to risky browser features such as JavaScript, certain fonts, media playback, icons, mathematical symbols, and dynamic web components.
These settings are especially important when visiting unknown websites, onion services, dark web resources, investigative sources, or any page where the user faces a higher risk of tracking, exploitation, malware, phishing, or deanonymization.
Tor Browser is not simply a normal browser with a proxy added. It is a carefully modified browser built to route traffic through the Tor network, resist tracking, reduce fingerprinting, isolate browsing sessions, and protect users against surveillance and censorship. Security settings are one part of that larger protection model.
What Tor Browser security settings do
Tor Browser security settings control how much functionality websites are allowed to use inside the browser. The main idea is simple: the more powerful a website’s code is, the more opportunities it may have to attack the browser, track the user, or exploit a vulnerability.
Modern websites use many active features. JavaScript, custom fonts, embedded media, icons, mathematical rendering, SVG graphics, browser APIs, and other technologies can make websites more useful and interactive. However, those same features can also increase the attack surface.
Tor Browser’s security levels allow users to reduce that attack surface. Higher security levels disable or restrict certain web features. This can make browsing safer, but it can also make some websites look broken, incomplete, or less interactive.
The three main security levels are:
- Standard
- Safer
- Safest
Each level represents a different balance between convenience and protection.
Why security levels matter
Tor protects the network path between the user and the destination. It helps hide the user’s real IP address from websites and helps prevent local observers from easily seeing which sites the user visits. However, network privacy is only one part of online safety.
A website can still attempt to identify or attack a user through browser features. For example, a malicious website may try to exploit JavaScript, collect fingerprinting information, trigger unsafe downloads, abuse media features, or trick users into revealing personal information.
Security levels matter because they reduce the number of risky features available to websites. They do not make the user invincible, but they make certain attacks harder.
Standard security level
Standard is the default Tor Browser security level.
At this level, all Tor Browser and website features are enabled. JavaScript is allowed, media works normally, fonts and images are generally available, and most websites behave as expected.
This level provides the best usability. It is suitable for ordinary browsing, reading news, using common websites, accessing basic services, and visiting trusted pages where functionality matters.
However, Standard also exposes the browser to the largest number of web features. For users with a higher threat model, this may not be enough.
Advantages of Standard
Standard offers the highest compatibility with modern websites. Pages that depend on JavaScript, login systems, forms, menus, media players, dashboards, and interactive tools usually work better at this level.
It is also the easiest level for new users because it produces fewer broken pages. A person who is learning how Tor Browser works may find Standard more comfortable at first.
Limitations of Standard
The main limitation of Standard is that JavaScript remains enabled. This means more browser features are exposed to websites, which increases the attack surface compared with higher security levels.
Standard is not the best option for unknown, suspicious, or high-risk websites. It is convenient, but convenience is not the same as maximum protection.
Safer security level
Safer increases protection by disabling website features that are often considered risky. This level may cause some websites to lose functionality, but it remains usable for many browsing tasks.
At this level, JavaScript is disabled on non-HTTPS websites. Some fonts and mathematical symbols are disabled, and HTML5 audio and video become click-to-play.
Safer is a strong middle ground. It reduces exposure to some common browser risks without making the web as limited as the highest setting.
What Safer changes
Safer changes how Tor Browser handles active and potentially risky web features.
JavaScript is disabled on non-HTTPS websites. Some fonts and mathematical symbols may not display normally. HTML5 audio and video require user interaction before playing. Some interactive features may stop working, especially on older websites or poorly configured pages.
This does not mean the browser is broken. It means Tor Browser is intentionally limiting features that may increase risk.
When to use Safer
Safer is appropriate when browsing unknown websites, visiting onion services, researching sensitive topics, avoiding unnecessary active content, or reducing exposure while keeping moderate usability.
It is also a reasonable default for users who want stronger protection than Standard but do not want to break most websites.
For many privacy-conscious users, Safer is the most practical everyday setting.
Advantages of Safer
Safer provides better protection than Standard while still allowing many websites to function. It reduces risk from JavaScript on insecure HTTP pages, limits some rendering surfaces, and gives users a stronger security posture without moving to a fully restrictive mode.
This level is especially useful for people who regularly visit unfamiliar pages, hidden web directories, onion services, or research resources.
Limitations of Safer
Some websites may not work correctly at this level. Login systems, search boxes, forms, navigation menus, embedded media, or interactive tools may break on certain pages.
Safer also does not disable JavaScript everywhere. Users who need the strongest protection should consider Safest instead.
Safest security level
Safest is the most restrictive Tor Browser security level.
At this level, Tor Browser only allows website features required for static sites and basic services. JavaScript is disabled by default on all websites. Some fonts, icons, mathematical symbols, and images are disabled. HTML5 audio and video are click-to-play.
Safest provides the strongest built-in protection against web-based attacks, but it also causes the most compatibility problems. Many modern websites depend heavily on JavaScript and may not function properly at this level.
What Safest changes
Safest disables JavaScript by default on all websites. It also restricts several visual and media features. Some fonts, icons, mathematical symbols, images, scripts, audio, and video elements may be blocked, limited, or changed.
Many dynamic web applications may fail to load. Pages that rely heavily on scripts may appear empty, incomplete, or unusable.
This is expected behavior. Safest is designed for protection, not maximum convenience.
When to use Safest
Safest is appropriate for high-risk browsing, unknown onion services, sensitive research, investigative work, hostile environments, or situations where security matters more than convenience.
It is also useful when the user wants to read mostly static content and avoid active scripts as much as possible.
For users visiting suspicious pages or handling sensitive research, Safest is the strongest built-in option available in Tor Browser.
Advantages of Safest
Safest greatly reduces JavaScript-based attack surface. It limits many active and dynamic web features and encourages safer, low-interaction browsing.
This level is especially useful when visiting untrusted onion services, unknown directories, suspicious websites, or pages that do not require login or interactivity.
Limitations of Safest
Many websites will break at this level. Some pages may appear incomplete. Login systems may fail. Search tools, forms, menus, media players, comment sections, and interactive features may stop working.
Safest is powerful, but it is not always comfortable. It is best used when the user’s threat model justifies the loss of convenience.
Comparing the three security levels
Tor Browser offers three security levels. Each one changes the balance between website compatibility and protection against risky web features.
Standard
Standard provides the highest compatibility. JavaScript is enabled by default, and most modern websites work normally. This level is useful for normal browsing, trusted websites, and pages that require full functionality.
Standard is the best option when usability matters more than reducing every possible browser feature. It is also the easiest level for new users, because websites are less likely to break.
Safer
Safer provides stronger protection while keeping many websites usable. JavaScript is disabled on non-HTTPS websites, some fonts are restricted, and audio or video may require user interaction before playing.
This level is recommended for unknown websites, onion services, privacy-conscious browsing, and general research. It is often the best balance between safety and usability.
Safest
Safest provides the strongest built-in protection. JavaScript is disabled by default on all websites, and several active web features are restricted.
Many modern websites may break at this level, but it is the best option for high-risk browsing, suspicious websites, sensitive research, and untrusted onion services.
JavaScript and Tor Browser security
JavaScript is one of the most important topics in Tor Browser security. It is a programming language used by websites to create interactive pages, login forms, menus, media players, animations, dashboards, and dynamic content.
However, JavaScript can also increase risk. It can expose more browser behavior to websites, provide more opportunities for fingerprinting, and create a larger surface for exploitation if a browser vulnerability exists.
This is why Tor Browser security levels treat JavaScript differently depending on the selected level.
In Standard, JavaScript is allowed.
In Safer, JavaScript is disabled on non-HTTPS sites.
In Safest, JavaScript is disabled by default on all sites.
Disabling JavaScript can greatly improve safety on unknown websites, but it can also break many modern pages. Users should understand this tradeoff before assuming that a broken website means Tor Browser is malfunctioning.
NoScript in Tor Browser
Tor Browser includes NoScript, an add-on used to control JavaScript and other active content. NoScript can give users more control over which scripts run on which websites.
However, users should be careful when changing NoScript settings manually. Tor Browser is designed so many users share similar browser behavior. Excessive customization may make a user stand out or cause unexpected privacy issues.
For most users, changing the main Tor Browser security level is safer and simpler than manually creating complicated NoScript rules.
HTTPS-Only Mode
Tor Browser includes HTTPS-Only Mode, which attempts to force websites to use encrypted HTTPS connections whenever possible.
HTTPS protects the connection between the browser and the website against tampering and eavesdropping. This is especially important when logging into accounts, submitting forms, reading sensitive pages, or copying payment-related information.
If a website does not support HTTPS, Tor Browser may show a warning before allowing the user to continue to the HTTP version. Continuing to an unencrypted HTTP site increases risk, especially when submitting information or copying sensitive data.
HTTPS does not replace Tor. Tor protects the network path and helps hide the user’s IP address. HTTPS protects the content of the connection between the browser and the destination when supported. The two technologies solve different problems and work best together.
New Identity and New Circuit
Tor Browser includes identity and circuit controls that are often confused with security levels.
New Circuit for this Site reloads the current site using a new Tor circuit. This can help when a website is not loading properly, when an exit relay is blocked, or when the user wants a fresh route for that specific site. It does not clear all private information or fully separate the user’s activity.
New Identity is stronger. It closes tabs, clears session data, and starts a new browsing identity. This is useful when the user wants to separate one activity from another.
These tools are important, but they are not the same as changing the security level. Security levels control browser features. Identity controls manage session separation and Tor circuit behavior.
Add-ons and extensions
Users should avoid installing extra add-ons or browser extensions in Tor Browser.
Even if an extension is popular in Firefox or Chrome, it may harm Tor Browser’s privacy model. Extensions can change browser behavior, create a unique fingerprint, bypass protections, access browsing data, or introduce new vulnerabilities.
Tor Browser is designed so users look as similar as possible to other Tor Browser users. Adding extensions can make a user more unique, which weakens anonymity.
This includes ad blockers, custom themes, download managers, script tools, password helpers, and privacy extensions that are not included by default. In Tor Browser, more extensions do not always mean more privacy.
Browser fingerprinting
Browser fingerprinting is a tracking technique that identifies users based on their browser characteristics. Websites may examine screen size, fonts, language, time zone, graphics behavior, extensions, media support, and many other signals.
Tor Browser is built to resist fingerprinting by making users appear more similar to each other. This is one reason users should avoid unnecessary customization.
Security settings can also affect fingerprinting. Higher security levels disable features that may expose additional signals, but extreme or unusual manual customization can make a browser stand out.
The safest approach is to use Tor Browser as designed, keep it updated, avoid extra extensions, and choose the security level that matches the user’s risk.
Downloads and external files
Tor Browser security settings do not make downloaded files automatically safe.
Documents, archives, scripts, images, PDFs, and applications from unknown websites may contain malware or tracking mechanisms. Opening downloaded files outside Tor Browser can expose the user’s real IP address or system information, especially if the file connects to the internet.
Users should be cautious with all downloads, especially from unknown onion services or dark web pages. For sensitive research, files should be handled in isolated environments and never opened carelessly on a personal system.
Logging into accounts
Tor Browser can hide the user’s IP address from a website, but it cannot hide information the user voluntarily provides.
If a user logs into a personal account, the website may not know the user’s real location, but it knows the account identity. If the user enters a real name, email address, phone number, shipping address, or payment information, Tor cannot make that information anonymous.
Security settings reduce technical risk. They do not replace careful behavior.
Tor Browser and other applications
Tor Browser only protects traffic that goes through Tor Browser. It does not automatically protect every application on the computer.
Other browsers, messaging apps, torrent clients, game launchers, cloud sync tools, and system services may connect directly to the internet unless separately configured. Users who need all traffic routed through Tor should consider dedicated systems designed for that purpose, such as privacy-focused live operating systems.
This distinction is important. Opening Tor Browser does not turn the entire computer into a Tor-protected device.
Tor Browser and VPNs
Some users believe that adding a VPN to Tor Browser always improves privacy. This is not necessarily true.
Using a VPN with Tor can create new trust and configuration problems. If configured incorrectly, it may reduce anonymity, create a misleading sense of protection, or make troubleshooting harder. Advanced users may have specific reasons for combining Tor and VPNs, but ordinary users should not assume that “Tor plus VPN” is automatically safer.
For most users, the better approach is to use Tor Browser correctly, keep it updated, avoid unsafe behavior, and choose the appropriate security level.
Recommended settings by threat model
Different users have different security needs. The best security level depends on what the user is doing, what kind of websites they are visiting, and how serious the consequences would be if something went wrong.
Low-risk browsing
For ordinary browsing, reading public websites, and accessing trusted pages, Standard may be acceptable. It provides the best compatibility while still using Tor Browser’s default privacy protections.
This level is useful when the user wants websites to work normally and is not visiting unknown or suspicious pages.
Moderate-risk browsing
For users visiting unknown websites, using onion services, researching sensitive subjects, or wanting stronger protection without breaking most pages, Safer is often a strong choice.
This level provides a practical balance. It reduces exposure to risky features while keeping many websites usable.
High-risk browsing
For users facing serious risk, visiting untrusted onion services, investigating suspicious pages, or operating in hostile environments, Safest is the most appropriate built-in security level.
This level may break many websites, but it provides the strongest protection available through Tor Browser’s normal security settings.
Users should remember that a higher setting is not a substitute for good operational security. It must be combined with careful behavior.
Practical recommendations
A strong practical setup for many users is to use Tor Browser only from the official Tor Project source, keep it updated, avoid installing extra extensions, and choose the security level according to the risk of the browsing session.
For general privacy-conscious browsing, Safer is often a good starting point. For unknown or high-risk onion services, Safest is usually more appropriate. For trusted websites that require full functionality, Standard may be more practical.
Users should also avoid opening downloaded files outside a safe environment, avoid entering personal information on untrusted websites, use HTTPS whenever possible, use New Identity when separating activities, and remember that Tor Browser does not automatically protect other applications on the device.
For directory-based research, users may consult organized resources such as In The Hidden Wiki to learn about onion links, tor links, privacy tools, and hidden web navigation. However, every destination should still be verified independently, and users should not assume that any directory can guarantee safety.
Common misconceptions
“Safest means completely anonymous”
This is false. Safest reduces browser attack surface, but it does not guarantee complete anonymity. User behavior, device security, account logins, downloads, and personal information still matter.
“Standard is unsafe”
Standard is not automatically unsafe. It still uses Tor Browser’s privacy protections, but it leaves more web features enabled. It is more usable but less restrictive.
“JavaScript must always be disabled”
Not always. Disabling JavaScript improves security in many situations, but it can break websites. The right choice depends on the user’s threat model.
“More extensions mean more privacy”
This is false. Extra extensions can make a user more fingerprintable or introduce privacy risks. Tor Browser should generally be used with its default extensions only.
“A VPN always improves Tor”
This is false. A VPN can complicate the trust model and may reduce privacy if configured poorly. Users should not combine tools without understanding the consequences.
“Security settings protect against every danger”
This is false. Security settings reduce technical attack surface. They do not protect against scams, phishing, illegal content, malware downloads, bad judgment, or voluntary self-identification.
Security settings and usability tradeoffs
The central idea behind Tor Browser security settings is tradeoff.
The more features a website can use, the more convenient it becomes. The fewer features it can use, the smaller the attack surface becomes.
There is no universal perfect setting. A high-risk user may accept broken websites in exchange for stronger protection. A casual user may accept more functionality because the risk is lower. A researcher may switch between Safer and Safest depending on the website being visited.
Good security is not about choosing the most extreme option at all times. It is about matching the setting to the risk.
Conclusion
Tor Browser security settings give users control over the balance between protection and usability. Standard offers the most compatibility, Safer provides a practical middle ground, and Safest gives the strongest built-in protection by disabling many active web features.
These settings are most effective when users understand what they do and what they do not do. They can reduce exposure to risky website features, limit JavaScript-based attacks, and improve safety on unknown pages. However, they cannot prevent every form of tracking, phishing, malware, account identification, unsafe download, or user error.
The best approach is to use Tor Browser as designed: keep it updated, avoid unnecessary customization, choose the right security level, verify important links, treat downloads carefully, and never confuse privacy tools with absolute protection.
Tor Browser is a powerful tool, but its strength depends on both technical design and user discipline. Security settings are one of the simplest ways to make that tool stronger.
See also
- Tor Browser
- Tor
- Onion Services
- Tor Links
- Onion Links
- Dark Web
- Online Privacy
- Browser Fingerprinting
- NoScript
- HTTPS
- Censorship Resistance
- Cybersecurity
References
- Tor Project Support. Security Levels in Tor Browser.
- Tor Project Support. Tor Browser best practices.
- Tor Project Support. JavaScript and NoScript in Tor Browser.
- Tor Project Support. HTTPS-Only Mode in Tor Browser.
- Tor Project Support. Managing identities in Tor Browser.
- Tor Project Support. Using Tor Browser with a VPN.
- Tor Browser Manual. Privacy, security, and onion services.