Everything You Need to Know About Tor’s Messenger System

For several years a number of governments around the world have worked tirelessly to monitor or somehow regulate the way in which their citizens interact on the Internet. Due to services like Tor and virtual private networks (VPNs), this task has been getting difficult and will continue to do so for the foreseeable future. As long as there are people willing to make utilities that help people become anonymous on the Web, there will always be a way to work around regulations and blocks set up by centralized administrations.

Onion routing (through Tor) has been one of the most popular ways of accomplishing this. At the end of October developers released a new service that runs on top of Tor that allows for anonymous chat/messaging. Here’s a condensed run-down on what you should know about this service.

How It Works

If you’re unsure of how Tor works, I’ve already written a piece here on MTE that explains it. On top of Tor, the messenger system will work by connecting you through the OR protocol first, then adding your chat service of choice’s protocol as another layer on top of it. You can connect to Facebook, Jabber, IRC, Google Talk, Twitter, Yahoo, and many other services that allow for private conversations using this method. The goal of Tor Messenger is to allow conversations between people in countries where such a protocol is blocked for various reasons. You will always be able to find a Tor relay in a country where these services are not blocked, allowing you to both chat and hide your location with end-to-end encryption.

Can’t You Just Run Tor Through Your Favorite Application?

tormessenger-encryptedchat

Here’s where we get to the crux of Tor Messenger and what makes it special compared to just configuring your application to run through Tor and using it to chat instead. Yes, technically you can configure onion routing through your browser, Yahoo! Messenger, or whatever it is you use to chat. But while that may give you peace of mind knowing you’re appearing from another country, it still allows exchanges and relays with your encryption keys to view the messages sent through their servers. The keys work only until the message is decrypted by the last server before reaching its destination.

With Tor Messenger you have an added layer of functionality. Instead of having a traditional cryptography model, you will be using “Off-the-Record” (OTR) messaging. The way OTR works is that you and your friend on the other side decide on a secret key to use and input it directly into the messenger interface. Your messages will be decoded not by the server sending them but by the program running on your computer. This leaves every OR relay (even the one on the tail end of the transmission) completely clueless about what you’ve sent or received. By doing this you eliminate the possibility that your traffic will somehow be sniffed out by someone malicious. Instead, only you and the person on the other end will see the message itself rather than the gibberish that is normally transmitted through the web.

Can’t Someone See The Key Before It’s Used, Though?

tormessenger-key

Of course, if you exchange the key through the same messaging system you intend to use it in, you’ve technically made all this effort for nothing. Someone can just easily grab your key and decode the entire conversation anyway. My suggestion is to make a phone call, send an SMS (less safe), or meet in person to exchange the key with the person you intend to speak with. Use a different key for each person you speak with to eliminate every possibility of sabotage if the conversation is extremely sensitive.

As long as you adopt these good practices, you’ll be able to keep your head underwater if privacy is that important to you in those particular moments.

What do you think? Is Tor Messenger taking paranoia a little too far, or is it providing an essential service? Tell us in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

The Greenland shark grows about one centimetre a year, does not reach sexual maturity until around age 150, and a specimen carbon-dated by Danish researchers in 2016 was estimated to be at least 272 years old, meaning it was already swimming the North Atlantic when Mozart was composing symphonies.
When Apple shipped iOS 12 in June 2018, a small feature called Screen Time slipped onto every iPhone with a counter nobody had quite prepared for — a tally of pickups — and within a day Tim Cook was telling CNN the number of times he picked up his own phone was simply too many
When NASA lost contact with the IMAGE satellite in 2005, an amateur radio operator in Canada named Scott Tilley picked up its signal in January 2018 while hunting for a classified spy satellite, and the spacecraft turned out to be still spinning, still powered, and still trying to phone home after 13 years of silence.
The original iPhone Steve Jobs unveiled in January 2007 could not record video, could not copy and paste text, could not run a single third-party app, and could only reach the internet over 2G — and Jobs spent ninety minutes on stage at Macworld arguing, one missing feature at a time, that every absence was actually a design decision.
In 1965, Joe Sutter’s Boeing team began shaping the 747 around a future they thought would belong to supersonic jets, lifting the cockpit onto a hump so the nose could open for cargo once the giant subsonic passenger plane had outlived its brief moment
Apple’s original 1984 Macintosh keyboard had no arrow keys, no function keys, and no numeric pad because Steve Jobs wanted users to reach for the mouse first. Then Apple quietly sold the missing keys as an accessory.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
Masahiro Hara and Denso engineers built the QR code in 1994 to help Toyota suppliers scan car parts from any angle, then kept the patent open until phone cameras and a 2020 pandemic turned the factory square into a daily ritual on restaurant tables