you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 0 min ago 255 onions tracked
home / news / tor network
24 December 2024 tor network 4 min read

Tor on Android: how far the mobile anonymity push has come, and where it still falls short

There was a time when anonymous browsing on Android meant bolting together Orbot and a patched browser called Orfox, and hoping for the best. Today Tor Browser ships as a native Android app that tracks Firefox's release train. The journey is a useful case study in what "full support" actually means.

From Orfox experiment to official client

For years, mobile Tor users relied on Orfox, a Guardian Project browser built on Firefox, paired with the Orbot proxy app. The Tor Project's first alpha of a dedicated Android Tor Browser arrived in September 2018, with developers explicitly noting it was the first official mobile Tor Browser ever shipped (Tor Project blog). The milestone mattered because mobile is not a niche. In parts of the Global South, a phone is the only way people get online, often under heavy surveillance or censorship. The Tor Project made those users a stated priority rather than an afterthought.

Stability arrives, one release at a time

Stable status landed with Tor Browser 8.5 in May 2019. The team highlighted that there were no proxy bypasses, first-party isolation was enabled against cross-site tracking, and most fingerprinting defenses were working, even though feature gaps versus desktop remained (Tor Project blog). Progress since then has been steady rather than dramatic. Tor Browser 12.0 brought HTTPS-Only mode by default on Android to counter SSL-stripping exit relays, plus a setting to prioritize .onion sites when Onion-Location headers advertise them (Tor Project blog). By October 2024, version 14.0 unified the Android codebase into a monorepo, tackled APK reproducibility, and improved fingerprinting protections enough to re-enable features like picture-in-picture and screenshots without weakening anonymity (Tor Project forum). That last trade-off is worth pausing on. Compatibility used to be the enemy of privacy. Every feature a site can use to probe your device is also a potential fingerprint, so each restoration is a calculated risk the Tor team documents publicly.

Orbot grows up alongside

Orbot remains the other half of the Android story. It started life requiring root for transparent proxying, but the Guardian Project dropped those "transproxy" features back in v15.5, arguing that pushing all device traffic through Tor blindly is a bad idea unless you know every app handles TLS correctly (Guardian Project). The modern approach uses Android's built-in VpnService API to route selected apps through a local Tor port. No exploits, no root, and per-app control. Development continues actively, with Tor now running as its own Linux process inside the current codebase (GitHub).

The VPN-over-Tor pattern, and its caveats

Many users chain commercial VPNs with Tor, either VPN-before-Tor or Tor-before-VPN. On Android this collides with a hard platform rule: only one VpnService connection can run at a time, so Orbot and another VPN cannot both be active simultaneously.
  • One VpnService slot means no true VPN-plus-Orbot stacking on stock Android.
  • Routing arbitrary apps through Tor exposes cleartext traffic at exits if an app skips TLS.
  • Kill-switch behavior depends entirely on the app; a crash can leak traffic outside the tunnel.
The Guardian Project's own guidance cuts to the point: if you want web access and onion services, just use the dedicated browser instead of tunneling everything. Selective routing beats magical whole-device Tor every time.

What still needs work

Honest accounting matters more than cheerleading. Query stripping is disabled on Android, font visibility protections are partially disabled, and the purple ".onion available" address-bar button remains desktop-only. Each gap traces back to platform constraints like Google Play's package size limit, which has already cost x86 devices the Conjure pluggable transport. None of this makes Android Tor Browser unsafe. It makes it different, and users deserve to know exactly where the edges are. For a step-by-step start, see our tor setup guide and follow ongoing coverage in our tor network notes. The trajectory is clear, though. A decade ago, mobile Tor was a community patch job. Now it sits inside the project's main build infrastructure, audited by external firms like Cure53, and released on the same day as desktop. The remaining question is not whether Android gets full parity, but when.

more notes

all news ›