Tor Browser Bundle 6.0


The Tor Browser Bundle is an easy-to-use portable package of Tor, Vidalia, Torbutton, and a Firefox fork preconfigured to work together out of the box. It contains a modified copy of Firefox that aims to resolve the privacy and security issues in mainline version.

Tor was originally designed, implemented, and deployed as a third-generation onion-routing project of the U.S. Naval Research Laboratory. It was originally developed with the U.S. Navy in mind, for the primary purpose of protecting government communications. Today, it is used every day for a wide variety of purposes by normal people, the military, journalists, law-enforcement officers, activists, and many others.

What's New Version 6.0

  • Update Firefox to 45.1.1esr
  • Update OpenSSL to 1.0.1t
  • Update Torbutton to
    • Make Torbutton compatible with Firefox ESR 45
    • Pref to hide 'Sign in to Sync' button in hamburger menu
    • Hide unusable items from help menu
    • Allow users to more easily set a non-tor SSH proxy
    • Provide shortcuts for New Identity and New Circuit
    • Translation updates
    • Code clean-up
  • Update Tor Launcher to
    • Do not store data in the application bundle
    • Tor Browser is not starting on OS X if put into /Applications
    • Setup wizard UI flow improvements
    • Translation updates
  • Update HTTPS-Everywhere to 5.1.9
  • Update meek to 0.22 (tag 0.22-18371-3)
    • Symlinks are incompatible with Gatekeeper signing
    • Mac OS: meek-http-helper profile not updated
  • Rebase Tor Browser patches to ESR 45
  • Fix broken updater on Linux
  • The update.xml hash should get checked during update
  • Disable SHA1 certificate support
  • Disable libmdns support for desktop and mobile
  • Disable additional welcome URL shown on first start
  • Exempt our extensions from signing requirement
  • Disable MediaDevices.enumerateDevices
  • Disable HTTP Alternative-Services
  • Disable Mozilla's tracking protection
  • Disable performance-based WebGL fingerprinting option
  • Disable Selfsupport and Unified Telemetry
  • Disable Network Tickler
  • Remove DNS lookup in lockfile code
  • Disable dom.push preferences
  • Remove the JS-based Flash VM (Shumway)
  • Disable MozTCPSocket explicitly
  • Place Canvas MediaStream behind site permission
  • Verify cache isolation for Request and Fetch APIs
  • Fix OCSP and favicon isolation for ESR 45
  • Disable for now
  • Exempt the meek extension from the signing requirement as well
  • Don't copy Torbutton, TorLauncher, etc. into meek profile
  • Test importScripts() for cache and network isolation
  • Hide pocket menu items when Pocket is disabled
  • Fix circuit isolation issues on Page Info dialog
  • Tor Browser should not fall back to Bing as its search engine
  • Use our search plugins in localized builds
  • Zip our language packs deterministically
  • Fix first-party isolation for blobs URLs in Workers
  • Disable or audit Reader View
  • Remove Pocket
  • Tor Browser reports "InvalidStateError" in browser console
  • Disable monitoring the connected state of Tor Browser users
  • Don't show error after add-on directory clean-up
  • Disable the option of logging TLS/SSL key material
  • SVGs should not show up on Page Info dialog when disabled
  • Spoof screen.orientation values
  • Disable Heartbeat prompts
  • Use English-only label intags
  • Investigate server logging in esr45-based Tor Browser
  • Add unit tests for keyboard fingerprinting defenses
  • Regression test to ensure CacheStorage is disabled
  • Add automated tests for updater cert pinning
  • Add test cases for favicon isolation
  • Remove some FTE bridges
  • Support OS X Gatekeeper
  • Tor Browser should not store data in the application bundle
  • HTTPS-E is missing after update
  • meek-http-helper profile not updated
  • Upgrade is not smooth (requires another restart)
Build System
  • Update toolchain for Firefox 45 ESR
  • Switch to Debian Wheezy guest VMs