The Tor network in Australia: an honest guide to what it does, what it doesn't, and the law
The Tor network in Australia: an honest guide to what it does, what it doesn't, and the law
Tor has a reputation problem. To some people it's a shadowy criminal tool; to others it's a magic anonymity cloak that fixes everything. Neither is true. Tor is a volunteer-run network that does one specific job well – hiding who is talking to whom – and does several adjacent jobs badly or not at all. This guide covers how it actually works, its real limits, and the Australian legal picture.
This is general information, not legal advice.
Short verdict
Using Tor is legal in Australia. Nothing in Commonwealth law prohibits downloading Tor Browser, browsing with it, running a relay, or hosting an onion service – what matters is what you do through it, which is governed by ordinary criminal law (LegalVision's Australian analysis reaches the same conclusion). Australia's intelligence and policing agencies have shown clear operational interest in the anonymity space, and the law gives them unusually broad powers – but using Tor itself is not an offence, and no Australian law requires you to decrypt or hand over Tor Browser passwords in ordinary circumstances (see the border caveat below).
How Tor actually works
Tor (The Onion Router) routes your traffic through three volunteer relays, wrapping it in layers of encryption – hence "onion" (Tor Project overview):
- Guard (entry) relay – sees your real IP address, but not your destination. Your ISP and Australia's metadata-retention regime see you connected to this relay's IP, and nothing about what you did after.
- Middle relay – sees neither your IP nor your destination. It's a pass-through.
- Exit relay – sees your destination, but not who you are. For plain (non-onion) web traffic, this is the hop that can read unencrypted content.
Each relay knows only its neighbours. No single relay can link you to your destination – the classic weakness is an adversary who watches both ends of the circuit, discussed below.
Onion services (.onion sites) are different: both you and the server stay hidden. The connection is built from both ends meeting in the middle at "rendezvous points", so neither side learns the other's IP, and content is end-to-end encrypted regardless of HTTPS. That's why SecureDrop, human-rights sites, and news organisations like the ABC's tips infrastructure run onion mirrors.
Directory authorities – a handful of hardened servers – maintain the list of relays your client trusts. If an adversary compromised a majority of them, they could poison the network view; that's why they're air-gapped, diversely located, and under heavy scrutiny.
What Tor protects against – and what it doesn't
Tor is good at:
- Hiding your browsing from your ISP, telco, and the two-year metadata retention regime under the Telecommunications (Interception and Access) Act 1979 framework – your telco sees a TLS connection to one relay IP.
- Defeating website IP tracking, ad-network profiling by IP, and geo-blocks on the way in.
- Anonymising both sides of an onion-service connection.
Tor is not good at – and you should know the honest list:
- Malicious exits. Anything unencrypted leaving an exit relay is readable by that relay's operator. There is a documented history: in 2020 the Tor Project issued a security advisory about exit relays running sslstrip, and researchers tracked thousands of malicious exit nodes intercepting traffic (largely targeting cryptocurrency users) over many months (The Record's coverage). Rule: never log into a non-HTTPS site over Tor; assume HTTP traffic is being read.
- Traffic correlation. If one party (a state actor, or a well-resourced adversary) watches the connection between you and your guard relay and between the destination and its exit, timing and volume patterns can correlate the two ends. This is a global-passive-adversary attack; Australia's Five Eyes alignment means sophisticated local agencies sit closer to that capability than most countries' police forces.
- Exit-node monitoring applies only to non-onion traffic leaving exits. Onion services bypass exits entirely.
- Browser fingerprinting. Tor Browser standardises its fingerprint aggressively, but a 2022 USENIX study showed website fingerprinting attacks on Tor work in the real world under lab-to-field conditions, and a 2026 arXiv "reality check" paper found real-world effectiveness remains contested. The honest statement: WF attacks are a research-grade threat, not something your ISP runs casually – but they're exactly what a serious adversary funds.
- Your own behaviour. Logging into your real-name accounts over Tor de-anonymises you. Tor protects the pipe, not the habits.
- Compromise of the endpoint. A backdoored device defeats Tor completely. Device hardening (see our degoogled phone guide) is a prerequisite, not an alternative.
Tor Browser vs Tails vs Whonix
| Tor Browser | Tails | Whonix | |
|---|---|---|---|
| What it is | Hardened Firefox + Tor | Amnesic live OS (USB boot) | Two VMs (Tor gateway + workstation) |
| Routes all traffic? | Browser only | Yes, everything | Yes, everything |
| Leaves traces on the machine? | Yes | No (amnesic by design) | On the host, unless host is live-booted |
| Best for | Everyday anonymity | High-risk sessions on borrowed/dedicated hardware | Persistent anonymity workstations (pair with Qubes) |
Tor Project's own comparison and the Whonix comparison wiki draw the same boundaries. Practical guidance: Tor Browser for most people; Tails if the stakes are high and you can boot dedicated hardware; Whonix under Qubes OS for persistent high-security work. All three get updates – run current versions.
Bridges and obfs4: when Tor is blocked
An ISP or state firewall can block known relay IPs. Bridges are unlisted entry points: obfs4 bridges disguise Tor traffic as random TLS-ish noise, and Snowflake tunnels Tor through volunteer WebRTC proxies. If Tor won't connect, Tor Browser's built-in connection assistant offers both (Tor Project: connecting from censored regions). In Australia, no ISP currently blocks Tor – but two trends make this worth knowing: libraries, schools and workplaces routinely block it via DNS/hostname filtering, and any future expansion of content-blocking schemes could put circumvention tools in scope. Requesting obfs4 bridges via email (from a risingsun or Gmail address through bridges.torproject.org) works even if the main site is filtered.
Australian relay numbers
Australia is a small player in relay terms. As of publication, Tor's directory data shows 51 Australian relays – 11 guards, 37 middles, and only 3 exits – contributing about 2.36 Gbit/s of bandwidth and roughly 0.07% of global consensus weight (1AEO Tor Metrics, live data refreshed from Onionoo). Global network context is on Tor Metrics (~7,000–8,000 relays worldwide). Two implications: Australia's exits are few, so most of your exit traffic will terminate overseas; and anyone running an Australian guard relay slightly improves national coverage. Running a middle relay is lawful and low-risk; running an exit in Australia carries legal exposure (abuse reports, and in the worst case liability for content transiting your connection) – read the Tor relay operator legal FAQ first and get informed consent from whoever owns the connection.
Australian law-enforcement interest in Tor
Three facts worth knowing, none of which make using Tor illegal:
- Identify and Disrupt powers. The Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 gave the AFP and ACIC network-access and account-takeover warrants – the ability to covertly access or disrupt online accounts and networks, including via anonymity services, with a court warrant and limited oversight reporting. These powers were explicitly framed around dark-web and anonymous-enabled crime.
- Onion services are squarely on the agenda. A 2021 PJCIS submission on Tor's underworld, onion services and child exploitation shows agencies treat onion infrastructure as an investigation target, not a legal target.
- The platform-ownership pattern. Operation Trojan Shield (2021) saw the FBI-designed ANOM encrypted platform run covertly with AFP participation, yielding thousands of arrests (AFP media release shows the same AFP operational posture in later money-laundering disruptions). The lesson for privacy readers: the strongest operations against anonymity networks rarely break the crypto – they own the platform, an informant, or the endpoint.
None of this changes the lawfulness of Tor itself. It changes the risk calculus for specific high-stakes uses: a determined AFP/ASIO investigation into a specific person is a different threat class than ISP tracking or ad profiling, and Tor alone is not engineered to defeat that class.
Practical guidance, by threat model
- Ordinary privacy (ad/tracking resistance, ISP-blind browsing): Tor Browser, keep it updated, don't log into real-name accounts, use HTTPS everywhere. That's it.
- Journalists and whistleblowers: Tor Browser for research; SecureDrop or Signal for sources; consider Tails on dedicated hardware for anything sensitive. Never use work devices. Remember the source is usually the weaker link – teach sources to use SecureDrop's Tor access, not just to email you.
- Domestic violence survivors: Tor helps with browsing anonymity but won't hide you from a stalker with access to your devices or accounts. Prioritise device hygiene first – see our stalker-OSINT lockdown guide – and use DV-specific services (1800RESPECT) which have specialist tech-safety staff.
- Running a relay: middle relays are safe and helpful; exits need real planning (dedicated IP, abuse handling, landlord consent).
- Borders: Australia's border-search powers apply at the border – a powered-off device can still be imaged or searched with limited cause under the Customs Act regime (see our border device search guide). Travelling with Tails media is legal, but assume device inspection if it matters.
Bottom line
Tor does one job – unlinking you from your traffic – and does it with a genuinely strong design that has survived twenty years of public attack. It does not protect you from malicious exits on plain HTTP, from a global adversary watching both ends, from fingerprinting research attacks, or from yourself. It is legal in Australia; the surveillance framework around it is aggressive; and the realistic failure mode, based on every major Australian operation to date, is platform or endpoint compromise rather than a broken network. Match the tool to the threat, layer it with device hardening, and don't confuse "Tor makes me anonymous" with "Tor makes me safe".
Disclosure: links to /blog/ and /product/ pages are our own site. Sources were live-verified at publication. This article is general information, not legal advice.