Tor Browser, set up properly
The right build from torproject.org, a clean first run, and bridges for when the network itself is the problem.
awazonip66usn4oq6vn5b3fqjyjjvavzu3ototnjbmi2wg6bocfc7aqd.onionawazonwilo4vky6obkwrkv62vx24tnf5323pts6d7gohdoj4pjt646qd.onionawazonvewzuve3emyxtz2z7ko6bjv6m6qieioi2tuvbgwiomn6vyryyd.onionPaste, don't retype. One wrong character out of 56 opens someone else's site.
Get the build from torproject.org
Tor Browser comes from one place: torproject.org. Desktop builds and an Android build, both from the project's own download page. The build is signed, which means the project publishes a signature next to it and a mismatch is visible to anyone who bothers. Most do not bother, and that is fine, the point is the option exists. The job it serves is opening the awazon market tor address with the browser doing its part end to end.
What the build should not come from: software catalogs, torrent sites, "updated versions" on random forums, an app store listing that nobody from the Tor project maintains. A Tor Browser from a torrent is a Tor Browser with a stranger's hands on it in between the project and the disk. For onion browsing that gap is where things go sideways, because the browser is the only layer standing between the clearnet and the circuit.
If a page offers Tor Browser with a download counter and a five star rating, close the tab. The counter and the stars are not from the Tor project.
The first run
First launch opens a welcome window. It explains what Tor is, in the tone of a museum placard, and it asks one question: connect through the normal network or through a bridge. If the network is open, the normal path. Hit Connect and leave the window alone while it works.
The first circuit is the slowest one the browser will ever build. It has to hand-shake with three relays in sequence, and a fresh install has no cached hints about which relays are reachable. Pages that later open in a couple of seconds take ten or more on the first pass. That is not a fault, that is the circuit being built. The second load of the same page is the real baseline, and if the second load is still a crawl, the network is the subject of the next section.
Security levels
Under the onion icon in the toolbar there is a shield, and behind the shield are three levels: Standard, Safer, Safest.
- Standard is enough for the market. The storefront loads, the queue loads, the captcha renders. Nothing about the market's front end needs the extra restraints.
- Safer strips some scripts and some media. The market survives it, but the storefront slows down and some product images may not render at all. If a page looks broken under Safer, that is the level doing its job, not the mirror.
- Safest cuts more, including parts of the rendering that an image-heavy storefront relies on. Categories may list, product cards may not. Under Safest the market is a skeleton with a name.
Before logging in, use the shield menu and pick New circuit for this site. A fresh circuit means the login does not share an exit path with whatever the browser fetched on the way in. It takes a few seconds. It is the difference between "the login went out on its own circuit" and "the login went out on the same path as the queue spinner".
Bridges: when the network is the problem
Symptom set: Tor Browser connects, the circuit builds, but every onion page takes a long time or dies mid-load, and the clearnet in the same browser is fine. Or the browser cannot connect at all, with a network error on the welcome screen. In both cases the market is not the problem. The path between the machine and the Tor network is.
Some providers block or throttle Tor by filtering the public relay list. The relays are public, the list is public, and a provider that wants to make Tor slow can read the list and act on it. Bridges are the answer: relays that are not in the public list. A bridge is a relay that answers only when told its address, so a filter that reads the public list does not see it.
To use one: the welcome window has a New Transport button (under the connect option). It opens the bridge settings. A bridge line is a string like obfs4 address:port id cert=i:xxxx iat-mode=0, and it is pasted into the field. Free bridge lists are published by the Tor project; the exact source of a bridge line matters less than the fact that it works. If one bridge line fails, try the next one. A working bridge is the one where the circuit actually builds and pages actually load, and that test takes thirty seconds, not a theory.
With a bridge in place, the whole opening sequence runs again from the top: paste the address, queue, captcha, storefront. If the mirror still refuses to load after the network is proven healthy, the failure is on the mirror side, and the not-loading page walks through that case.