Home / Setup / Verify the download before you run it

nexus-access.bizVerify the download before you run it

The signature check that proves the file came from the Tor Project unmodified, why it is worth the ten minutes, and what a failure means.

3 verified addresses published // 8 access routes // 6 setup steps // no accounts, no forms, nothing collected
Nexus Market onion addresses
All three reach the same market with the same account, balance and orders behind each. Copy one rather than typing it, then confirm it on the login screen before you sign in.
[01]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[02]nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
[03]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion
Read this before signing in Open these in Tor Browser only. When the login screen loads, compare the onion printed on the page against your browser address bar, reading from the end backwards. A copied page reproduces the design perfectly and cannot sit at the real address. If they differ, close the tab.

This is the step everybody skips and the only one that proves the file on your disk is the file the project published. It takes about ten minutes once.

Step
02 of 6
Time
10 min
Needed
Once, not per visit

What it proves

That the download was not modified between the project and your machine. Not by a network operator, not by a compromised mirror, not by anything sitting in the middle. Without the check you are trusting the whole path the file travelled, and that path includes parts nobody can inspect.

The idea in one paragraph

The project signs each release with a private key. The signature file published alongside the download can be checked against their public key. If the file changed by even one byte, the check fails. You do not need to understand the cryptography, you need to run one command and read one line of output.

How it goes

  1. Download both the installer and the small signature file next to it.
  2. Import the Tor Browser developers public key, which the project documents on its verification page.
  3. Run the verify command against the signature and the installer.
  4. Read the output. A good signature says so plainly.

The warning that confuses people

A message saying the key is not certified with a trusted signature is normal and does not mean the check failed. It means you have not personally vouched for the key, which almost nobody has. What matters is the line saying the signature is good.

If it fails

Delete the file and download it again, ideally on a different network. If it fails a second time, something between you and the project is interfering, which is exactly the situation this check exists to catch. Do not run it anyway.

The rest of the setup

STEP 03 // 2 min

Set the security level before your first visit

Tor Browser ships on its most permissive setting. What the three levels change, why Safest is the right default here, and what breaks.

STEP 04 // 3 min

Save the three addresses so you never have to search

Nearly every phishing story starts with somebody looking for an address during an outage. Saving them properly is the cheapest defence there is.

STEP 05 // 10 min

Set up the account once, properly

Username, password, recovery phrase and two factor. Ten minutes at the start that decide what a leak elsewhere costs you later.

Then pick a route in