The signature check that proves the file came from the Tor Project unmodified, why it is worth the ten minutes, and what a failure means.
nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onionnexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onionnexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onionThis is the step everybody skips and the only one that proves the file on your disk is the file the project published. It takes about ten minutes once.
That the download was not modified between the project and your machine. Not by a network operator, not by a compromised mirror, not by anything sitting in the middle. Without the check you are trusting the whole path the file travelled, and that path includes parts nobody can inspect.
The project signs each release with a private key. The signature file published alongside the download can be checked against their public key. If the file changed by even one byte, the check fails. You do not need to understand the cryptography, you need to run one command and read one line of output.
A message saying the key is not certified with a trusted signature is normal and does not mean the check failed. It means you have not personally vouched for the key, which almost nobody has. What matters is the line saying the signature is good.
Delete the file and download it again, ideally on a different network. If it fails a second time, something between you and the project is interfering, which is exactly the situation this check exists to catch. Do not run it anyway.
Tor Browser ships on its most permissive setting. What the three levels change, why Safest is the right default here, and what breaks.
Nearly every phishing story starts with somebody looking for an address during an outage. Saving them properly is the cheapest defence there is.
Username, password, recovery phrase and two factor. Ten minutes at the start that decide what a leak elsewhere costs you later.
The full Windows route to a Nexus onion address, what the operating system keeps behind your back, and the settings worth changing before you start.
DesktopHow to get to a Nexus onion address on a Mac, the Gatekeeper prompts you will meet, and which macOS conveniences work against you here.
DesktopThe Linux route to a Nexus onion address, why the distribution package is usually the wrong choice, and what a sensible setup looks like.