The Tor network: guards, middles and what each position can see
Tor is not one organisation and not one machine. It is a large number of relays run by unrelated people, and a circuit is an arrangement of strangers who each see a different part of the same connection.
Nobody in the network holds the whole path
A relay is a computer somebody else set up, paid for and placed somewhere you did not choose. Different owners, different countries, different reasons for running one. There is no head office keeping a complete log of your circuit, because no position in the design would produce one.
That changes what a question like "can Tor see me" even means. There is no Tor to ask. There is a first relay, a middle, and then either an exit or a meeting point inside the network, and each is a separate party with a separate and narrow view. This section takes those positions one at a time.
Each position is handed a different slice
- The first relay, your guard
- Your real network address, and that the traffic is Tor. Not the destination, not the content.
- A middle relay
- One relay before it and one relay after it. Not you, not the destination, nothing readable.
- An exit relay
- The destination host, and any content that is not separately encrypted. Ordinary websites only. Never your address.
- A directory position
- That some circuit asked for a particular lookup value at a particular time. Not who asked.
- A meeting point for an onion connection
- Two circuits joined together, and how much passes between them. Neither end, and not the address.
Read down that list and the shape of the design is visible. The position that knows who you are does not know where you are going. The position that knows where you are going does not know who you are. Under ordinary running, nothing puts both halves in the same pair of hands.
This site does not offer that as a promise. It is a description of what each machine is handed, which is a smaller and more useful claim. The failure cases belong to research literature rather than a catalogue page, and writing them up as a recipe is not what this section is for.
An onion address is a different shape of connection
When you fetch an ordinary website over Tor, the traffic has to leave the network somewhere, because the server at the far end is not part of it. The relay it leaves through is the exit, and the exit is the position most people picture when they worry about Tor. It is the one with a view of where you went.
An address ending in .onion is not fetched that way. There is no exit in the path at all. Both sides build circuits into the network and meet at an agreed relay, so the connection terminates inside rather than being handed back out to the ordinary internet. No position on the path strips the encryption and passes the contents onward. The card on exits and onion addresses sets this out properly, with a table, and the other cards here point at it rather than repeating it.
The result is a correction that runs both ways. A reader who assumes an exit operator could read what they do on the market has overestimated the exit. A reader who concludes that the whole activity is therefore unobservable has underestimated everything else. Your line still carries a Tor connection, the subject of opening Tor at home. The server at the far end still records what you type into it, which is the whole of the market section. And no property of a circuit reaches a physical parcel.
What the network is not doing for you
Tor moves a connection between two points. It does not move a parcel, it does not unwrite a delivery address you typed into a form, and it does not remove a row from a database. Every card here is narrow on purpose: it answers what one relay position sees, and says out loud which worries it has no bearing on.
For the seven observers side by side rather than one at a time, the observers page lays them out in a row and the catalogue lists every card. The observer most readers underweight is not on this page at all. It is the far end, which learns things because you told it.
The six cards in this section
They run roughly in the order a connection is built. The first relay, then the middle, then the correction about exits that most of the others lean on. After that, how an address is located inside the network at all, what the new circuit menu item actually swaps out, and finally what happens to the observer list when a commercial VPN is added to the arrangement.
Questions that come up
Does the Tor network know which market I am visiting?
There is no single party called the Tor network to know it. Your first relay knows your address and nothing about the destination. A middle relay knows two other relays. For an address ending in .onion there is no exit relay in the path, so the position that would normally see a destination is not present at all.
Does using Tor hide the fact that I am using Tor?
Not from your own line by default. Relay addresses are published, so a connection to one is recognisable as Tor from the network side. That is the subject of the network section rather than this one.