Checks that TUN/VPN mode really carries your traffic (#83), fixes a kill switch that switched itself off, and brings a redesigned Home page (#73).
Fixed
- TUN/VPN mode now checks that the tunnel really carries your traffic (#83). The IP on Home was always fetched through Tor's own SOCKS port, so it showed a Tor exit whenever Tor was running, even if the tunnel carried nothing at all. A user saw "all traffic via Tor" next to a Tor IP while Firefox reported their real one. Full-tunnel sessions now also make a fresh connection the way any other program would and compare its public IP with the one seen before connecting. If it comes out with your real address, Home turns red with "Not protected" and says what to do. When the check passes, Home shows "Tunnel verified". If you have routing rules that send some sites, countries or categories around Tor, a direct answer may simply be one of them, so that case is logged as inconclusive instead of raising the alarm.
- On connect, TUN/VPN mode now warns that programs already online can keep their old connections outside Tor. Windows keeps a connection on the network adapter it started on, and browsers hold connections to sites open for minutes, so reloading an IP check page right after connecting can show your real address even though everything new goes through the tunnel. Restart your browser after connecting.
- The kill switch no longer switches itself off seconds after it fires. When the tunnel died with the kill switch on, OnionHop blocked all traffic and then went straight into its normal automatic disconnect, which removed the block again. Traffic went back out on your real connection without you doing anything, which is the one thing a kill switch exists to prevent. The block now stays until you decide to end it: press Restore internet on Home, or connect again. It also fires when Tor or Arti stops unexpectedly, it is still there (and shown) if you restart OnionHop, and Home says plainly that traffic is blocked instead of "Disconnected".
- The kill switch can be turned on again. Its switch lived on the old Home page and was lost in the V3 redesign while the setting kept working: anyone who had it on kept it without seeing it, and nobody else could turn it on. It is back under Settings > Advanced > TUN engine.
- Proxy Mode now notices when something resets the system proxy, and puts it back. Proxy Mode only protects traffic while the Windows proxy setting points at Tor, but that was never re-checked. When Windows, another VPN, a cleanup tool or a browser reset it mid-session, the System proxy switch still read ON while traffic went out directly. It is now re-checked every 15 seconds while connected and restored, with a log line saying so. A proxy that belongs to another program is never overwritten; that case is reported instead.
- Downloaded Tor and tunnel components are checked before they are used. sing-box, xray and wintun are checked against SHA-256 hashes pinned in the app, and the Tor Expert Bundle against the checksum the Tor Project publishes beside it. A download that does not match is deleted and never run. The tunnel cores are also pinned to the versions OnionHop ships and is tested with, instead of whatever was newest on GitHub. These downloads only happen when a bundled component is missing.
- Logs no longer contain your real IP, your plain bridges or your Windows account name. People paste these logs into public issues. Your IP is shortened to the network part (for example
91.236.x.x), plain (vanilla) bridges are logged as their address only, and your user folder shows as%USERPROFILE%. - Switches that don't apply now look it. A disabled switch looked exactly like a working one, so in full-tunnel mode the split tunneling switches read "on" and ignored every click. They are now faded. Block UDP traffic only ever did anything with split tunneling (full tunnel never lets UDP out), so it is only available there and says so.
- Onion services. The fields for a new service have labels now: three of the four start with a value, so their placeholders never showed and the row read "80, 127.0.0.1, 80" with nothing saying which port was which. The on/off button is a switch, and the section's messages are translated.
- Settings. The Bridge type list could come up empty. Two settings showed another setting's description, and three described working features as coming later. The connection timeout explanation was cut off inside its text box. The Snowflake volunteer section told people to build the proxy with a developer script, although it ships with the app.
- The bridge "last updated" time no longer shows a Solar Hijri date in an English interface on Persian-locale Windows.
- Translations. 22 settings that were still English in every other language are translated. German and French texts that had lost their umlauts and accents are fixed, and a stray letter from another script inside a Kurdish word is gone.
Added
- Redesigned Home page (#73), based on the proposal by @alirezafarvardin. The status now answers one question, "am I protected", in a word or two ("Connected", "Connecting", "Disconnected", "Not protected") with one plain sentence underneath. That sentence is worked out from what is actually happening, so it can no longer contradict the controls: before, switching the system proxy on after connecting left the button reading ON next to a headline saying the system proxy was off.
- While connecting you see Tor's live progress, and a new Latest line shows the most recent meaningful event with a shortcut to Logs.
- The Mode choice explains itself where you make it (Proxy Mode only covers apps that follow the Windows proxy setting, TUN/VPN mode covers every app) and is locked during a session.
- The System proxy switch sits with the mode it belongs to and only appears where it does anything.
- Four compact figures replace the large speed bars: downloaded, uploaded, circuits built and identity changes, with live speeds.
- Update bridges and the last update time moved to Settings, Bridges. A More settings link on Home goes straight there.
Downloads
| Platform | File |
|---|---|
| Windows installer | OnionHop-Setup-v3.exe
|
| Windows portable | OnionHopV3-Portable-3.8.3-win-x64.zip
|
| Windows CLI | OnionHop-CLI-Setup-3.8.3.exe / OnionHopCLI-Portable-3.8.3-win-x64.zip
|
| Linux | OnionHop-x86_64.AppImage
|
| Linux CLI | OnionHopCLI-3.8.3-linux-x64.tar.gz
|
| macOS (Apple Silicon) | OnionHop-3.8.3-macOS-arm64.dmg
|
| macOS (Intel) | OnionHop-3.8.3-macOS-x64.dmg
|
| macOS CLI (Apple Silicon) | OnionHopCLI-3.8.3-macos-arm64.tar.gz
|
| macOS CLI (Intel) | OnionHopCLI-3.8.3-macos-x64.tar.gz
|