Live data from Hacker News

“Our primary goal is to un-fork the Tor Browser”

bugzilla.mozilla.org

91–100 of 122 posts

Re: “Our primary goal is to un-fork the Tor Browser”

#91
post #84

Earlier quoted context omitted.

Speed for starters (Tor is an order of magnitude slower) and many things, like advanced JavaScript (websockets for example), flash and Java, simply can't traverse it reliably. Also it's not what people expect. Many people expect private mode to make it so their active session's browsing doesn't effect their browsing history or they tracked history, not to anonymize them entirely.

> Tor is an order of magnitude slower This claim is frequently made but I think I can objectively say (it's not the Tor fan speaking) that it's wrong. Can you back this up with numbers? Like, real world user's numbers. That means WiFi or 3g, or at best a 100mbps wire to an old WRT54G; not a professional, cabled desktop setup with FTTH or 802.11ac that many of us might use (as professionals or hobbyists). Depending on…

A quick test I did just now.

Response from google via Tor: 208 ms.

Response from google without: 32 ms.

To be fair I am basically on a trunk line via my university.

I mean you are right though, a domestic WiFi connection is likely to be in the 200 ms range, so another 200 ms on-top of that might not be as big of a deal, but I would suspect it would still end up being closer to 500 ms to get a response. Google made a point where anything over 200 ms feels slow to users. Tor is definitely going to push everything over that.

Re: “Our primary goal is to un-fork the Tor Browser”

#92
post #89

Earlier quoted context omitted.

The burning of CPU cycles whilst idling on Google's result page is the most infuriating bug in Firefox but doesn't seem to have been accorded any priority. It has persisted for at least three years. https://support.mozilla.org/fr/questions/965360 Unfortunately I usually only remember to close the results tabs when my fan spins-up.

Well, you could always just use startpage.com (uses Google) or duckduckgo.com. It's not like Google is still ages ahead of the competition as it once was. I am not sure where the bug comes from but it would be much easier for Google to fix it, given that their JS is heavily obfuscated. But then again, that's not really in their interest, is it?

But then again, that's not really in their interest, is it?

That thought struck me as well. Lets ask :-)

Googlers at HN: is this a lack of QA, a deliberate stab at Firefox or something else?

Re: “Our primary goal is to un-fork the Tor Browser”

#93
post #50

Earlier quoted context omitted.

See also this comment further up in the bug: "Mozilla leadership has already decided to help Tor move toward being able to build off a Release Firefox rather than an ESR--it's safer for our users. I don't know if we'll get to the point where they can just ship a re-packaged bundle with some pref flips and add-ons, but the more of their patches we incorporate into mozilla-central the easier it will be for them to appl…

It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.

> Maintenance of each ESR, through point releases, is limited to high-risk/high-impact security vulnerabilities and in rare cases may also include off-schedule releases that address live security vulnerabilities. Backports of any functional enhancements and/or stability fixes are not in scope.

https://www.mozilla.org/en-US/firefox/organizations/faq/

Re: “Our primary goal is to un-fork the Tor Browser”

#94
post #80
post #73

Earlier quoted context omitted.

Why couldn't Firefox use Tor in the "private mode"? Wouldn't that be the ultimate private mode? It would also greatly help the Tor community, as it would "mainstream Tor" so it wouldn't have as much stigma as it does today.

Because that's not safe. Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs. That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing. Also, the Tor network probably doesn't have enough exit node capacity to handle th…

Not to mention non-technical users will be confused and complain how slow it would become.

Re: “Our primary goal is to un-fork the Tor Browser”

#95
post #50

Earlier quoted context omitted.

See also this comment further up in the bug: "Mozilla leadership has already decided to help Tor move toward being able to build off a Release Firefox rather than an ESR--it's safer for our users. I don't know if we'll get to the point where they can just ship a re-packaged bundle with some pref flips and add-ons, but the more of their patches we incorporate into mozilla-central the easier it will be for them to appl…

It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.

Speculating but some new features are security features, like support for additional CSP directives, cipher suites, that sort of thing.

Re: “Our primary goal is to un-fork the Tor Browser”

#96
post #65
post #14

This would be a miracle for privacy advocates. However, I'm worried that Mozilla could become irrelevant in the meantime. I say this as a die-hard Firefox user (I even refuse to use any of the forks that remove the branding). Mozilla needs to be making moves that keep them relevant. This move is great for some privacy-minded folks who don't know that the Tor Browser Bundle exists, but unfortunately... most people don…

> They need to start acting like the situation is getting dire. We might start by start offering free mandatory history lessons everytime anyone uncritically evangelizes for Chrome or create anything that "works best in IE^h^hChrome". Or continue to remind those poor souls that their browser still doesn't support real extensions after all these years ;-)

> their browser still doesn't support real extensions after all these years

I'm confused. What is a "real extension"? Given the rich extension library for chrome I'm not sure of the difference.

Rather than remind the poor souls, it may be time to acknowledge and accept the fact that "real extensions" aren't an actual benefit of Firefox over Chrome? If it is a reference to IE. I think the only reason IE has market share now is the fact that it is the default on Windows.

Re: “Our primary goal is to un-fork the Tor Browser”

#97
post #4

It would be really cool if Tor became like an open web standard that every browser supported. We would be able to freely host services with incredibly strong privacy guarantees and then work them into existing web infrastructure so that normal users can benefit from strong privacy without having any special knowledge. Doing the same thing with Bitcoin wallets would also be a good idea, though I'd want for there to be…

I agree with this. "Tor Browser Mode" should become the default "Private browsing mode" on Firefox. It seems to me that a lot of uneducated users seem to have the idea that Incognito/Private mode does, somehow, give them more anonymity in a way other than locally. The extra streaming traffic would probably cripple Tor exit nodes in the short run if Mozilla didn't run worldwide fast exits on their own, but it'd be a s…

> if Mozilla didn't run worldwide fast exits on their own

If a huge portion of tor traffic is going through exit nodes owned by one organization and presumably deployed on a uniform consistent infrastructure, this becomes a prime target for hackers, state-sponsored or otherwise.

Re: “Our primary goal is to un-fork the Tor Browser”

#99
post #84

Earlier quoted context omitted.

Speed for starters (Tor is an order of magnitude slower) and many things, like advanced JavaScript (websockets for example), flash and Java, simply can't traverse it reliably. Also it's not what people expect. Many people expect private mode to make it so their active session's browsing doesn't effect their browsing history or they tracked history, not to anonymize them entirely.

> Tor is an order of magnitude slower This claim is frequently made but I think I can objectively say (it's not the Tor fan speaking) that it's wrong. Can you back this up with numbers? Like, real world user's numbers. That means WiFi or 3g, or at best a 100mbps wire to an old WRT54G; not a professional, cabled desktop setup with FTTH or 802.11ac that many of us might use (as professionals or hobbyists). Depending on…

I'm a tor fan (I run a relay) and installed it on my phone, it was objectively much much slower and things like url redirects (from emails etc) wouldn't load, I ended up having to turn it off so often that I effectively abandoned it.

I would like to move to a tor only setup, my biggest issue is that it's just too slow.

Granted I am in Australia so most of my requests were literally going to the other side of the world and then back again to complete.

Re: “Our primary goal is to un-fork the Tor Browser”

#100

Earlier quoted context omitted.

It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.

> Maintenance of each ESR, through point releases, is limited to high-risk/high-impact security vulnerabilities and in rare cases may also include off-schedule releases that address live security vulnerabilities. Backports of any functional enhancements and/or stability fixes are not in scope. https://www.mozilla.org/en-US/firefox/organizations/faq/

Damn; I assumed since it was shipped in Debian Stable it had all the same guarantees as the rest of the distro, but I guess the browser codebases tend to be such security disasters that they can't necessarily keep up.
Post reply on HN