Live data from Hacker News

“Our primary goal is to un-fork the Tor Browser”

bugzilla.mozilla.org

101–110 of 122 posts

Re: “Our primary goal is to un-fork the Tor Browser”

#101
post #78

Earlier quoted context omitted.

Definitely, if it's in a mainstream browser it suddenly seems a lot less clandestine. Just like a VPN. I wonder if this will create a load on exit nodes as the new users are unlikely to bring proportional exit nodes?

This is really nothing to do with Tor specifically, but it's a good fit for a question that I think is curious about optional payment systems. If your browser counted how much resources you've consumed in browsing and asked you to retroactively & optionally "pay your bill," could this generate the cash to keep the service running?

This is a nice idea. It could keep running totals for other free resources as well, such as Wikipedia.

I bet it would increase donations to useful projects like these.

Re: “Our primary goal is to un-fork the Tor Browser”

#102
post #14

This would be a miracle for privacy advocates. However, I'm worried that Mozilla could become irrelevant in the meantime. I say this as a die-hard Firefox user (I even refuse to use any of the forks that remove the branding). Mozilla needs to be making moves that keep them relevant. This move is great for some privacy-minded folks who don't know that the Tor Browser Bundle exists, but unfortunately... most people don…

> most people don't care about > their privacy online Apple are betting they will do, and I think that's prescient. Only need a few more Ashley Madisons to see a sea change in this area, and a browser that's been ahead of the curve for a long time has a lot to gain.

> > most people don't care about their privacy online

> Apple are betting they will do

No they're not. iCloud is still not end-to-end encrypted; iMessage users still trust Apple to verify identity; macOS and iOS users still cannot verify the source of the OSes they run.

Apple may be betting that people care about online-privacy snake oil.

Re: “Our primary goal is to un-fork the Tor Browser”

#103
post #96
post #65

Earlier quoted context omitted.

> They need to start acting like the situation is getting dire. We might start by start offering free mandatory history lessons everytime anyone uncritically evangelizes for Chrome or create anything that "works best in IE^h^hChrome". Or continue to remind those poor souls that their browser still doesn't support real extensions after all these years ;-)

> their browser still doesn't support real extensions after all these years I'm confused. What is a "real extension"? Given the rich extension library for chrome I'm not sure of the difference. Rather than remind the poor souls, it may be time to acknowledge and accept the fact that "real extensions" aren't an actual benefit of Firefox over Chrome? If it is a reference to IE. I think the only reason IE has market sha…

For me, and I guess many hardcore FF users, the extensions on Chrome is a dealbreaker. I honestly tried and it was beyond my patience.

A number of the best extensions just doesn't exist on Chrome, most notably all good tab-tree extensions.

I guess this makes me a spoiled brat, but hey it is free so anyone can be a spoiled brat.

Re: “Our primary goal is to un-fork the Tor Browser”

#104
post #80
post #73

Earlier quoted context omitted.

Why couldn't Firefox use Tor in the "private mode"? Wouldn't that be the ultimate private mode? It would also greatly help the Tor community, as it would "mainstream Tor" so it wouldn't have as much stigma as it does today.

Because that's not safe. Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs. That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing. Also, the Tor network probably doesn't have enough exit node capacity to handle th…

These are bogus arguments that sound reasonable in the absence of a relevant comparison but are all flimsy and uninformed upon inspection.

For example, by what definition would this not be 'safe'? Do you mean in comparison to Firefox's defaults, which enable profoundly privacy-invasive tracking, hide the contents of the cookie management dialog box, and enable the delivery of malvertising at will by visiting "safe" websites - just to name a few?

MitM positions exist on the internet for all users today, both for HTTP and in the situation of "new HTTPS bugs". So you point out risks taken when using the internet in general, and the Tor Browser Bundle already mitigates many of those risks via NoScript and various patches. I've used Tor Browser Bundle daily for all purposes - including online banking and shopping - for several years with zero problems. Malicious exits exist and get flagged out of the network rapidly. Essentially all remaining risk is trivially defeated by toggling the 'block all unencrypted requests' pref in HTTPSEverywhere, which is part of the Tor Browser Bundle and could be built into an implementation in Firefox with a warning for HTTP traffic.

And you're probably thinking of 2009-era Tor network experience. For me, Tor network performance routinely boils down to ~200ms additional latency with ~1.5-2MB/s download speeds. The difference between that and an average broadband connection is barely noticeable.

I recommend using the Tor network and the Tor Browser Bundle before criticizing this idea.

Re: “Our primary goal is to un-fork the Tor Browser”

#106
post #84

Earlier quoted context omitted.

> Tor is an order of magnitude slower This claim is frequently made but I think I can objectively say (it's not the Tor fan speaking) that it's wrong. Can you back this up with numbers? Like, real world user's numbers. That means WiFi or 3g, or at best a 100mbps wire to an old WRT54G; not a professional, cabled desktop setup with FTTH or 802.11ac that many of us might use (as professionals or hobbyists). Depending on…

A quick test I did just now. Response from google via Tor: 208 ms. Response from google without: 32 ms. To be fair I am basically on a trunk line via my university. I mean you are right though, a domestic WiFi connection is likely to be in the 200 ms range, so another 200 ms on-top of that might not be as big of a deal, but I would suspect it would still end up being closer to 500 ms to get a response. Google made a…

> a domestic WiFi connection is likely to be in the 200 ms range

My wifi connection gives me ~18ms roundtrip to Google, and about 8ms extra to work, and ~50ms roundtrip from my moms house in Norway where I am currently, via her wifi, to my home server in the UK (and ~18ms roundtrip to Google from here too).

These are nothing special for developed countries - just regular consumer connections. When I've been on business fibre subscriptions we've consistently gotten better results.

EDIT: I initially wrote "maybe 5 years ago", without thinking. Some additional observations: While ~200ms roundtrips to a site was a thing going back long enough, first hop latencies even on dialup was rarely even 100ms. I know: I ran an ISP, and had to deal with irate customer if latency from them to their nearest games servers got to that kind of level, even in the mid 90's.

SSH connection roundtrips start becoming painful in the ~120ms roundtrip range, and it's been a decade plus since that's been a problem other than when managing a slow system on the US west coast or Asia for me (connecting from Europe). Beijing or New Zealand has been in the 200ms+ range for me. If anything closer is in that range, it's a sign something is wrong.

Re: “Our primary goal is to un-fork the Tor Browser”

#107
post #78

Earlier quoted context omitted.

Definitely, if it's in a mainstream browser it suddenly seems a lot less clandestine. Just like a VPN. I wonder if this will create a load on exit nodes as the new users are unlikely to bring proportional exit nodes?

This is really nothing to do with Tor specifically, but it's a good fit for a question that I think is curious about optional payment systems. If your browser counted how much resources you've consumed in browsing and asked you to retroactively & optionally "pay your bill," could this generate the cash to keep the service running?

This isn't altogether uncommon in free software, and is sometimes referred to as 'beggarware'.

I've been guilted into donating by some of these, but if it's too annoying it can have the opposite effect and cause you to drop the software.

One that comes to mind is a download site that tracked your download count and put a rainbow-colored '(maybe you should donate)' link next to it. Not very detrimental to the UX, but gets the message across.

Re: “Our primary goal is to un-fork the Tor Browser”

#108
post #50

Earlier quoted context omitted.

See also this comment further up in the bug: "Mozilla leadership has already decided to help Tor move toward being able to build off a Release Firefox rather than an ESR--it's safer for our users. I don't know if we'll get to the point where they can just ship a re-packaged bundle with some pref flips and add-ons, but the more of their patches we incorporate into mozilla-central the easier it will be for them to appl…

It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.

An example is "Slaughterhouse" (see https://bugzilla.mozilla.org/show_bug.cgi?id=929539 and http://bholley.net/blog/2016/the-right-fix.html). This is not the only incident where Mozilla people have suggested hiding bugs until an old ESR goes end of life BTW.

Re: “Our primary goal is to un-fork the Tor Browser”

#109
post #80
post #73

Earlier quoted context omitted.

Why couldn't Firefox use Tor in the "private mode"? Wouldn't that be the ultimate private mode? It would also greatly help the Tor community, as it would "mainstream Tor" so it wouldn't have as much stigma as it does today.

Because that's not safe. Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs. That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing. Also, the Tor network probably doesn't have enough exit node capacity to handle th…

> Exit nodes can trivially screw around with plain HTTP (both snoop on and rewrite), and it also puts them in a MitM position for new HTTPS bugs.

This is no different from your ISP or the guy next to you on the coffee shop wireless.

If you don't want people to snoop and rewrite your HTTP connection, don't use HTTP. And the solution to broken HTTPS is to fix HTTPS. Tor doesn't decrease your security in either of these cases.

> That's a risk you take when using Tor, and it's not a tradeoff you can reasonably convey to existing Firefox users who are used to Private mode meaning a certain thing.

1. It's not a tradeoff. Tor does not decrease your security in either case. There are cases where Tor doesn't provide privacy protections, but there's not a case I know of where using Tor provides fewer protections than not using Tor.

2. It's impossible to convey to non-technical users that private browsing doesn't provide privacy from their ISP, governments, etc. I don't understand how you can claim that providing fewer privacy protections is less confusing to the non-technical user.

> Also, the Tor network probably doesn't have enough exit node capacity to handle the volume it would get.

This is a solvable problem.

Re: “Our primary goal is to un-fork the Tor Browser”

#110

Earlier quoted context omitted.

> Maintenance of each ESR, through point releases, is limited to high-risk/high-impact security vulnerabilities and in rare cases may also include off-schedule releases that address live security vulnerabilities. Backports of any functional enhancements and/or stability fixes are not in scope. https://www.mozilla.org/en-US/firefox/organizations/faq/

Damn; I assumed since it was shipped in Debian Stable it had all the same guarantees as the rest of the distro, but I guess the browser codebases tend to be such security disasters that they can't necessarily keep up.

Projects release new versions of software not just for new features, but (one would hope) constant improvements to the underlying architecture.

Firefox in particular has been evolving quickly, with many of under-the-hood improvements that may not fix "high-risk" security issues, but constantly improve security directly or indirectly (e10s?). You can't expect maintainers of an ESR to backport all those things.

There's always a risk in adopting the latest version of a program, but there's also a risk with keeping the old, less actively maintained version. I get burned all the time with Debian Stable, running into bugs fixed in the latest version but not backported. (nonetheless, I do prefer Debian Stable to most other solutions)

A project I'm involved in even has an automatic "toxic code" warning for PRs on known functions/classes that need to be refactored, and where monkey-patching will likely cause other security issues one way or another.

Post reply on HN