Live data from Hacker News

Javascript exploit actively used against TorBrowser

lists.torproject.org

41–50 of 138 posts

Re: Javascript exploit actively used against TorBrowser

#42

Earlier quoted context omitted.

This likely points to this being an FBI "network investigative technique".* I'm really curious where this attack was injected, as that also means that that .onion is also compromised. My guess? Some darknet market. * Sure, this could be some type of awkward false flag, but it seems unlikely to my gut.

Background for the uninitiated: https://www.eff.org/deeplinks/2016/09/playpen-story-fbis-unp...

Unrelated, but kudos on the arbitrary hash use on the Wordpress auto updater last week.

Re: Javascript exploit actively used against TorBrowser

#43

Earlier quoted context omitted.

What's their biggest struggle with it? PS, if you're ever on the US West Coast or in Singapore, drop me a DM. I'll buy you a drink someplace.

Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…

Hey! I don't mean to hijack this conversation, but I see you built Umbrella specifically for android.

In an attempt to take back a little control over my personal data, I've switched from android devices back to ios. I notice that orbot/orfox aren't available for ios and it doesn't appear umbrella is either.

Is there something I am missing about apple's platform that makes android the better choice for security? Or why aren't people building ios apps for security?

Re: Javascript exploit actively used against TorBrowser

#45

Earlier quoted context omitted.

What's their threat model, then? If you're going to be actively targeted by exploits like this, then you shouldn't give a damn about some of these tradeoffs. If you have journalists/activists willing to go to information war with a nation-state, they shouldn't be surprised when their adversaries have the resources to pwn them. If David wants to fight goliath, they will need to take this into account. The guys with gu…

If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting. I get what your saying but humans are humans, journalists are busy and security is a pain for most people (until they need it). The threat model really depends and so is too wide for me…

>>I get what your saying but humans are humans, journalists are busy and security is a pain for most people (until they need it).

...until they see they need it.

Sad, as most people may not even know that they need to go to these kind of depths. For them, TBB seems more than enough.

Re: Javascript exploit actively used against TorBrowser

#46

Earlier quoted context omitted.

Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…

Hey! I don't mean to hijack this conversation, but I see you built Umbrella specifically for android. In an attempt to take back a little control over my personal data, I've switched from android devices back to ios. I notice that orbot/orfox aren't available for ios and it doesn't appear umbrella is either. Is there something I am missing about apple's platform that makes android the better choice for security? Or w…

Hey no worries....a few things.

-Umbrella on iOS is coming in 2nd quarter of next year! Whoohoo (We get asked about this all the time).

-The main reason that we and a number of other open-source projects built on Android first is that because is by far the dominant smartphone platform. Especially in developing areas with significant human rights problems like China, Russia, parts of Africa and Asia. Mainly because the cost of Android phones is low.

-On the security specific question. I think the Android vs iOS debate has evolved. A few years ago it was felt that the open-source(ish) and customisation aspects of the Android platform meant that it was the more obvious choice for a secure phone.

I think that what we have seen recently, with tens of millions of Android phones not getting updates etc - has probably challenged that[1]. Especially when iOS now has encryption as standard and other security features. Of course there are Android options like Copperhead/F-Droid/Guardian Project which are examples of how you can retake control to a certain extent, but I think for the average person's threat model iOS is probably pulling ahead on the security side of things.

[1] https://threatpost.com/android-security-report-29-percent-of...

Re: Javascript exploit actively used against TorBrowser

#47
post #45

Earlier quoted context omitted.

If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting. I get what your saying but humans are humans, journalists are busy and security is a pain for most people (until they need it). The threat model really depends and so is too wide for me…

>>I get what your saying but humans are humans, journalists are busy and security is a pain for most people (until they need it). ...until they see they need it. Sad, as most people may not even know that they need to go to these kind of depths. For them, TBB seems more than enough.

Couldn't agree more.

Re: Javascript exploit actively used against TorBrowser

#48

If TBB leads want to run Firefox with JavaScript "default on", then Tor Browser Bundle needs to be messaged as insecure. Either that or turn on NoScript and inform people what bad shit can happen when their browser is interpreting arbitrary code in a not-so-sandboxed manner. TBB is not a solution against targeted deanonymization attacks. This is neither the first nor is the last 0day in Firefox that will affect TBB.…

I've never understood the Tails threat model, and this comment does not really help. You say that it will prevent the attackers from learning any information, except the real IP address of the user. But hiding the IP address of the user is the whole point of Tor.

If you give that up, then what's even the point? The state can simply drive a black van to your house and get the rest of your information at their leisure.

Re: Javascript exploit actively used against TorBrowser

#49
Has nobody tried putting Gopher and Tor together? Would probably yield slightly better results given how minimalist Gopher is, mostly text based. It might not work as well if you try to have a "community" on Tor, but it would be interesting to know how Gopher works out in Tor if at all?

Re: Javascript exploit actively used against TorBrowser

#50

Earlier quoted context omitted.

Hey! I don't mean to hijack this conversation, but I see you built Umbrella specifically for android. In an attempt to take back a little control over my personal data, I've switched from android devices back to ios. I notice that orbot/orfox aren't available for ios and it doesn't appear umbrella is either. Is there something I am missing about apple's platform that makes android the better choice for security? Or w…

Hey no worries....a few things. -Umbrella on iOS is coming in 2nd quarter of next year! Whoohoo (We get asked about this all the time). -The main reason that we and a number of other open-source projects built on Android first is that because is by far the dominant smartphone platform. Especially in developing areas with significant human rights problems like China, Russia, parts of Africa and Asia. Mainly because th…

Thanks! That's mostly what I suspected. Android does have massive market share outside of North America, but here it is much closer to 50/50. Obviously our security/privacy concerns are drastically different than those in other parts of the world so it makes sense to secure android first.

It's hard to recommend alternative distributions of android to most people. I feel like it's similar to linux 15 years ago, it CAN be more secure, but it can also be incredibly insecure if setup improperly. And if you are just going to go install playstore and google apps, was anything really accomplished?

Post reply on HN