Live data from Hacker News

Javascript exploit actively used against TorBrowser

lists.torproject.org

81–90 of 138 posts

Re: Javascript exploit actively used against TorBrowser

#81

I feel like Tor Browser should just spin up a fresh VM with a minimal Linux distribution and fullscreen Tor browser, with the VM's only networking tunneled through Tor. I think Hyper-V can do graphics as well and it looks like bhyve added some sort of graphics support earlier this year, but xhyve has none. Not sure if there are any other lightweight hypervisors that support graphics (or maybe just use a protocol like…

Yes it can.

It is a type 1 hypervisor and DX is supported since a few versions.

Also the foundation of Windows 10 containers and secure kernel.

Re: Javascript exploit actively used against TorBrowser

#82
post #13

As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…

Last time I checked, it was just for process separation and did not provide any security guarantees.

It's a separate project from e10s (though it depends on it): https://wiki.mozilla.org/Security/Sandbox

Chromium had a fair bit of sandbox escapes during the first years, and there's no reason to believe this is going to be different with Firefox.

I agree. Note that people still find sandbox escapes against Chrome anyway. Yes, sometimes they use the OS, but due to how the sandboxing works that's to be expected.

Even Microsoft Edge is better at this.

CVE counting, especially the ones published by the developers themselves, aren't a very good measure of security.

Re: Javascript exploit actively used against TorBrowser

#83
post #13

As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…

> Chrome's security team is probably the strongest in the industry and they poured an absurd amount of effort into Chrome's security. Could you elaborate? I'm curious what they do for security.

Just google for Project Zero.

Re: Javascript exploit actively used against TorBrowser

#85

If TBB leads want to run Firefox with JavaScript "default on", then Tor Browser Bundle needs to be messaged as insecure. Either that or turn on NoScript and inform people what bad shit can happen when their browser is interpreting arbitrary code in a not-so-sandboxed manner. TBB is not a solution against targeted deanonymization attacks. This is neither the first nor is the last 0day in Firefox that will affect TBB.…

VMs are all nice and that but if the exploit can compromise the TBB it's too late already, sandboxing needs to happen in the browser on Linux you can use namespaces + strict seccomp rules but don't know what one would use for Windows. First priority would be to sandbox the browser and work your way down if you want to sandbox more stuff. For Windows EMET can help to prevent certain exploits I guess but yea a browser…

VMs are all nice and that but if the exploit can compromise the TBB it's too late already, sandboxing needs to happen in the browser on Linux you can use namespaces + strict seccomp rules but don't know what one would use for Windows.

You can take a look at the sandbox implementation of Firefox (shared with Chrome) to see. TBB uses ESR which predates all that, though.

Re: Javascript exploit actively used against TorBrowser

#86
post #13

As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…

Is the situation with Firefox this dire, when compared to Chrome? Can anyone corroborate?

This realization may be enough for me to finally switch, if so.

Re: Javascript exploit actively used against TorBrowser

#87
post #71

Earlier quoted context omitted.

The same vulnerability apparently also exists in Firefox, which Tor Browser is based on.

But its worse on Tor. Regular internet has a few protections: 1. Google safe browsing 2. AdBlocking 3. Websites try to keep their reputation. Tor exit nodes, on the other hand, have no reputation (and if one gets sullied, spin up another) and costs money.

I have one question: the list of exit nodes is public, we can know at any time the circuit's complete list of servers.

Does something prevents us from rating tor exit nodes according to their "transparency" and add this rating in the consensus file?

Does anybody already worked on that? I cannot find anything on the internet…

Re: Javascript exploit actively used against TorBrowser

#88

If TBB leads want to run Firefox with JavaScript "default on", then Tor Browser Bundle needs to be messaged as insecure. Either that or turn on NoScript and inform people what bad shit can happen when their browser is interpreting arbitrary code in a not-so-sandboxed manner. TBB is not a solution against targeted deanonymization attacks. This is neither the first nor is the last 0day in Firefox that will affect TBB.…

I've never understood the Tails threat model, and this comment does not really help. You say that it will prevent the attackers from learning any information, except the real IP address of the user. But hiding the IP address of the user is the whole point of Tor. If you give that up, then what's even the point? The state can simply drive a black van to your house and get the rest of your information at their leisure.

If you're using Tor from a coffee shop, so an IP address alone isn't enough to identify you.

Or if you're in a country oppressive enough that they'll raid your house for using Tor, but free enough that they'll let you off if they don't find evidence you were doing something illegal over Tor, and they didn't compromise the site you were visiting just asked your ISP to look for Tor users.

Re: Javascript exploit actively used against TorBrowser

#89

Earlier quoted context omitted.

> A better solution would be to run javascript in a sandbox (as is done in Chrome/Chromium based browser) which has a much higher barrier to exit. Sure, but we can't get TBB rewritten overnight to work instantly with Chromium, and I'm sure there'd be a lot of push back on that.

An easier solution would be to enable e10s. It should be on by default in the next ESR, and I know TBB has been working to make their patches compatible with it.

Not just e10s, they also need to enable the sandboxing, i.e. it requires Firefox 50 at least.

It should actually be easier for Tor to enable stricter sandboxing than in the default Firefox, though, as presumably they have to care less about compatibility.

Re: Javascript exploit actively used against TorBrowser

#90

Earlier quoted context omitted.

"If"? Are there any Tor users who don't need to worry about leaking their IP address? Then why do they use Tor in the first place? The Tor project itself seems to promote Tails much more than Whonix, which seems very odd to me.

After thinking about this, I agree with your point, but it's past me being able to edit my original comment to address this issue there. OK, now you have an IP. Now what? You get a warrant and search the place. What do you find? A computer, maybe an amnesic virtual machine. No actual access to the website/onion in question. IMO Tails promotes better opsec when using Tor - you don't leave any traces behind of your bro…

You look at this from the privacy perspective of someone who wants to hide something within the constraints and confines of a working - and at least somewhat ethical - legal and judiciary framework.

The original use case for Tor is for people who actually need to be able to use the net and hide. If their location and they get it with the equivalent of their local government's "search warrant", it's more likely a raid, interrogation, threats, harassment, censorship, and possibly torture and death.

It's a whole different ball-game.

Post reply on HN