Live data from Hacker News

Tor Browser disabled NoScript, but can't update

lists.torproject.org

61–70 of 125 posts

Re: Tor Browser disabled NoScript, but can't update

#61
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

Lack of understanding of the technology and excessive paranoia will lead to that, I guess. "I'm telling you people, the man's after us!", and this man gets to feel like he's the hero exposing some conspiracy.

Re: Tor Browser disabled NoScript, but can't update

#62
post #46

One of the weird things here is that javascript is not disabled by default in the Tor Browser and instead an addon is needed. This whole thing is also yet another reason to use something like Tails or Whonix which are much safer to use with JS enabled.

It is a valid trade-off to leave Javascript enabled by default in Tor Browser. The reason being, the experience is much more user-friendly to a layperson and thus results in greater network usage and diversity. "Safe" is a relative concept in information security and not everyone has the same goals or risks - though in principle I agree disabling JS greatly hardens a browser.

> Layperson > Tor browser Pick one.

Re: Tor Browser disabled NoScript, but can't update

#63
post #23

Somewhat related to this ongoing Mozilla plugin saga, are there any infamous stories I should look up that involve huge mistakes leading to unfixable clients? Ie. Imagine bricking your customer's devices with an irreversible buggy update. In Mozilla's case they were able to deploy a hotfix for many, and an update for others. But I imagine there's got to be some great stories about completely bricking countless device…

It's one of my favorite interview questions. I only know the answer because it happened to us once with 5M users on the affected version before it was discovered. It's a very good question to see how people react in a mostly hopeless situation. The only candidate out of 100s to logically get to the solution (or essentially it) was one of the best engineesr I've hired and worked with. "So you and your team just releas…

You make the next version a major upgrade. Similar to Firefox 53?

Re: Tor Browser disabled NoScript, but can't update

#64
post #26
post #23

Earlier quoted context omitted.

It's one of my favorite interview questions. I only know the answer because it happened to us once with 5M users on the affected version before it was discovered. It's a very good question to see how people react in a mostly hopeless situation. The only candidate out of 100s to logically get to the solution (or essentially it) was one of the best engineesr I've hired and worked with. "So you and your team just releas…

I'm super interested to know the answer to this question. I imagine it's more interesting than just uninstall/reinstall.

As said in the other answer, hopefully the interviewee asks how it's unable to connect. If it's an Oculus situation [0] where the signing certificate is expired and you don't have a backdoor like Firefox studies, the only way is a reinstall or a "fix utility" [1].

0: https://news.ycombinator.com/item?id=16541235

1: https://www.theverge.com/2018/3/8/17095414/oculus-rift-softw...

Re: Tor Browser disabled NoScript, but can't update

#65
post #2

If Mozilla hadn't locked down Firefox so much, the fix could have been as simple as going into about:config and flipping a switch to allow unsigned plugins.

FWIW, since the original intent of the change to block unsigned plugins was to prevent third party software installers from adding malicious plugins without user consent, leaving a preference to toggle it back would have been pretty pointless as the third party installers could have just toggled the preference themselves (about:config is just some sort of easily modifiable data format on disk). TBH it’s not hard for…

If you have disk access, why even bother with a malicious plugin that has to follow all the plugin rules? You could just modify the executable itself and do whatever you wanted with no use visibility.

Re: Tor Browser disabled NoScript, but can't update

#66
post #23

Somewhat related to this ongoing Mozilla plugin saga, are there any infamous stories I should look up that involve huge mistakes leading to unfixable clients? Ie. Imagine bricking your customer's devices with an irreversible buggy update. In Mozilla's case they were able to deploy a hotfix for many, and an update for others. But I imagine there's got to be some great stories about completely bricking countless device…

It's one of my favorite interview questions. I only know the answer because it happened to us once with 5M users on the affected version before it was discovered. It's a very good question to see how people react in a mostly hopeless situation. The only candidate out of 100s to logically get to the solution (or essentially it) was one of the best engineesr I've hired and worked with. "So you and your team just releas…

To play around with a non-technical solution I would consider rushing out a "Version 2.0" of the application that accomplishes the following (if possible within a 1) Has a functioning update service that fixes the original problem

2) A quick re-skin/theme-change to i.e. a more "modern" version of its original design

3) Whatever performance/security improvements you can cobble together quickly or were in the pipe already

I would do this because I see this as also a business/finance/sales/marketing problem as a technical one. Assuming this bricked the core product, you have to save the business first, then save the quarter, then the week, then the day.

I think this would work because it is much easier to get a user to re-download a version 2.0 with performance/security/design improvements then it is to download almost anything else (imo). Again, this is assuming no saner solution exists. Interested to hear your accepted answer though.

Re: Tor Browser disabled NoScript, but can't update

#67

Earlier quoted context omitted.

If the malicious plugin or executable can write to disk it's probably to late anyway?

You're right, I think it just makes it less "gray". If Oracle bundles crapware with a Java installer that installs an unsigned plugin in Firefox, you can write a PR release to smooth things over. If the crapware uninstall Firefox, install Firefox Dev Edition, and installs the unsigned plugin, there's not much of a "gray" defence there.

Adware came bundled with chrome itself (for the money), i.e. installing new browsers is not out of the question here. That excuse feels really flimsy and tailored to permit only the exact choices made and no other option. But there are other options, such as helping users to get rid of adware when it's detected in the browser. It would also result in a larger benefit of improving their system instead just the browser.

Re: Tor Browser disabled NoScript, but can't update

#68
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

If I'm not mistaken, then very well could revoke the intermediate certificate if they wanted. This wasn't a case of that, but it seems it could happen.

Usually the whole certificate chain is distributed as a bundle, and most software don't bother checking revocations.

Re: Tor Browser disabled NoScript, but can't update

#69

Earlier quoted context omitted.

Tor project is US government op, true. It's good at hiding government employees using untrusted networks from hostile third parties. It is also good for foreign whistleblowers releasing data to US government. Tor is NOT good at keeping you private from government. It is good at keeping you private from your ISP or employer however. Don't do anything illegal using tor and thinking you are safe.

> Tor is NOT good at keeping you private from government This is a bold claim. Would you mind backing it up?

All tor exit nodes.

https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=1...

Tor is a beacon

Re: Tor Browser disabled NoScript, but can't update

#70
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

Letting a certificate expire is the same as flicking a switch IMO. Mozilla is a real organization with full time paid staff, things like this don't just slip through the cracks, especially when the 'fix' is to let Mozilla run spyware on your computer.
Post reply on HN