> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.
Tor Browser disabled NoScript, but can't update
91–100 of 125 posts
Re: Tor Browser disabled NoScript, but can't update
#92Earlier quoted context omitted.
Not sure of the Firefox implementation; just pointing out revocation isn't necessarily straightforward.
The way I understand it is: certificate revocation is handled by checking OCSP servers, and OCSP servers can be programmed so they give different answers depending on the IP address of whomever is asking. In other words, it should be possible to disable all addons for a selected user by targeting him by IP address.
Mozilla, you've really been testing my patience for the last two years.
Re: Tor Browser disabled NoScript, but can't update
#93If Mozilla hadn't locked down Firefox so much, the fix could have been as simple as going into about:config and flipping a switch to allow unsigned plugins.
...which is to say, it's a trade-off, and though you can disagree with the weight Mozilla assigned to the pros and cons, their reasoning was valid.
Re: Tor Browser disabled NoScript, but can't update
#94Use curl -H "" and links --dump. Until we have something sane that's really the only safe way to browse TOR if you actually have something to hide.
(There's dillo and other things like the absolutely horrifying browser I've been writing but that hardly even supports forms right now heh. but I'm worried about connecting stuff like that to stuff like TOR)
Re: Tor Browser disabled NoScript, but can't update
#95> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.
If I'm not mistaken, then very well could revoke the intermediate certificate if they wanted. This wasn't a case of that, but it seems it could happen.
One or both would need to be true for a normal revocation to have any effect.
Re: Tor Browser disabled NoScript, but can't update
#96Earlier quoted context omitted.
Not sure of the Firefox implementation; just pointing out revocation isn't necessarily straightforward.
The way I understand it is: certificate revocation is handled by checking OCSP servers, and OCSP servers can be programmed so they give different answers depending on the IP address of whomever is asking. In other words, it should be possible to disable all addons for a selected user by targeting him by IP address.
[1] https://wiki.mozilla.org/CA/Revocation_Checking_in_Firefox
Re: Tor Browser disabled NoScript, but can't update
#97> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.
Letting a certificate expire is the same as flicking a switch IMO. Mozilla is a real organization with full time paid staff, things like this don't just slip through the cracks, especially when the 'fix' is to let Mozilla run spyware on your computer.
Re: Tor Browser disabled NoScript, but can't update
#98Earlier quoted context omitted.
It's a dumb comment. There was a ton of malware being distributed as add-ons that came packaged with other installers. This solved that issue.
Burning down London stopped the plague too.
Re: Tor Browser disabled NoScript, but can't update
#99I remember saying over and over again that using Firefox for the TOR browser was a horrible idea. Use curl -H "" and links --dump. Until we have something sane that's really the only safe way to browse TOR if you actually have something to hide. (There's dillo and other things like the absolutely horrifying browser I've been writing but that hardly even supports forms right now heh. but I'm worried about connecting s…
https://www.freehaven.net/anonbib/cache/usability:weis2006.p...
People with heightened privacy concerns can always use Whonix or Tails instead.
Re: Tor Browser disabled NoScript, but can't update
#100Earlier quoted context omitted.
Letting a certificate expire is the same as flicking a switch IMO. Mozilla is a real organization with full time paid staff, things like this don't just slip through the cracks, especially when the 'fix' is to let Mozilla run spyware on your computer.
I think almost anyone who has worked at real organisations with full-time paid staff can tell you that things do slip through the cracks. At least I can.