Live data from Hacker News

Tor Browser disabled NoScript, but can't update

lists.torproject.org

121–125 of 125 posts

Re: Tor Browser disabled NoScript, but can't update

#122

Earlier quoted context omitted.

In reality though, this change has been live for a year. How many of the malicious actors switched to the model of uninstalling Firefox Stable and installing Firefox Developer Edition? (And presumably updating all the user’s aliases, start menu items, etc to point to the new browser). I haven’t heard of this actually happening.

"attack widely known and observed in the wild" is usually not the bar by which computer security systems are measured.

Mozilla’s thesis is that attackers wouldn’t be willing to go to this next step (actually uninstalling Firefox and replacing it with a different binary) because antivirus vendors would start treating them like malware.

In other words, it’s not a purely technical solution, it’s a political solution, and the success or failure of such a political solution can only be judged by real world results rather than technical possibility.

Re: Tor Browser disabled NoScript, but can't update

#123

Earlier quoted context omitted.

How could Tor both be " good at hiding government employees using untrusted networks from hostile third parties " and " NOT good at keeping you private from government "?

This article sums up all the issues with tor https://restoreprivacy.com/tor/ In particular, silk road shutdown, and various pedophile rings successfully de-anonymized and operators arrested. There is good evidence that powerful enough entity (esp. entity spanning multinational geographic regions) can successfully de-anonymize tor traffic. If you keep low profile and just use tor to browse regular internet privately,…

This sounds like FUD.

Why would it be better to connect directly to a site, rather than force them to expend resources to deanonymize my connection?

Re: Tor Browser disabled NoScript, but can't update

#124

Earlier quoted context omitted.

To play around with a non-technical solution I would consider rushing out a "Version 2.0" of the application that accomplishes the following (if possible within a 1) Has a functioning update service that fixes the original problem 2) A quick re-skin/theme-change to i.e. a more "modern" version of its original design 3) Whatever performance/security improvements you can cobble together quickly or were in the pipe alre…

I might not be your target user base, but that's exactly the opposite of what I would like as an user. I am already forced to update because the current version does not work correctly. Forcing UI/design/any major change (especially ones that are "quickly cobbled together" and thus might be buggy) on me in that situation is not nice. I am then left with the choice between a) non working software or b) a major update…

You’re definitely right, my suggestion is business friendly (theoretically) and likely user-hostile depending on how well it’s executed.

Re: Tor Browser disabled NoScript, but can't update

#125
I observed the whole scenario for the last days: For me it looks clear that the US spygov along with NAS, Mossad and EU UK have overtaken the security infrastructure on TOR net. Since 1-2 years, they control mozilla (firefox), oracle (java) and some other devs. to flaw security sensitive code. And now, this simple trick with the certificate infrastructure and the pushing of mozilla to only signed code they have compromised some 10mio. users worldwide and shown their power to kill torbrowser security with a simple wrong certificate. They have killed the most important security component - noscript - in many browsers. And if u look around .... NOBODY gives some clear information: just we make a fix and wait for next time .... It looks like the killing of truescrypt some years ago! With no real reason a worldclass security and crypto system was shut down by US LEA agents. With this action taken by US agencies it is clear that they are on the way to compromise all worldwide security software to get control on. NEVER EVER TRUST ANY US ORGANUSATION or US based SOFTWARE SYSTEM!
Post reply on HN