Live data from Hacker News

Tor Browser 10

blog.torproject.org

11–20 of 106 posts

Re: Tor Browser 10

#11
> Bug 11154: Disable TLS 1.0 (and 1.1) by default

I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

Re: Tor Browser 10

#12
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care?

I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

Re: Tor Browser 10

#13
post #8

Been using Tor a lot more, since Youtube started disallowing danes access to nearly all music. Get bent, Google.

You can yell at google all you want but ultimately it’s the rights holders who push this initiative

All of them at once, for some reason, or is Google just covering their ass? I heard there was some boring lawyer standoff between Google and KODA, the danish music cartel, but the Google blockade goes way beyond danish music. I've seen Russian music blocked even. [1]

But I see your point, though I'm not sure who is more unlikeable, Google or the music industry. Actually, let it never be said that I'm not fair: They can all get bent.

[1] Never thought I'd link this on HN: https://www.youtube.com/watch?v=1t_sMynan_k

Re: Tor Browser 10

#14
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

The plan was actually to deprecate support this year (only https://www.ssllabs.com/ssl-pulse/

https://nakedsecurity.sophos.com/2020/04/02/covid-19-forces-...

Re: Tor Browser 10

#15
post #6

Earlier quoted context omitted.

Yes. It disables many (all?) mozilla integrations such as password manager and intermediate certificate preload. I prefer to use the story network with standard Firefox because I value the mozilla features except for Pocket.

Is there an extra fork for de-tored Tor Browser or do you just have to live with the warning that Tor is disabled? I've heard that Whonix makes a custom tor based browser but I don't think it is supported anymore.

Waterfox is a decent de-Mozzila'd fork of Firefox

Re: Tor Browser 10

#16

Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?

I adapted a user.js template [1] that hardens Firefox by disabling a lot of features, including disabling Mozilla products like Pocket.

By default it is very strict though, so you will probably want to go through the config setting by setting and relax it a bit. Like enabling Webassembly and the search engine integration of the URL bar.

Most settings have inline comments explaining what they do and why they are chosen.

[1] https://github.com/pyllyukko/user.js

Re: Tor Browser 10

#17
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

If anything, websites made with drag-and-drop website builders should always use the latest TLS standard because it’s just a single change for the hosting provider to make for all of the customers. I think the hosting provider generates a certificate anyway.

Re: Tor Browser 10

#18
post #7
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

I think it remains the best in class for private browsing. They have to make difficult trade-offs that achieve acceptable levels of performance while not leaking metadata like a sieve. They do also have a good track record of handling security vulnerabilities. For the average user, the greatest threat is actually everything outside the Tor browser. For example, downloading certain files using Tor, then opening it in…

There are some ways to mitigate some of the threats that you mention. Using Qubes or Whonix could prevent network access to other programs. The unencrypted requests can be blocked by turning on the EASE option in the HTTPS-Everywhere preferences. Tor doesn't have any way to protect against global adversaries performing timing analysis or attacks though.

Re: Tor Browser 10

#19
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

For users wanting to prevent their ISP from sniffing around then tor works as intended. Against advertisers it also work decently as a self cleaning browsers that constantly change its IP address.

For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats.

It also works mostly fine against national and ISP firewalls that is intended to censor citizens and lead people away from places which the state has declared unsuited for its population.

Against police force it seem to mostly work as a free tool that get used by criminals as something better than nothing, but with some larger caveats and the police have cases from time to time where they have identified criminals (from either good investigations or parallel constructions depending on who you ask). The tor browsers has also not been immune to malware.

Against national-level intelligence agency, "citizen scores", and whistleblowers employed within such agencies, the protection granted by tor may be very far from 100%. It is not recommended by anyone to depend on tor against that threat model.

Re: Tor Browser 10

#20
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

My understanding is that the general argument is that if we all require security for comedy browsing, the traffic of the people who require better security is better because it’s less conspicuous? See also declaring your personal pronouns as someone who thinks they will never be misgendered, or using Tor for normal browsing
Post reply on HN