Live data from Hacker News

Tor Browser 10

blog.torproject.org

21–30 of 106 posts

Re: Tor Browser 10

#21
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

The reason is that encrypted websites are a bit harder to hack and inject malicious code into. In particular MITM attacks are much harder to pull off - such as those by airport/mall free wifis.

Using the latest version of TLS makes us safe from hacking.

Re: Tor Browser 10

#22

Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?

No. It's a hacked up, out of date, insecure version of Firefox. It is the opposite of worth it to ever run Tor Browser.

Re: Tor Browser 10

#23

You are not authorized to access this page. edit: it finally became available a bit later

My workplace has it blocked - as well as standard Tor traffic. Have to use a bridge to access Tor at work.

Yesterday, I made them unblock amnesty international's website.

Re: Tor Browser 10

#24
post #22

Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?

No. It's a hacked up, out of date, insecure version of Firefox. It is the opposite of worth it to ever run Tor Browser.

I'm not sure where you got the idea that it's out of date. It's based on Firefox ESR and is kept up to date with upstream patches. I'm also not sure how you came to the conclusion that it's "hacked up", considering many of its privacy enhancing patches made it into Firefox.

Re: Tor Browser 10

#26
post #13

Earlier quoted context omitted.

You can yell at google all you want but ultimately it’s the rights holders who push this initiative

All of them at once, for some reason, or is Google just covering their ass? I heard there was some boring lawyer standoff between Google and KODA, the danish music cartel, but the Google blockade goes way beyond danish music. I've seen Russian music blocked even. [1] But I see your point, though I'm not sure who is more unlikeable, Google or the music industry. Actually, let it never be said that I'm not fair: They c…

What did I just watch? :D

Re: Tor Browser 10

#27
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

I don't disagree with you but you will be more shocked to know that there are plenty of webhosts that are running old outdated websites/web applications and will fail in TLS 1.2. That is not an excuse but still a reality.

Re: Tor Browser 10

#29
post #19
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

For users wanting to prevent their ISP from sniffing around then tor works as intended. Against advertisers it also work decently as a self cleaning browsers that constantly change its IP address. For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats. It also works mostly fine again…

>It also works mostly fine against national and ISP firewalls that is intended to censor citizens and lead people away from places which the state has declared unsuited for its population.

Can't most countries just block all Tor traffic? Russia does this as far as I know. If you're the kind of state that would have a national firewall, why would you let your citizens use Tor at all?

Post reply on HN