Live data from Hacker News

Tor Browser 10

blog.torproject.org

61–70 of 106 posts

Re: Tor Browser 10

#61
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

[deleted]

Re: Tor Browser 10

#62
post #49

If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...).

To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)

Re: Tor Browser 10

#63

You are not authorized to access this page. edit: it finally became available a bit later

My workplace has it blocked - as well as standard Tor traffic. Have to use a bridge to access Tor at work. Yesterday, I made them unblock amnesty international's website.

https://web.archive.org/web/2020/https://blog.torproject.org... should work.

Re: Tor Browser 10

#64
post #49

If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...). To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)

The state could easily track who accesses that GitHub page, if they control the ISP.

Re: Tor Browser 10

#65
post #11

> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

Obviously your web browser doesn't know if this is "just" some Wix brochureware site where you don't actually care about security or if it's a bank or your webmail or the passport office.

So to keep browser users safe we need to deliver the security they expect all the time. The rule has to be consistent, either the rule is "TLS 1.0 is no good, stop that" or it's "TLS 1.0 is fine, First Bank of Springfield can keep right on using it".

There's not really space for nuance here because there's no sign of a capacity for nuance in the ordinary user's understanding of web security. If anything the continued existence of plaintext HTTP is already too much nuance for users, but unlike adding a special "Kinda sorta secure" TLS 1.0 mezzanine that's a legacy problem we're stuck with already.

Re: Tor Browser 10

#66
post #64

Earlier quoted context omitted.

You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...). To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)

The state could easily track who accesses that GitHub page, if they control the ISP.

That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?

Re: Tor Browser 10

#67
post #45

Earlier quoted context omitted.

That's unfortunately so true. The thorough and strongly regulated engineering results in good quality for mechanical products, but is detrimental for the fast paced software world. SSL3.0 is from 1996. That's the life cycle of 2-3 cars and much less than a building, so "not a long time ago" in engineering terms "when it still works". I joined a German engineering company and made the naive assumption that proficiency…

Having to deal with Siemens healthcare software - they take the very understandable risk aversion (some of which is a must when it comes to medical equipment) and take it so far that it seriously hampers their ability to keep up with the industry, and (ironically) to maintain a stable product. I think it's their North American software teams that keep them moving forward, otherwise they'd still to this day be selling…

Oh god... The Siemens modalities that I work on are garbage.

Same for Phillips.

I have mixed feelings about GE as well.

Healthcare tech is definitely hampered by the speed at which software _should_ move forward. The cost of getting FDA approval is crazy, especially for simple changes/security updates.

Re: Tor Browser 10

#68
post #59
post #49

If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

There's way too much noise in this measurement for it to be seriously meaningful, unless ownership of tor was itself a crime.

Maybe in the west that'd be true- since we can freely trade information over the public internet, TOR doesn't have much utility. Let's say you're in a more totalitarian government that censors more information- TOR might look like a practical solution there, and might have people using it for more practical purposes.

Re: Tor Browser 10

#69
post #66
post #64

Earlier quoted context omitted.

The state could easily track who accesses that GitHub page, if they control the ISP.

That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?

Just did some research, and you're right! TLS obscures the URL by default. I didn't know that.

Only nuance being that an attacker can draw conclusions about the length of the URL- which won't be very helpful on Github.

Re: Tor Browser 10

#70
post #66
post #64

Earlier quoted context omitted.

The state could easily track who accesses that GitHub page, if they control the ISP.

That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?

Yeah they need to hack or infiltrate Github, or get a warrant for your data.
Post reply on HN