> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
Tor Browser 10
61–70 of 106 posts
Re: Tor Browser 10
#62If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.
To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)
Re: Tor Browser 10
#63You are not authorized to access this page. edit: it finally became available a bit later
My workplace has it blocked - as well as standard Tor traffic. Have to use a bridge to access Tor at work. Yesterday, I made them unblock amnesty international's website.
Re: Tor Browser 10
#64If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.
You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...). To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)
Re: Tor Browser 10
#65> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
So to keep browser users safe we need to deliver the security they expect all the time. The rule has to be consistent, either the rule is "TLS 1.0 is no good, stop that" or it's "TLS 1.0 is fine, First Bank of Springfield can keep right on using it".
There's not really space for nuance here because there's no sign of a capacity for nuance in the ordinary user's understanding of web security. If anything the continued existence of plaintext HTTP is already too much nuance for users, but unlike adding a special "Kinda sorta secure" TLS 1.0 mezzanine that's a legacy problem we're stuck with already.
Re: Tor Browser 10
#66Earlier quoted context omitted.
You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...). To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)
The state could easily track who accesses that GitHub page, if they control the ISP.
Re: Tor Browser 10
#67Earlier quoted context omitted.
That's unfortunately so true. The thorough and strongly regulated engineering results in good quality for mechanical products, but is detrimental for the fast paced software world. SSL3.0 is from 1996. That's the life cycle of 2-3 cars and much less than a building, so "not a long time ago" in engineering terms "when it still works". I joined a German engineering company and made the naive assumption that proficiency…
Having to deal with Siemens healthcare software - they take the very understandable risk aversion (some of which is a must when it comes to medical equipment) and take it so far that it seriously hampers their ability to keep up with the industry, and (ironically) to maintain a stable product. I think it's their North American software teams that keep them moving forward, otherwise they'd still to this day be selling…
Same for Phillips.
I have mixed feelings about GE as well.
Healthcare tech is definitely hampered by the speed at which software _should_ move forward. The cost of getting FDA approval is crazy, especially for simple changes/security updates.
Re: Tor Browser 10
#68If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.
There's way too much noise in this measurement for it to be seriously meaningful, unless ownership of tor was itself a crime.
Re: Tor Browser 10
#69Earlier quoted context omitted.
The state could easily track who accesses that GitHub page, if they control the ISP.
That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?
Only nuance being that an attacker can draw conclusions about the length of the URL- which won't be very helpful on Github.