Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?
Tor Browser 10
81–90 of 106 posts
Re: Tor Browser 10
#82Re: Tor Browser 10
#83Re: Tor Browser 10
#84Earlier quoted context omitted.
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
Obviously your web browser doesn't know if this is "just" some Wix brochureware site where you don't actually care about security or if it's a bank or your webmail or the passport office. So to keep browser users safe we need to deliver the security they expect all the time. The rule has to be consistent, either the rule is "TLS 1.0 is no good, stop that" or it's "TLS 1.0 is fine, First Bank of Springfield can keep r…
But what harm does allowing 1.0 if you want to read a static HTML web page from 2001 about the Cowboy Bebop anime series?
Re: Tor Browser 10
#85Earlier quoted context omitted.
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
My understanding is that the general argument is that if we all require security for comedy browsing, the traffic of the people who require better security is better because it’s less conspicuous? See also declaring your personal pronouns as someone who thinks they will never be misgendered, or using Tor for normal browsing
People who really care can enable 1.2+ on their servers and the browser will use it, but someone who just has a site up 'for fun' could be cut off.
In some ways it motivates people to not even bother with HTTPS because it now because higher maintenance to keep up with all the settings. This could actually encourage just leaving HTTP, which could be worse.
Re: Tor Browser 10
#86Earlier quoted context omitted.
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
The reason is that encrypted websites are a bit harder to hack and inject malicious code into. In particular MITM attacks are much harder to pull off - such as those by airport/mall free wifis. Using the latest version of TLS makes us safe from hacking.
What how does disabling 1.0 specifically do?
Re: Tor Browser 10
#87Earlier quoted context omitted.
Maybe in the west that'd be true- since we can freely trade information over the public internet, TOR doesn't have much utility. Let's say you're in a more totalitarian government that censors more information- TOR might look like a practical solution there, and might have people using it for more practical purposes.
> since we can freely trade information over the public internet No we can’t.
Re: Tor Browser 10
#88If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.
Re: Tor Browser 10
#89Earlier quoted context omitted.
> since we can freely trade information over the public internet No we can’t.
Don't be pedantic, you're doing it right now.
Re: Tor Browser 10
#90If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.
If your adversary was a state, they probably control most of the exit nodes you connect to.
US or someone from 5 eyes? Yes for sure!
Algeria? You're probably safer