Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

11–20 of 156 posts

Re: Security Vulnerability in Tor Browser

#11
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Hm, this is probably a joke, but I do vast majority of my browsing without javascript (noscript+umatrix or w3m). It's especially pleasant on news sites which are crammed with junk the few times I carelessly open them on the JS-only profile I reserve for Google's app suite.

Re: Security Vulnerability in Tor Browser

#12
post #4

Earlier quoted context omitted.

What about the Brave browser in a private window? That used Tor but theoretically also has some added protection because of the browser. I’d love to hear your thoughts.

Anything with JavaScript leaks. You can fingerprint a computer just based on Canvas.

[deleted]

Re: Security Vulnerability in Tor Browser

#13
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I use brave and browse with JS disabled by default. Some sites don't work, some do. I regularly decide the info I'm looking for can be found somewhere else and back out of a broken site because of it. Some sites I enable and proceed with.

Re: Security Vulnerability in Tor Browser

#14
post #3
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

Re: Security Vulnerability in Tor Browser

#15
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time.

Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.

Re: Security Vulnerability in Tor Browser

#16
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

[deleted]

Re: Security Vulnerability in Tor Browser

#17
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

The more unique your browser (i.e., the more you deviate from the Tor Browser based on Firefox ESR), the more unique and therefore fingerprintable you are.

The Tor browser is 100% unique, it makes no attempt to pretend to be anything other than itself. Your anonymity set is other Tor users, not other Firefox users.

Re: Security Vulnerability in Tor Browser

#18
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

Isn't this taking demand into account? Exploits for Chrome are worth more because more people want them.

Re: Security Vulnerability in Tor Browser

#19
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

This chart does not support the referred claim at all. Payouts are not only linked to the browser's hardening, but also to the amount of affected users. Given Firefox's engine low market share, it's not very surprising that payouts for its vulnerabilities is lower than for Chrome.

Re: Security Vulnerability in Tor Browser

#20
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

That's not a reliable source or claim to support the argument claimed here. That's more aligned with market demand, and whatever that company wants to pay out.
Post reply on HN