Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

21–30 of 156 posts

Re: Security Vulnerability in Tor Browser

#21
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

Firefox, Safari and Edge being in the same price bracket and less than Google Chrome is not related to their relative security, but their marketshare being a lot less.

Re: Security Vulnerability in Tor Browser

#22

Earlier quoted context omitted.

The more unique your browser (i.e., the more you deviate from the Tor Browser based on Firefox ESR), the more unique and therefore fingerprintable you are.

The Tor browser is 100% unique, it makes no attempt to pretend to be anything other than itself. Your anonymity set is other Tor users, not other Firefox users.

The fact that they can detect that you're using the TOR browser configuration isn't that shocking when they also see that you are coming out of a TOR exit node, or the site you are loading is an Onion site. The anonymity comes from looking like every other person who downloaded Tails.

Re: Security Vulnerability in Tor Browser

#23
post #15

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time. Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.

[deleted]

Re: Security Vulnerability in Tor Browser

#24
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

using just this image it would imply chrome was the least secure browser, but I'm not sure I can really infer much at all from this image other than bugs have been found in all browsers.

Was this intended on showing firefox is the least hardened browser somehow?

Re: Security Vulnerability in Tor Browser

#25
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D

But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains have to be whitelisted to make it fully functual if they aren't. Or actually whitelist the domain for every website on the first visit. Tedious, but you only need to do it once per site.

Doing so at least protects a bit against malicious iframes or injected scripts from 3rd party domains, doesn't it? :)

[1] https://addons.mozilla.org/de/firefox/addon/umatrix/

Re: Security Vulnerability in Tor Browser

#26
post #15

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time. Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.

Which major sites still work just fine without JS? Which ones do you have to avoid?

Re: Security Vulnerability in Tor Browser

#27
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

Re: Security Vulnerability in Tor Browser

#28
post #3

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines Citations and sources for this claim?

https://zerodium.com/images/zerodium_prices.png

tar RCE, linux & macos LPE valued less than adobe pdf/cpanel? Interesting.

If you look at number of CVEs[1] Chrome is above Firefox, but I admit that especially given the market share that doesn't say much. I wish they had some score weighted rank.

1. https://www.cvedetails.com/top-50-products.php?year=2022

Re: Security Vulnerability in Tor Browser

#29
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

> Lets be real, you need to be using JavaScript for the internet to be functional,

Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security environment I've worked in recently don't allow js (although admittedly the sites we are allowed to access from there are limited).

Re: Security Vulnerability in Tor Browser

#30
post #27
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

Where did Tor come from, again?
Post reply on HN