Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

31–40 of 156 posts

Re: Security Vulnerability in Tor Browser

#31
post #15

Earlier quoted context omitted.

For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time. Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.

Which major sites still work just fine without JS? Which ones do you have to avoid?

I mean, I don't have JS enabled for HN, although I don't know if you count that as "major".

But I'm not really keeping track, honestly. If I come across a website that isn't working with JS, I make the decision "is this worth allowing JS?". Sometimes the answer is yes, sometimes it is no. Often it means enabling the first-party domain to run JS but no others.

Conveniently, some of the paywalls on various news sites don't work with JS, but you can still read the article. So that'd be some of them that arguably work better without JS.

I don't use Tor for everyday browsing, only for the times I need/want it. In those cases, the equation always equals "no JS" -- that's the reason Im using Tor in the first place.

It's a balancing act, as all security always is.

Re: Security Vulnerability in Tor Browser

#32
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

No post body was provided.

Re: Security Vulnerability in Tor Browser

#33
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Ed Snowden said to turn off the fucking scripts.

So I did.

Most of the web works fine.

Re: Security Vulnerability in Tor Browser

#34
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> I'm ambivalent about Tor, but if you're using Tor, don't use the Browser Bundle.

What do you suggest?

Re: Security Vulnerability in Tor Browser

#35
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Actually some DNMs heavily encourage you or even force you to turn off Javascript before they let you log in/interact with the website. So while I think that JS is probably necessary for most of the regular web, that's not really the case here. It's only true if you use Tor to browse the clear net, which is probably not recommended anyways.

Re: Security Vulnerability in Tor Browser

#36
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

If a hidden service doesn't work without JS it's probably run by feds.

Re: Security Vulnerability in Tor Browser

#37
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Or use Whonix on Qubes OS, relying on hardware virtualization to protect you.

Re: Security Vulnerability in Tor Browser

#38
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I regularly browse internet via Lynx, which does not support JavaScript. A lot of sites appear to be actively hostile toward Lynx but there are some sites that are very functional and even enjoyable.

Re: Security Vulnerability in Tor Browser

#39

Earlier quoted context omitted.

The Tor browser is 100% unique, it makes no attempt to pretend to be anything other than itself. Your anonymity set is other Tor users, not other Firefox users.

The fact that they can detect that you're using the TOR browser configuration isn't that shocking when they also see that you are coming out of a TOR exit node, or the site you are loading is an Onion site. The anonymity comes from looking like every other person who downloaded Tails.

Yes.

Re: Security Vulnerability in Tor Browser

#40
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

You say that on a website where you don't need JavaScript either.
Post reply on HN