Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

41–50 of 156 posts

Re: Security Vulnerability in Tor Browser

#41

Earlier quoted context omitted.

The more unique your browser (i.e., the more you deviate from the Tor Browser based on Firefox ESR), the more unique and therefore fingerprintable you are.

The Tor browser is 100% unique, it makes no attempt to pretend to be anything other than itself. Your anonymity set is other Tor users, not other Firefox users.

This doesn't contradict anything I said. If you believe you are contradicting what I said, perhaps you could rephrase what you thought my comment was communicating. Otherwise, I will interpret the intent of your reply as adding supporting details.

Re: Security Vulnerability in Tor Browser

#42
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

I no longer use Tor either (unless I have to for work projects such as remote pentesting).

What is you opinion of Landlock (Linux kernel 5.13 and newer)? If we wrap vanilla FireFox in LandLock, proxy that to tor and use Apparmor/Tomoyo to further limit what FireFox could do (when it gets compromised) then I think that would be a much safer approach than using the Tor Browser Bundle.

Here's a landlock wrapper (in Go) for FireFox: https://github.com/62726164/misc/blob/main/go/landlock/firef...

Also, I've only ever been able to get Tomoyo to work as MAC for FireFox. SELinux and Apparmor were too difficult.

Re: Security Vulnerability in Tor Browser

#43

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…

uBlock Origin allows most of those things when it's opted in: https://github.com/gorhill/uBlock/wiki/Dynamic-filtering

Re: Security Vulnerability in Tor Browser

#44
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Pffft. Even JavaScript is now letting script kiddies make persistent JS things of dubious nature, now that you can write JS to store files.

Re: Security Vulnerability in Tor Browser

#45
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

[deleted]

Re: Security Vulnerability in Tor Browser

#46

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…

Is uMatrix being maintained again?

Re: Security Vulnerability in Tor Browser

#47
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

> Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor

That's incorrect, especially the last part. Dark services work very hard to design their websites to work without JS, due to these exact vulnerabilities. Nobody on the dark web trusts JS, at all.

Re: Security Vulnerability in Tor Browser

#48

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I use brave and browse with JS disabled by default. Some sites don't work, some do. I regularly decide the info I'm looking for can be found somewhere else and back out of a broken site because of it. Some sites I enable and proceed with.

[deleted]

Re: Security Vulnerability in Tor Browser

#49

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I use brave and browse with JS disabled by default. Some sites don't work, some do. I regularly decide the info I'm looking for can be found somewhere else and back out of a broken site because of it. Some sites I enable and proceed with.

> I use brave and browse with JS disabled by default.

That’s hilarious given the founder of Brave (Brendan Eich) literally invented JavaScript.

Re: Security Vulnerability in Tor Browser

#50
post #30
post #27

Earlier quoted context omitted.

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

Where did Tor come from, again?

"Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." https://news.ycombinator.com/newsguidelines.html (Not sure a rhetorical question to make some vague accusation counts as a substantive comment)
Post reply on HN