Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

51–60 of 156 posts

Re: Security Vulnerability in Tor Browser

#51
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I just thought no js just made the internet work better sometimes, and now you're telling me I can be smug about it too?

Now how much would you pay? :)

Re: Security Vulnerability in Tor Browser

#52
post #4

Earlier quoted context omitted.

What about the Brave browser in a private window? That used Tor but theoretically also has some added protection because of the browser. I’d love to hear your thoughts.

Anything with JavaScript leaks. You can fingerprint a computer just based on Canvas.

https://en.wikipedia.org/wiki/Canvas_fingerprinting#Mitigati...

> Tor Browser notifies the user of canvas read attempts and provides the option to return blank image data to prevent fingerprinting.

> Canvas Defender, a browser add-on, spoofs Canvas fingerprints.

> The LibreWolf browser project includes technology to block access to the HTML5 canvas by default

It doesn't seem to be the case that anything with javascript must leak canvas fingerprints.

Are you saying that Brave is unsafe because it has JS like every other browser on the planet or because it doesn't resist canvas fingerprinting specifically?

Re: Security Vulnerability in Tor Browser

#53

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

Wow, talk about proving the parent's point.

I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft).

YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login.

I think you are incorrect with your "nonsense" judgement, as this top-10 sampling is pretty sensible.

EDIT: `ewzimm` makes a good criticism of my analysis: these aren't necessarily the top sites used by Tor. However, how many Tor users (in authoritarian countries or just regular users) don't use it to visit the banned sites on the Top-100 list?

Re: Security Vulnerability in Tor Browser

#54
post #30
post #27

Earlier quoted context omitted.

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

Where did Tor come from, again?

Created by the US Navy and currently majorly funded by the US Department of State, for those unaware.

Re: Security Vulnerability in Tor Browser

#55
post #4
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

What about the Brave browser in a private window? That used Tor but theoretically also has some added protection because of the browser. I’d love to hear your thoughts.

Can't tell why this was downvoted, it sounds like a legitimate question and on-topic given that this is an alternative to the TBB which GP was recommending to avoid.

Re: Security Vulnerability in Tor Browser

#56
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

This is deeply misleading and based on old data.

> A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project.

Tor Browser ships updates as soon as new ESR versions come out.

> Firefox is already not one of the most hardened browser engines.

That might've been true in the past, it's hard to argue for it now.

> Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to target.

The overwhelming majority of exit traffic now is using HTTPS and Tor Browser ships with HTTPS Everywhere to avoid SSL Striping attacks (in fact the next version of the Tor Browser will have the HTTPS-Only mode enabled by default, it's already being tested in the alpha release), so how will those evil exit node burn those exploits?

> I'm ambivalent about Tor, but if you're using Tor, don't use the Browser Bundle.

First off, the "Tor Browser Bundle" is a deprecated name. If you're not using the Tor Browser you're making yourself both insecure (it ships with a smaller attack surface, no WebGL for example) and fingerprintable defeating thus the full privacy advantages of the Tor Browser. There is simply no other alternative.

You can read the Tor Browser design documentation (though old) to get a rough sketch of what it's trying--and what it's not trying--to achieve: https://2019.www.torproject.org/projects/torbrowser/design/

Further reading in case you think VPNs are the solution: https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browse...

Re: Security Vulnerability in Tor Browser

#57
post #50
post #30

Earlier quoted context omitted.

Where did Tor come from, again?

"Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." https://news.ycombinator.com/newsguidelines.html (Not sure a rhetorical question to make some vague accusation counts as a substantive comment)

It's not a "vague accusation", onion routing was developed by the US Naval Research Academy ("NRL", a 3 letter government agency).

See https://en.wikipedia.org/wiki/Tor_(network)#History for more detail.

Re: Security Vulnerability in Tor Browser

#58
post #53

Earlier quoted context omitted.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

There are alternatives that will work without JS though.. obviously the majority of people use it by default, but if you don't want to have it enabled there is plenty of other options.

Re: Security Vulnerability in Tor Browser

#59
post #53

Earlier quoted context omitted.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?”

I also prefer w3m and find most of the web much better as text only, switching over to another browser when I want video or some other JS feature. Or I can use something like youtube-dl to fetch a video. And there’s much more out there than the top 100 websites.

Re: Security Vulnerability in Tor Browser

#60
post #57
post #50

Earlier quoted context omitted.

"Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." https://news.ycombinator.com/newsguidelines.html (Not sure a rhetorical question to make some vague accusation counts as a substantive comment)

It's not a "vague accusation", onion routing was developed by the US Naval Research Academy ("NRL", a 3 letter government agency). See https://en.wikipedia.org/wiki/Tor_(network)#History for more detail.

The vague accusation is that because "onion routing"[1] has roots in the military, it must have a backdoor that we haven't uncovered in decades. If the person had posted this Wikipedia link with the info you mentioned, for example, I wouldn't have thought it unsubstantial per the guidelines (even if the claim/accusation itself is unsubstantiated by the evidence, that's a difference of opinion and not a guidelines thing).

[1] Not the cryptography, not even the code implementation, but just the general concept: having a message packed in several layers of encryption such that intermediate routers don't know the contents. https://en.wikipedia.org/wiki/Onion_routing

Post reply on HN