Earlier quoted context omitted.
If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?” I also prefer w3m and find most of the web much better as text only, switching over to another browser when I want video or some other JS feature. Or I can use something like youtube-dl to fetch a video. And there’s much more out there than the top 100 websites.
> If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?” No, but the reponse is more like: I only listen to Indie, Billboard isn't music. The vast majority of internet traffic, e.g., the most popular sites, mostly require JS. If you only visit obscure indie-rock sites, then fine, but we're talking about the masses, not the small niche exceptions.
Security Vulnerability in Tor Browser
71–80 of 156 posts
Re: Security Vulnerability in Tor Browser
#72Earlier quoted context omitted.
Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…
> YouTube, Twitter and Instagram We clearly have very different lifestyles and values. For me that's the dank basement of the internet,
It however does not matter for the large majority of people who use those top 100 or even top 100,000 websites or even top 1,000,000 websites, and do not have the education, skill or time to learn about all the alternatives, if there are even any. It doesn't matter for the people living under repressive regimes who want to inform themselves on foreign news sites, access foreign NGO sites, or even watch things on youtube or look and/or participate in social media. And so on...
A large part of the web is not functional without js, and just because you chose to not use that part of the web (much) doesn't invalidate that point.
So I'd politely suggest you may tone it down a little when it comes to calling "nonsense".
Re: Security Vulnerability in Tor Browser
#73A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
They also still enable JavaScript by default, which is time and time again the source of these vulnerabilities.
Concerns about Javascript are rooted in two avenues:
1. Fingerprinting concerns.
2. Zero-day exploits against Firefox.
The reason we feel that leaving Javascript enabled trumps these concerns is:
1. We want enough people to actually use Tor Browser such that it becomes less interesting that you're a Tor user. We have plenty of academic research and mathematical proofs that tell us quite clearly that the more people use Tor, the better the privacy, anonymity, and traffic analysis resistance properties will become.
In fact, my personal goal is to grab the entire "Do Not Track" userbase from Mozilla. That userbase is probably well in excess of 12.5 million people: http://www.techworld.com.au/article/400248/
I do not believe we can capture that userbase if we ship a JS-disabled-by-default browser.
2. Exploitable vulnerabilities can be anywhere in the browser, not just in the JS interpreter. We disable and/or click-to-play the known major vectors, but the best solutions here are providing bug bounties (Mozilla does this; we should too, if we had any money) and sandboxing systems (Seatbelt, AppArmor, SELinux).
[1] : https://lists.torproject.org/pipermail/tor-talk/2012-May/024...
Re: Security Vulnerability in Tor Browser
#74Re: Security Vulnerability in Tor Browser
#75A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.
Re: Security Vulnerability in Tor Browser
#76These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.
Re: Security Vulnerability in Tor Browser
#77These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.
"Mozilla is aware of websites exploiting this vulnerability already."
Re: Security Vulnerability in Tor Browser
#78Earlier quoted context omitted.
Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.
> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…
Re: Security Vulnerability in Tor Browser
#79Earlier quoted context omitted.
> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…
Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…
Re: Security Vulnerability in Tor Browser
#80Earlier quoted context omitted.
For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time. Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.
Most important of all porn doesn’t work