Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

81–90 of 156 posts

Re: Security Vulnerability in Tor Browser

#81

Earlier quoted context omitted.

Nonsense. I was hired freelance to create a web forum for someone who wanted it to run on Tor and making everything work without JavaScript was the top requirement. The guy wanted an option to enable JS for those who were willing to trust it, but it was disabled by default and I designed all parts of the forum to run without JS.

No one said it's possible to design a site without JavaScript, just that for the vast majority of the internet, including sites user's rely on, it's unusable without it enabled.

I was replying to a poster claiming JS is needed "even within tor"

Re: Security Vulnerability in Tor Browser

#82
post #71
post #70

Earlier quoted context omitted.

> If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?” No, but the reponse is more like: I only listen to Indie, Billboard isn't music. The vast majority of internet traffic, e.g., the most popular sites, mostly require JS. If you only visit obscure indie-rock sites, then fine, but we're talking about the masses, not the small niche exceptions.

It’s true that most people will likely stick to the most popular websites, but how likely are they to use Tor, especially self-configured outside the Tor browser? I’d bet the people who would do that are much more likely to spend more time outside the most popular websites.

That's a good point: this discussion is in the context of TOR, so that does self-select to some extent. It would make more sense for my argument if I knew what are the top-20 sites used by TOR and their JS requirements. I know people use Tor for Twitter in Turkey, so there's a problem right there!

Re: Security Vulnerability in Tor Browser

#83
post #4
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

What about the Brave browser in a private window? That used Tor but theoretically also has some added protection because of the browser. I’d love to hear your thoughts.

Brave provides far less protection than Tor Browser

Re: Security Vulnerability in Tor Browser

#84

These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.

Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."

Citation needed.

Also, they've specifically called that out in the advisory when they're aware of that being the case. See the last out-of-band security update they released for example:

https://www.mozilla.org/en-US/security/advisories/mfsa2022-0...

Re: Security Vulnerability in Tor Browser

#85
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to target.

Yeah, I was never a fan of their position on this. It's basically "let all websites track you and push ads at you all day long, but we've customized 50,000 settings so that you should look identical to everyone else using the Tor Browser" where as I don't trust that they've managed to cover every possible means to fingerprint a specific user/browser install.

Instead, I prefer to limit the amount of data websites can collect about me in the first place. I harden the browser as best as I can, block all active content by default, block all the ads I can, and I randomize a few little details (like screen and window resolution or user agent) which in total makes me feel better about my chances of avoiding being fingerprinted across sites and prevents most of the vulnerabilities that would cause a person to get compromised just by browsing to a website.

I still love the Tor Browser project though because they're great at spotting things introduced into firefox that would make it easier for you to be fingerprinted, and while I prefer to not give data, or give random data I do understand their reasoning for what they do.

Re: Security Vulnerability in Tor Browser

#86
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

No post body was provided.

Re: Security Vulnerability in Tor Browser

#87

These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.

Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."

We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory.

Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.

Re: Security Vulnerability in Tor Browser

#88
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> Firefox is already not one of the most hardened browser engines

I'm pretty sure it's one of the most hardened, because the list of major engines that are on that list in first place numbers approximately 3. If you want to claim that blink or webkit are more secure that's a reasonable argument, but just say that.

Re: Security Vulnerability in Tor Browser

#89
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

> Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Nope. I do, and I'm not lying. I started because it was required for my work and I just got used to it and now do it everywhere. The internet with NoScript is the best way to browse 90% of the time.

Even today, the vast majority of the sites I visit (including the one linked to in this post) work just fine (for what I want) without JS. That means the text I clicked to read is displayed and is readable, the images I clicked to view are displayed, etc. Other parts of the site may not work (menus for example), but if I'm just following a link to an article I want to read and I can read it without javascript why do I care if the menus on the site are broken or if i can't leave a comment?

For the sites I regularly visit that really do need JS I enable only the JS files needed to accomplish the things that I want and that's only necessary to do one time for each site. NoScript remembers my preferences on each domain.

For those rare occasions I actually need to enable JS to get the functionality I want on a site I'm visiting only once I can just temp allow only the scripts I need to get the content I want and the next time I close my browser (or clear those temp permissions by hand) that site is no longer allowed to use JS. Ill admit that for some random sites I wasn't that interested in in the first place, there are times where I'll still just close the tab and move on.

I really don't understand why people think it's so hard to use the web with NoScript. Overall, websites load much faster and look cleaner without JS and I'm much much more secure. Most of the time, it's really not a problem.

I will say, I do have an add-on called NukeAnything that lets you right click and remove whatever you want from webpages (only until the page is reloaded) and that occasionally does help fix some issues for sites that don't handle the lack of JS gracefully. If somebody's poorly designed JS heavy menu is spewed all over the page and covering the content I want to see, I can just right click and remove it. Same with obnoxious "we use cookies" banners that I refuse to interact with.

Honesty it's the other things I've done to harden the browser (disabling redirects, service workers, WebGL, WebRTC, Wasm, location sharing, DRM, plugins, cookies, web storage, etc.) that cause the most problems with sites, and I do keep another unhardened browser around (brave atm) to handle the sites I absolutely need to access that depend on that junk.

Re: Security Vulnerability in Tor Browser

#90
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

[deleted]
Post reply on HN