Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

91–100 of 156 posts

Re: Security Vulnerability in Tor Browser

#91
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

If you use anything but the Tor Browser on the Tor network you're going to stand out like a flare

Further - many of the privacy enhancements in Firefox, such as fingerprint protection, were adopted from the work on Tor Browser

Re: Security Vulnerability in Tor Browser

#92
post #53

Earlier quoted context omitted.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

With firefox and NoScript, you can whitelist the specific JS you need to make those sites work. You do it one time for a site you know you'll come back to often, and then you're done. In my case for example I whitelisted the scripts at old.reddit.com and redditstatic.com, and leave everything else blocked by default and it works fine for my needs (reading comments).

The fact that there are a handful of very frequently used websites that use JS doesn't make it impossible or overly burdensome to take sensible steps to limit which scripts you allow.

I use amazon in firefox with NoScript without issue, and while amazon gets to run some scripts, none of the JS at amazon-adsystem.com ever runs in my browser.

Youtube wants to load JS from over a dozen different places, but you only need to allow a couple to get videos to play (I personally prefer to just download yt videos to disk and watch them in VLC avoiding that issue entirely)

Re: Security Vulnerability in Tor Browser

#93
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> Firefox is already not one of the most hardened browser engines I'm pretty sure it's one of the most hardened, because the list of major engines that are on that list in first place numbers approximately 3. If you want to claim that blink or webkit are more secure that's a reasonable argument, but just say that.

Yeah, Gecko is one of the most hardened browser engines out there at this point. Fission and the win32k.sys isolation basically bring the general architecture up to par with Chromium. Chromium got those features earlier and hence has more mature implementations of them, so the edge goes to Chromium, but there's not much of a large-scale difference anymore.

There are a few areas in which one browser has the edge over the other in terms of security (e.g. JIT hardening in Chromium's V8 gives it an advantage over Firefox, memory safety of pdf.js in Firefox reduces attack surface over the C++ PDFium in Chromium), but these are nowhere near the old days of "Chrome has a sandbox and Firefox doesn't" or even "Chrome isolates tabs from each other and Firefox doesn't".

Re: Security Vulnerability in Tor Browser

#94
And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM.

Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years.

Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" everything coming in that port. So even if you pop the workstation and have root, you still can't beacon out directly without going through the gateway - you'd have to find an exploit in that bit as well, with only network access. Not impossible, but a lot harder.

And then package all that into Qubes and use it that way, because a disposable Whonix VM set is probably the safest way to browse the web...

And still disable Javascript.

Re: Security Vulnerability in Tor Browser

#95
post #80
post #61

Earlier quoted context omitted.

Most important of all porn doesn’t work

I wouldn't be surprised if pornhub-dl exists. ;-)

I'm sure youtube-dl works, but one google away is https://github.com/Nukesor/pornhub-dl which seems to have site specific features.

Re: Security Vulnerability in Tor Browser

#96

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

[deleted]

Re: Security Vulnerability in Tor Browser

#97
post #82
post #71

Earlier quoted context omitted.

It’s true that most people will likely stick to the most popular websites, but how likely are they to use Tor, especially self-configured outside the Tor browser? I’d bet the people who would do that are much more likely to spend more time outside the most popular websites.

That's a good point: this discussion is in the context of TOR, so that does self-select to some extent. It would make more sense for my argument if I knew what are the top-20 sites used by TOR and their JS requirements. I know people use Tor for Twitter in Turkey, so there's a problem right there!

To be fair, the websites you listed are extremely difficult to use anonymously with or without JS enabled. Most of the popular sites go pretty far out of their way to attach you to an identity that can be used to identify you outside their website.

If you’re using Tor to do your Amazon shopping - I wouldn’t recommend using the same environment to do anything where your anonymity being compromised could put you in danger since you just gave Amazon your credit card and mailing address.

Re: Security Vulnerability in Tor Browser

#98
post #53

Earlier quoted context omitted.

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

With firefox and NoScript, you can whitelist the specific JS you need to make those sites work. You do it one time for a site you know you'll come back to often, and then you're done. In my case for example I whitelisted the scripts at old.reddit.com and redditstatic.com, and leave everything else blocked by default and it works fine for my needs (reading comments). The fact that there are a handful of very frequentl…

If you just want to read comments, libreddit & teddit are fantastic. Libreddit has some onion instances too.

Re: Security Vulnerability in Tor Browser

#99
post #53

Earlier quoted context omitted.

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

This is mostly the fault of lazy and ignorant front end developers.

I doubt that. Monetization is a goal of most of these platforms, which makes the JS and privacy-hostile stuff absolutely intentional and implemented with malice aforethought. There's no reason to require client-side computing for the vast majority of sites, and the remainder are relatively niche webapps. Media-viewing sites aren't niche, and have good UX reasons, but I'd bet the vast majority of use is outside of the web interface anyways (ie. on mobile).

Re: Security Vulnerability in Tor Browser

#100
post #99

Earlier quoted context omitted.

This is mostly the fault of lazy and ignorant front end developers.

I doubt that. Monetization is a goal of most of these platforms, which makes the JS and privacy-hostile stuff absolutely intentional and implemented with malice aforethought. There's no reason to require client-side computing for the vast majority of sites, and the remainder are relatively niche webapps. Media-viewing sites aren't niche, and have good UX reasons, but I'd bet the vast majority of use is outside of the…

[deleted]
Post reply on HN