Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

121–130 of 156 posts

Re: Security Vulnerability in Tor Browser

#121

Earlier quoted context omitted.

True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…

uBlock Origin allows most of those things when it's opted in: https://github.com/gorhill/uBlock/wiki/Dynamic-filtering

Right, and uMatrix is actually not maintained anymore, so this is a better idea than installing uMatrix. :D

Re: Security Vulnerability in Tor Browser

#122
post #52

Earlier quoted context omitted.

Anything with JavaScript leaks. You can fingerprint a computer just based on Canvas.

https://en.wikipedia.org/wiki/Canvas_fingerprinting#Mitigati... > Tor Browser notifies the user of canvas read attempts and provides the option to return blank image data to prevent fingerprinting. > Canvas Defender, a browser add-on, spoofs Canvas fingerprints. > The LibreWolf browser project includes technology to block access to the HTML5 canvas by default It doesn't seem to be the case that anything with javascri…

[deleted]

Re: Security Vulnerability in Tor Browser

#123

Earlier quoted context omitted.

True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…

Is uMatrix being maintained again?

Oops. It isn't, thank you for the notice. So better don't install uMatrix and use uBlock, which has a similar feature. ^^

Re: Security Vulnerability in Tor Browser

#124
post #110

It's a JavaScript engine bug and JS is disabled by default. Still important, but I question whether anyone who enables JS in Tor is worth compromising.

>JS is disabled by default This isn't true any more.

But it still comes with No script built in, so concerned user is left with a choice

Re: Security Vulnerability in Tor Browser

#125
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Terrible advice. If there is one thing I know from ~8 years of following the darkweb markets is that there's nothing worse than stepping outside of the common practice of: use Tor, use Tails, use Whonix

If you read the the DOJ indictments of Tor users what they have in common is that they stepped out of those bounds

There _was_ a period where Firefox (hence: the Tor Browser) was terrible and 0days were cheap (which is why most of the darkweb switched up to using VM's behing their browsers), but those days are over[0]

I can't recall a recent indictment where the adversary in the USA broke Tor Browser. If you are a dissident in Turkey, Syria or Russia .. you're more than safe using the Tor Browser bundle.

The NSA aren't burning 0days in Firefox and VM's on 99.9% of Tor users - if you're in that other 0.01% then good luck to you[1], your threat model is very different to those looking to obfuscate from oppressive regimes.

As somebody with an infosec background, this is where I feel the industry fails in the sense of "perfect is the enemy of good" - there is no such thing as perfect (I bet most who preach against Tor Browser wouldn't be able to come up with a model that is) - the practical advice today is, and always has been, use Tor (Browser), use Tails, use Whonix

[0] I used ungoogled-chromium in that period, until an DNM administrator during a chat told me he could spot me in his acccess logs

Re: Security Vulnerability in Tor Browser

#127
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

So what are people supposed to use? Chrome? Rofl.

Re: Security Vulnerability in Tor Browser

#128

Earlier quoted context omitted.

> YouTube, Twitter and Instagram We clearly have very different lifestyles and values. For me that's the dank basement of the internet,

That's perfectly fine. It however does not matter for the large majority of people who use those top 100 or even top 100,000 websites or even top 1,000,000 websites, and do not have the education, skill or time to learn about all the alternatives, if there are even any. It doesn't matter for the people living under repressive regimes who want to inform themselves on foreign news sites, access foreign NGO sites, or ev…

> and do not have the education, skill or time to learn about all the alternatives,

With respect, this is hacker news. When I converse with people here I do so with a different expectation of intellect and curiosity. There are voices here who excuse technological abuses by appeal to the ignorance of "the masses" - completely missing that there is a different spirit going on in the sub-text of innovation and entrepreneurialism here. If, as you claim, the majority are using defective technologies, then that is a bigger problem, not something to be celebrated. They deserve better and it's our job to help them get that.

Re: Security Vulnerability in Tor Browser

#129
> This vulnerability doesn’t break the anonymity and encryption of Tor connections.

> The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

> For example, after you visit a malicious website, an attacker controlling this website might access the password or other sensitive information that you send to other websites afterwards during the same Tails session.

This makes it relatively tame.

Re: Security Vulnerability in Tor Browser

#130

Earlier quoted context omitted.

For any such agency, a handful of Tor nodes gives your own agents a useful secure channel. An overwhelming majority of nodes would give you good insight into what other users are doing, but it's very hard to get such a majority since of course all your competitors think the same. Putting in place a handful of nodes to benefit your own agents is very possible, so that's what you do.

You can just hack into existing nodes. There are few enough nodes that accessing a large proportion of them is easily within the budget of a state security agency.

And so can all the other agencies, same consequences.
Post reply on HN