Earlier quoted context omitted.
> I use brave and browse with JS disabled by default. That’s hilarious given the founder of Brave (Brendan Eich) literally invented JavaScript.
I mean I'm not arguing JavaScript's utility. Its a tool with a time and place for proper usage.
Security Vulnerability in Tor Browser
131–140 of 156 posts
Re: Security Vulnerability in Tor Browser
#132Earlier quoted context omitted.
Apple's and Oranges; tails is designed for storing sensitive files amongst many other features whereas Whonix is a live CD that doesn't offer storage and is focused only on secure browsing.
I think you're backwards. Tails is the LiveCD with a browser (that can beacon straight out). Whonix is the VM based system. I think it's capable of more than just browsing, but I use it as the "secure browser" in Qubes as a disposable VM, because it just automatically does the right stuff with the gateway VM and such.
The most obvious concern is the RAM-usage (because of tmpfs and each VM having allocated RAM on top of that) and if disk-usage between the gateway and workstation images could be de-duplicated to save space in the live-image.
Re: Security Vulnerability in Tor Browser
#133A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
Re: Security Vulnerability in Tor Browser
#134Earlier quoted context omitted.
Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
Re: Security Vulnerability in Tor Browser
#135Re: Security Vulnerability in Tor Browser
#136Earlier quoted context omitted.
Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.
Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.
Re: Security Vulnerability in Tor Browser
#137Earlier quoted context omitted.
>JS is disabled by default This isn't true any more.
I wonder why not. It seems like that's the cause of most of these.
Re: Security Vulnerability in Tor Browser
#138Since it's not directly mentioned in the submitted link: Fixed in: Firefox 100.0.2, Firefox ESR 91.9.1, Firefox for Android 100.3, Thunderbird 91.9.1 https://www.mozilla.org/en-US/security/advisories/mfsa2022-1...
Re: Security Vulnerability in Tor Browser
#139Earlier quoted context omitted.
Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
Although the two patches have now been public for ~6 days at this point.
Re: Security Vulnerability in Tor Browser
#140Earlier quoted context omitted.
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
Who are "we" here?