Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

131–140 of 156 posts

Re: Security Vulnerability in Tor Browser

#131

Earlier quoted context omitted.

> I use brave and browse with JS disabled by default. That’s hilarious given the founder of Brave (Brendan Eich) literally invented JavaScript.

I mean I'm not arguing JavaScript's utility. Its a tool with a time and place for proper usage.

I'm not arguing, it's just amusing / ironic.

Re: Security Vulnerability in Tor Browser

#132
post #112
post #108

Earlier quoted context omitted.

Apple's and Oranges; tails is designed for storing sensitive files amongst many other features whereas Whonix is a live CD that doesn't offer storage and is focused only on secure browsing.

I think you're backwards. Tails is the LiveCD with a browser (that can beacon straight out). Whonix is the VM based system. I think it's capable of more than just browsing, but I use it as the "secure browser" in Qubes as a disposable VM, because it just automatically does the right stuff with the gateway VM and such.

It is an complex idea but in theory one could produce a live-image that spins up the Whonix 'gateway' and 'workstation' virtual-machines into RAM. Boom, probably better than Tails.

The most obvious concern is the RAM-usage (because of tmpfs and each VM having allocated RAM on top of that) and if disk-usage between the gateway and workstation images could be de-duplicated to save space in the live-image.

Re: Security Vulnerability in Tor Browser

#133
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Anyone know how much the Tor Browser 'Safer' security-level mitigates real exploits? Among several things it disables the JavaScript JIT functionality which has been a known mechanism for exploits.

Re: Security Vulnerability in Tor Browser

#134

Earlier quoted context omitted.

Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."

We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.

Who are "we" here?

Re: Security Vulnerability in Tor Browser

#135
post #110

It's a JavaScript engine bug and JS is disabled by default. Still important, but I question whether anyone who enables JS in Tor is worth compromising.

>JS is disabled by default This isn't true any more.

I wonder why not. It seems like that's the cause of most of these.

Re: Security Vulnerability in Tor Browser

#136
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

I use a text-only browser that has no suport for JS or CSS. I use it to read and comment on HN and to read every website submitted to HN. I have no idea what these websites look like in graphical browsers, but I can read 100% of them. I do not see fonts, images, layout, etc. I just read text and download files. For searching and downloading video from YouTube, I do not even use a text-only browser. I do everything from the command line. The only time I use a graphical browser that runs Javascript is for online shopping, banking and so forth. That is a very small percentage of overall internet use for me.

Re: Security Vulnerability in Tor Browser

#137
post #135
post #110

Earlier quoted context omitted.

>JS is disabled by default This isn't true any more.

I wonder why not. It seems like that's the cause of most of these.

Because the web isn't practically browsable without js, so rather than users fiddling with noscript and ending up disabling a ton of security features, instead they just turned js on.

Re: Security Vulnerability in Tor Browser

#138
post #126

Since it's not directly mentioned in the submitted link: Fixed in: Firefox 100.0.2, Firefox ESR 91.9.1, Firefox for Android 100.3, Thunderbird 91.9.1 https://www.mozilla.org/en-US/security/advisories/mfsa2022-1...

I maintain a table with release history for Android builds: https://divestos.org/misc/ffa-dates.txt

Re: Security Vulnerability in Tor Browser

#139

Earlier quoted context omitted.

Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."

We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.

Perhaps Tails copy/pasted the page from an older notice?

Although the two patches have now been public for ~6 days at this point.

Re: Security Vulnerability in Tor Browser

#140

Earlier quoted context omitted.

We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.

Who are "we" here?

Judging by the post and the user's post history, almost certainly 'we' refers to Mozilla.
Post reply on HN