Just a heads up for Android users: The Play store version is a few releases out of date, to get current use FDroid and make sure Guardian Project repo is selected (it's not by default). Question for the Mozillans/Googlers: How is it that Firefox Nightly are fast-track released multiple times a day to Play Store but stable Tor Browser updates are stuck for weeks? Is there a 'skip the review' option for nightly release…
Security Vulnerability in Tor Browser
141–150 of 156 posts
Re: Security Vulnerability in Tor Browser
#142And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…
as far as I am aware Tails use IP tables to force all network connections through tor. You would require an escape from the browser and then a privilege escalation to get around this.
Re: Security Vulnerability in Tor Browser
#143A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
Re: Security Vulnerability in Tor Browser
#144A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.
Tor doesn't defend against a global adversary like a three-letter agency with capabilities to monitor network traffic and latency globally, panopticon-style. This is explained plainly in the Tor design spec.
Re: Security Vulnerability in Tor Browser
#145And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…
Re: Security Vulnerability in Tor Browser
#146Earlier quoted context omitted.
No one said it's possible to design a site without JavaScript, just that for the vast majority of the internet, including sites user's rely on, it's unusable without it enabled.
I was replying to a poster claiming JS is needed "even within tor"
Re: Security Vulnerability in Tor Browser
#147And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…
> Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP as far as I am aware Tails use IP tables to force all network connections through tor. You would require an escape from the browser and then a privilege escalation to get around this.
Re: Security Vulnerability in Tor Browser
#148Re: Security Vulnerability in Tor Browser
#149Earlier quoted context omitted.
Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
Re: Security Vulnerability in Tor Browser
#150Earlier quoted context omitted.
You can just hack into existing nodes. There are few enough nodes that accessing a large proportion of them is easily within the budget of a state security agency.
And so can all the other agencies, same consequences.