Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

141–150 of 156 posts

Re: Security Vulnerability in Tor Browser

#141

Just a heads up for Android users: The Play store version is a few releases out of date, to get current use FDroid and make sure Guardian Project repo is selected (it's not by default). Question for the Mozillans/Googlers: How is it that Firefox Nightly are fast-track released multiple times a day to Play Store but stable Tor Browser updates are stuck for weeks? Is there a 'skip the review' option for nightly release…

It may not be in that repo for much longer: https://gitlab.com/guardianproject/fdroid-metadata/-/issues/...

Re: Security Vulnerability in Tor Browser

#142
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

> Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP

as far as I am aware Tails use IP tables to force all network connections through tor. You would require an escape from the browser and then a privilege escalation to get around this.

Re: Security Vulnerability in Tor Browser

#143
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Wow, what incredible FUD to be reading. "Least safe"? Compared to what? Can you cite any objective sources to back up such extraordinary claims?

Re: Security Vulnerability in Tor Browser

#144
post #27
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

> I've always assumed that Tor was a top target for 3 letter agencies

Tor doesn't defend against a global adversary like a three-letter agency with capabilities to monitor network traffic and latency globally, panopticon-style. This is explained plainly in the Tor design spec.

Re: Security Vulnerability in Tor Browser

#145
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

Modern browsers should really be treated like operating systems because they have so many capabilities and are so complex. I try to run all of mine in separate virtual machines on Debian Linux using virt-manager. Additionally, they're sandboxed with firejail (looking at moving to bubblewrap) and apparmor. I'm less concerned with my IP address and more with a website being able to access random files on my computer.

Re: Security Vulnerability in Tor Browser

#146

Earlier quoted context omitted.

No one said it's possible to design a site without JavaScript, just that for the vast majority of the internet, including sites user's rely on, it's unusable without it enabled.

I was replying to a poster claiming JS is needed "even within tor"

I understand. And if anyone wants to use one of the sites that requires JavaScript within tor, then JS is needed within tor for them. Just because some random forum was developed to work without JS doesn't help if they want to use a site that wasn't developed to work without JS.

Re: Security Vulnerability in Tor Browser

#147
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

> Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP as far as I am aware Tails use IP tables to force all network connections through tor. You would require an escape from the browser and then a privilege escalation to get around this.

Local privilege escalations are about a dime a dozen. If you're executing arbitrary code, root isn't a far jump.

Re: Security Vulnerability in Tor Browser

#149

Earlier quoted context omitted.

Perhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."

We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.

Tails has updated their advisory to remove that statement: https://tails.boum.org/security/prototype_pollution/index.en...

Re: Security Vulnerability in Tor Browser

#150

Earlier quoted context omitted.

You can just hack into existing nodes. There are few enough nodes that accessing a large proportion of them is easily within the budget of a state security agency.

And so can all the other agencies, same consequences.

I don't understand: How does it protect end-user privacy if multiple state agencies, rather than just one, can access their identity and metadata?
Post reply on HN