Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

151–156 of 156 posts

Re: Security Vulnerability in Tor Browser

#151

Earlier quoted context omitted.

And so can all the other agencies, same consequences.

I don't understand: How does it protect end-user privacy if multiple state agencies, rather than just one, can access their identity and metadata?

No, no, at most one can obtain such dominance.

Multiple state agencies can fight over control of nodes and, if one of them somehow controls enough nodes they get such information.

If you're right that such agencies can afford to, I dunno, expend zero days to seize control of nodes, they're all going to do that. That doesn't magically create more nodes, just makes it harder to decide who (if anyone) controls them.

The most likely outcome isn't that multiple state agencies can get this done, but that none of them can despite their fervent wishes otherwise.

Re: Security Vulnerability in Tor Browser

#152
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Wikipedia does not require Javascript to be "functional". Also, the "internet" is much more than the www. The majority of protocols used on the internet do not rely on Javascript to be functional.

Re: Security Vulnerability in Tor Browser

#153

Earlier quoted context omitted.

I don't understand: How does it protect end-user privacy if multiple state agencies, rather than just one, can access their identity and metadata?

No, no, at most one can obtain such dominance. Multiple state agencies can fight over control of nodes and, if one of them somehow controls enough nodes they get such information. If you're right that such agencies can afford to, I dunno, expend zero days to seize control of nodes, they're all going to do that. That doesn't magically create more nodes, just makes it harder to decide who (if anyone) controls them. The…

With repetition and italics - well that's more convincing!

They don't need to control the node; good hacking and spying doesn't reveal your presence unless that is beneficial. Nothing stops multiple attackers from having access unless they want to interfere with each other.

Re: Security Vulnerability in Tor Browser

#154
post #147

Earlier quoted context omitted.

> Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP as far as I am aware Tails use IP tables to force all network connections through tor. You would require an escape from the browser and then a privilege escalation to get around this.

Local privilege escalations are about a dime a dozen. If you're executing arbitrary code, root isn't a far jump.

So that's not a single exploit away then

Re: Security Vulnerability in Tor Browser

#155

Earlier quoted context omitted.

No, no, at most one can obtain such dominance. Multiple state agencies can fight over control of nodes and, if one of them somehow controls enough nodes they get such information. If you're right that such agencies can afford to, I dunno, expend zero days to seize control of nodes, they're all going to do that. That doesn't magically create more nodes, just makes it harder to decide who (if anyone) controls them. The…

With repetition and italics - well that's more convincing! They don't need to control the node; good hacking and spying doesn't reveal your presence unless that is beneficial. Nothing stops multiple attackers from having access unless they want to interfere with each other.

During the Blitz and through the V-weapon attacks, Germany relied heavily on field agents to let it know what it was really hitting in England. If the agents consistently reported that attacks were striking outer North West London for example, German targets would be adjusted South East to compensate. Like when target shooting.

Except, those agents didn't actually work for the Germans. Twenty Committee (because twenty = XX in Roman Numerals, a Double Cross) had identified all the German agents and offered them either indefinite imprisonment for Espionage, or service as agents feeding bogus information to their German masters (and we can infer, the third alternative was death). You can guess what most of them chose.

Twenty Committee in effect ran German Espionage in WWII. If they had destroyed all these agents the Germans would have known and perhaps, in time, the Germans would have replaced them, but instead the Germans believed they had a working on-the-ground network of agents in Britain.

The point of the story is: "Just" having accurate information when actually somebody else controls your source of intelligence isn't actually having accurate information at all, it means you're a fool. Either you have control or you do not.

Re: Security Vulnerability in Tor Browser

#156

Earlier quoted context omitted.

> Firefox is already not one of the most hardened browser engines I'm pretty sure it's one of the most hardened, because the list of major engines that are on that list in first place numbers approximately 3. If you want to claim that blink or webkit are more secure that's a reasonable argument, but just say that.

Yeah, Gecko is one of the most hardened browser engines out there at this point. Fission and the win32k.sys isolation basically bring the general architecture up to par with Chromium. Chromium got those features earlier and hence has more mature implementations of them, so the edge goes to Chromium, but there's not much of a large-scale difference anymore. There are a few areas in which one browser has the edge over…

> memory safety of pdf.js in Firefox reduces attack surface over the C++ PDFium in Chromium

I thought Firefox abandoned PDF.js a few month ago.

Post reply on HN