Live data from Hacker News

Tor Browser 8.5

blog.torproject.org

11–20 of 99 posts

Re: Tor Browser 8.5

#11
I'm rooting for Mozilla and the Tor Project to uplift Tor into Firefox. Imagine a world where people need to opt in to get less privacy.

Re: Tor Browser 8.5

#12
post #5

I wish people used the deep web for something besides illegal buying and child pornography

I've used it to maintain normal(ish) internet service for myself when visiting places like China.

When I went to China I expected problems so I setup my laptop with an SSL tunnel on port 443 to a virtual server and then routed openvpn over that. It worked like a charm. My favorite feature of openvpn is it can maintain state, so even if the tunnel resets and openvpn has to reconnect all the tcp connections just pick up where they left off.

Re: Tor Browser 8.5

#13

Earlier quoted context omitted.

Tor Browser routes all data via the Tor network. Brave is a standard browser with built in ad-ware.

This is amusingly uninformed. Saying nothing about the ad-ware comment, since that seems designed to deliberately obfuscate/obscure reality, you probably weren't aware of: https://brave.com/tor-tabs-beta To OP - check out the issues, there's a reason it's still in beta: https://github.com/search?utf8=&q=is%3Aopen+is%3Aissue+org%3...

This is amusingly uninformed. Describing Brave as adware is generous to say the least, Brave is more of a scam than a business. The kind of scams you would find in tech bubbles like what happened in late 1990s.

Re: Tor Browser 8.5

#14

I wish people used the deep web for something besides illegal buying and child pornography

Less than 3% of Tor traffic is to onion services of any kind (which means 97% is to websites already accessible on the public internet), and the most popular onion service on the internet by a large margin is Facebook's (facebookcorewwwi.onion). More than 2 million people use Tor every day -- are they all bad people? Heck, government agents use Tor when traveling abroad.

Do bad people do bad things using Tor? Yes. Do political dissidents in oppressive regimes use Tor? Yes.

However the vast majority of people are just ordinary citizens using Tor to access the internet -- the cross-section of Tor users is the same as the cross-section of ordinary internet users.

Re: Tor Browser 8.5

#15

How is this better than Brave browser?

There are a bunch of privacy-improving patches in the Tor browser (such as protections against font fingerprinting, screen size fingerprinting, and so on). Brave doesn't have those.

(There's also the fact that Tor Browser routes everything over Tor, but apparently Brave can do this too now?)

Re: Tor Browser 8.5

#16

I wish people used the deep web for something besides illegal buying and child pornography

I do and a lot of people I know also do. Just for added privacy, or anything sensitive but legal. Tor became such a pleasant (and fast, unlike it used to be) experience that it can be used for general anon surfing.

You have to be a little weary using tor. Anyone can run an exit node and it is trivial to rewrite and inject onto web pages. You can also on the fly intercept SSL requests and generate your own self signed certificate that fails proper verification but looks real enough if inspected that will always trick a percentage of users. If you've used tor with any frequency you've probably hit weird SSL cert errors that go away if you change routes.

Re: Tor Browser 8.5

#17

I wish people used the deep web for something besides illegal buying and child pornography

I wish people would at least learn the difference between "deep web" and "dark web". ;) I bet you use the "deep web" multiple times each week. The "dark web" on the other hand, probably not.

Re: Tor Browser 8.5

#18
Allow me to send a big shoutout and my deepest thanks to the maintainers and volunteers of both the Tor Browser and the Tor Project in general. You make the world a better place, even if the majority of the population don't realise they should pay more attention to your work. You're the real MVPs!

Re: Tor Browser 8.5

#19

Earlier quoted context omitted.

Tor Browser routes all data via the Tor network. Brave is a standard browser with built in ad-ware.

This is amusingly uninformed. Saying nothing about the ad-ware comment, since that seems designed to deliberately obfuscate/obscure reality, you probably weren't aware of: https://brave.com/tor-tabs-beta To OP - check out the issues, there's a reason it's still in beta: https://github.com/search?utf8=&q=is%3Aopen+is%3Aissue+org%3...

Brave's "Basic Attention Token" was described as replacing ads on websites with ads from Brave's own ad network[0], which I recall is a common practice among adware to go unnoticed on an infected user's machine. The homepage of the Basic Attention Token completely fails to mention that it blocks publisher's "genuine" ads and replaces it with their own ads[1].

On top of that Brave has seemingly no interest in asking for consent for this practice, while also going as far as to use people's names and photos to solicit donations to them, without those people even being aware that Brave is accepting money for them[2].

Now I believe the ad-replacement feature is opt-in, but I'm not willing to install Brave and go through the opt-in flow to determine if it goes through the proper steps in explaining that the Brave Ad money may never reach its intended recipient.

[0] https://cryptobriefing.com/what-is-basic-attention-token-int... "Brave integrated BAT into its browser to block ads at the site level, and instead serve them through the browser itself." [1] https://basicattentiontoken.org/ [2] https://twitter.com/tomscott/status/1076160882873380870

Re: Tor Browser 8.5

#20
post #16

Earlier quoted context omitted.

I do and a lot of people I know also do. Just for added privacy, or anything sensitive but legal. Tor became such a pleasant (and fast, unlike it used to be) experience that it can be used for general anon surfing.

You have to be a little weary using tor. Anyone can run an exit node and it is trivial to rewrite and inject onto web pages. You can also on the fly intercept SSL requests and generate your own self signed certificate that fails proper verification but looks real enough if inspected that will always trick a percentage of users. If you've used tor with any frequency you've probably hit weird SSL cert errors that go aw…

It is fair to say that using unauthenticated protocols like HTTP over Tor is a pretty bad idea (and there really should be more warning bells about this in the Tor Browser). However on the TLS comment -- almost all modern websites use HSTS, so sslstrip doesn't really work any more.
Post reply on HN