I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
Tor Browser 10
11–20 of 106 posts
Re: Tor Browser 10
#12> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
Re: Tor Browser 10
#13Been using Tor a lot more, since Youtube started disallowing danes access to nearly all music. Get bent, Google.
You can yell at google all you want but ultimately it’s the rights holders who push this initiative
But I see your point, though I'm not sure who is more unlikeable, Google or the music industry. Actually, let it never be said that I'm not fair: They can all get bent.
[1] Never thought I'd link this on HN: https://www.youtube.com/watch?v=1t_sMynan_k
Re: Tor Browser 10
#14> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
https://nakedsecurity.sophos.com/2020/04/02/covid-19-forces-...
Re: Tor Browser 10
#15Earlier quoted context omitted.
Yes. It disables many (all?) mozilla integrations such as password manager and intermediate certificate preload. I prefer to use the story network with standard Firefox because I value the mozilla features except for Pocket.
Is there an extra fork for de-tored Tor Browser or do you just have to live with the warning that Tor is disabled? I've heard that Whonix makes a custom tor based browser but I don't think it is supported anymore.
Re: Tor Browser 10
#16Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?
By default it is very strict though, so you will probably want to go through the config setting by setting and relax it a bit. Like enabling Webassembly and the search engine integration of the URL bar.
Most settings have inline comments explaining what they do and why they are chosen.
Re: Tor Browser 10
#17> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?
Re: Tor Browser 10
#18What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.
I think it remains the best in class for private browsing. They have to make difficult trade-offs that achieve acceptable levels of performance while not leaking metadata like a sieve. They do also have a good track record of handling security vulnerabilities. For the average user, the greatest threat is actually everything outside the Tor browser. For example, downloading certain files using Tor, then opening it in…
Re: Tor Browser 10
#19What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.
For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats.
It also works mostly fine against national and ISP firewalls that is intended to censor citizens and lead people away from places which the state has declared unsuited for its population.
Against police force it seem to mostly work as a free tool that get used by criminals as something better than nothing, but with some larger caveats and the police have cases from time to time where they have identified criminals (from either good investigations or parallel constructions depending on who you ask). The tor browsers has also not been immune to malware.
Against national-level intelligence agency, "citizen scores", and whistleblowers employed within such agencies, the protection granted by tor may be very far from 100%. It is not recommended by anyone to depend on tor against that threat model.
Re: Tor Browser 10
#20> Bug 11154: Disable TLS 1.0 (and 1.1) by default I'm still a little shocked by this. It's 2020 and we were still allowing these old protocols?
For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?