Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

101–110 of 156 posts

Re: Security Vulnerability in Tor Browser

#101
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

I knew about Tails but not Whonix. This is really nice. No live system like Tails though?

Re: Security Vulnerability in Tor Browser

#102
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Perhaps you mean "don't rely on just the Tor Browser"? How else would one use tor to browse the web? Certainly Whonix or another protection layer is advisable if you're doing anything serious as well.

Re: Security Vulnerability in Tor Browser

#103
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

then why not just use Whonix

Re: Security Vulnerability in Tor Browser

#104
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

> Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to target.

That's a good thing too because of browser fingerprinting. It takes a lot of identifying points away by having everyone use the same.

Re: Security Vulnerability in Tor Browser

#105

Earlier quoted context omitted.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

you're not using the web like 90% of other users though (which is facebook, tiktok, twitter, big news sites, instagram, etc)

And those other 90% of users aren't using Tor.

Re: Security Vulnerability in Tor Browser

#106
post #102
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

Perhaps you mean "don't rely on just the Tor Browser"? How else would one use tor to browse the web? Certainly Whonix or another protection layer is advisable if you're doing anything serious as well.

I don't know, you could just use a simpler (non-js) browser over torsocks

Re: Security Vulnerability in Tor Browser

#107
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

I almost find it suspicious how heavily Tails is promoted over Whonix. Tails focuses on largely imaginary scenarios that only happen to people named Bob or Alice, while Whonix fixes the actual attacks that come up in subpoenas.

Re: Security Vulnerability in Tor Browser

#108
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

I almost find it suspicious how heavily Tails is promoted over Whonix. Tails focuses on largely imaginary scenarios that only happen to people named Bob or Alice, while Whonix fixes the actual attacks that come up in subpoenas.

Apple's and Oranges; tails is designed for storing sensitive files amongst many other features whereas Whonix is a live CD that doesn't offer storage and is focused only on secure browsing.
Post reply on HN