Live data from Hacker News

Javascript exploit actively used against TorBrowser

lists.torproject.org

111–120 of 138 posts

Re: Javascript exploit actively used against TorBrowser

#111

I reversed the shellcode, it's almost exactly the same used in 2013 (freedom hosting): https://twitter.com/TheWack0lian/status/803736507521474560

The post mentions "VirtualAlloc" in "kernel32.dll". Does this exploit work on Mac/Linux or is it Win specific?

The bug is generic, the exploit is Windows specific. It should be possible to construct Mac and Linux exploits.

Re: Javascript exploit actively used against TorBrowser

#112

Earlier quoted context omitted.

Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…

Tails' existence is a symptom of much greater illnesses but offers a false, inconvenient panacea that just muddies the water. The major, underlying issue is untrustworthy applications, operating systems and hardware the "free market" hasn't brought integrity, privacy and anonymity to barely anyone in a practical, consistent and verifiable form. It may not be easy to accomplish end-to-end verifiably-uncompromised syst…

I don't know whether we should push for more system integrity from the manufactures. They'll give us locked down systems that run binary blobs that your OS can't control, prevent installing alternatives OSs by only booting signed kernels... If you want user freedom you have to go another route.

Re: Javascript exploit actively used against TorBrowser

#114

Earlier quoted context omitted.

Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…

What's their threat model, then? If you're going to be actively targeted by exploits like this, then you shouldn't give a damn about some of these tradeoffs. If you have journalists/activists willing to go to information war with a nation-state, they shouldn't be surprised when their adversaries have the resources to pwn them. If David wants to fight goliath, they will need to take this into account. The guys with gu…

> If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting.

The problem with this mentality is, often its not themselves they're protecting but others. If Alice and Bob are communicating, and only Alice is the one under threat: Alice may be willing to go to great lengths to make her side secure, but you really need to be making it as easy as possible for Bob, who has less of a direct incentive to overcome the inconveniences.

Re: Javascript exploit actively used against TorBrowser

#115

Earlier quoted context omitted.

Just to provide some balance: Chrome exploits are not as rare as you claim in this post. Pretty much any time Pwn2Own or similar contests are held, with non-trivial prize money, somebody brings a fully working Chrome exploit. If you check https://zerodium.com/program.html you can see that the current market prize for a Chrome exploit with sandbox escape is about 80k USD. Firefox is cheaper (30k USD), but only by a bi…

Also, it is safe to say that ChakraCore (the JS interpreter inside Edge) is much more broken / easier to find bugs in than Firefox, at least at the moment.

Why is that safe to say?

Re: Javascript exploit actively used against TorBrowser

#116

Earlier quoted context omitted.

What's their threat model, then? If you're going to be actively targeted by exploits like this, then you shouldn't give a damn about some of these tradeoffs. If you have journalists/activists willing to go to information war with a nation-state, they shouldn't be surprised when their adversaries have the resources to pwn them. If David wants to fight goliath, they will need to take this into account. The guys with gu…

> If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting. The problem with this mentality is, often its not themselves they're protecting but others . If Alice and Bob are communicating, and only Alice is the one under threat: Alice may be w…

Yep. That's the beauty of Signal App or WhatsApp use of Signal Protocol. You a making it much easier to meet the person-at-risk on a platform where they already are. As opposed to tasking to use something like Pidgin.

Re: Javascript exploit actively used against TorBrowser

#117
post #108
post #107

Earlier quoted context omitted.

> The fuss made here illustrates it: 0-days are rare enough that "rather often" is a serious mischaracterisation. A RCE in a browser is literally the worst possible case and Firefox had multiple of them, most trivially exploitable with JavaScript. This simply doesn't happen with Chrome. > Chromium means you miss features that Chrome has (H264, Netflix, ...) Google made an effort to open-source everything, including t…

I specifically pointed out H264 support (and you ignored it) because it's an annoyance when using Chromium. And yes, that's due to licensing reasons as well.

That's up to the distribution policy/packaging. Fedora refuses to add H264, on Ubuntu you can install chromium-codecs-ffmpeg-extra and it works fine.

The code is there in Chromium and it's fully open source.

Re: Javascript exploit actively used against TorBrowser

#118

Earlier quoted context omitted.

Fine. Replace Tails with Whonix-Workstation and Whonix-Gateway, if you need to worry about leaking the IP address.

"If"? Are there any Tor users who don't need to worry about leaking their IP address? Then why do they use Tor in the first place? The Tor project itself seems to promote Tails much more than Whonix, which seems very odd to me.

I know several people who use Tor purely for its tunneling, and not because of security. There are more use cases.

Re: Javascript exploit actively used against TorBrowser

#119
post #13

As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…

Just to provide some balance: Chrome exploits are not as rare as you claim in this post. Pretty much any time Pwn2Own or similar contests are held, with non-trivial prize money, somebody brings a fully working Chrome exploit. If you check https://zerodium.com/program.html you can see that the current market prize for a Chrome exploit with sandbox escape is about 80k USD. Firefox is cheaper (30k USD), but only by a bi…

I fully agree with you, Chrome isn't magically secure either (especially with Flash and Windows prior to Win10). The Chrome and project zero bug trackers are full of PoCs for old vulnerabilities. It's just in a much better shape than Firefox.

Did not know those prices were public, really interesting.

Re: Javascript exploit actively used against TorBrowser

#120
post #99

Earlier quoted context omitted.

> fullscreen Tor browser Tor recommends not going full-screen, since window size can be used as one of several identifiers.

How does this work? I would expect a generic resolution like 1920x1080 to convey much less identifiable information that some random 1583x1176 that the user might resize tor browser window to.

The idea is to not change the window size at all from the default. If this advice is followed, you minimize the possible information leak. In your example, 1583x1176 tells us that your system is capable of rendering at least that size. Given the unusual numbers, we further suspect you're not maximized on a system capable of an 1176px tall browser (much fewer of those than 1920x1080). While not uniquely identifying, it's a piece of the puzzle.

https://trac.torproject.org/projects/tor/ticket/7255

Post reply on HN