Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

111–120 of 156 posts

Re: Security Vulnerability in Tor Browser

#111
post #52

Earlier quoted context omitted.

Anything with JavaScript leaks. You can fingerprint a computer just based on Canvas.

https://en.wikipedia.org/wiki/Canvas_fingerprinting#Mitigati... > Tor Browser notifies the user of canvas read attempts and provides the option to return blank image data to prevent fingerprinting. > Canvas Defender, a browser add-on, spoofs Canvas fingerprints. > The LibreWolf browser project includes technology to block access to the HTML5 canvas by default It doesn't seem to be the case that anything with javascri…

I'm saying Brave doesn't do anything as far as I'm aware to stop fingerprinting, and since it is Chromium-based I'm guess also leaks Client Hints.

Re: Security Vulnerability in Tor Browser

#112
post #108

Earlier quoted context omitted.

I almost find it suspicious how heavily Tails is promoted over Whonix. Tails focuses on largely imaginary scenarios that only happen to people named Bob or Alice, while Whonix fixes the actual attacks that come up in subpoenas.

Apple's and Oranges; tails is designed for storing sensitive files amongst many other features whereas Whonix is a live CD that doesn't offer storage and is focused only on secure browsing.

I think you're backwards. Tails is the LiveCD with a browser (that can beacon straight out). Whonix is the VM based system. I think it's capable of more than just browsing, but I use it as the "secure browser" in Qubes as a disposable VM, because it just automatically does the right stuff with the gateway VM and such.

Re: Security Vulnerability in Tor Browser

#113
post #80
post #61

Earlier quoted context omitted.

Most important of all porn doesn’t work

I wouldn't be surprised if pornhub-dl exists. ;-)

    wc -l yt-dlp/*/*/*porn*
       75 yt-dlp/yt_dlp/extractor/alphaporno.py
      127 yt-dlp/yt_dlp/extractor/eporner.py
       73 yt-dlp/yt_dlp/extractor/hellporno.py
       33 yt-dlp/yt_dlp/extractor/lovehomeporn.py
       60 yt-dlp/yt_dlp/extractor/porn91.py
      101 yt-dlp/yt_dlp/extractor/porncom.py
       41 yt-dlp/yt_dlp/extractor/pornez.py
       78 yt-dlp/yt_dlp/extractor/pornflip.py
      117 yt-dlp/yt_dlp/extractor/pornhd.py
      814 yt-dlp/yt_dlp/extractor/pornhub.py
       83 yt-dlp/yt_dlp/extractor/pornotube.py
      103 yt-dlp/yt_dlp/extractor/pornovoisines.py
       54 yt-dlp/yt_dlp/extractor/pornoxo.py
       76 yt-dlp/yt_dlp/extractor/sunporno.py
       65 yt-dlp/yt_dlp/extractor/watchindianporn.py
      182 yt-dlp/yt_dlp/extractor/youporn.py
       65 yt-dlp/yt_dlp/extractor/yourporn.py
That appears to be a thing on yt-dlp [1]

[1] - https://github.com/yt-dlp/yt-dlp.git

Re: Security Vulnerability in Tor Browser

#114

Earlier quoted context omitted.

I use brave and browse with JS disabled by default. Some sites don't work, some do. I regularly decide the info I'm looking for can be found somewhere else and back out of a broken site because of it. Some sites I enable and proceed with.

> I use brave and browse with JS disabled by default. That’s hilarious given the founder of Brave (Brendan Eich) literally invented JavaScript.

I mean I'm not arguing JavaScript's utility.

Its a tool with a time and place for proper usage.

Re: Security Vulnerability in Tor Browser

#115
Just a heads up for Android users: The Play store version is a few releases out of date, to get current use FDroid and make sure Guardian Project repo is selected (it's not by default).

Question for the Mozillans/Googlers: How is it that Firefox Nightly are fast-track released multiple times a day to Play Store but stable Tor Browser updates are stuck for weeks? Is there a 'skip the review' option for nightly releases?

Re: Security Vulnerability in Tor Browser

#116
post #94

And this is why Whonix is critical - because even when you pop the browser, you still have another layer of protection - the gateway VM. Tails browser on [almost anything] is one browser exploit away from beaconing out directly from your IP, and has done so rather frequently over the years. Whonix stuffs the whole browser and such into a workstation VM, which is only connected to the gateway VM - which "torifies" eve…

then why not just use Whonix

"Whonix alone" is probably fine against browser exploits in the Tor browser (of which I generally assume there are many, because it's a browser of Very Much Interest to plenty of agencies). However, if you assume a "dirty host," with various bits of nastiness on it, if you're just using Virtualbox or something, it would be easy enough for a compromised Whonix workstation VM to chatter away with the host and have the host beacon out, or have the host modify the disk images for Whonix to add badness, or something of the sort. It's not a high risk, but if you're going to be doing something with Tor where failure of opsec puts you in prison for life (see DPR), it's something to consider.

Qubes adds a few more layers of isolation and security, because you now have a Type 1 hypervisor under everything (currently Xen), with your other isolation VMs separated out. Badness in another VM can't directly impact the Whonix VMs, unless it's compromised Dom0, at which point you've lost with Qubes anyway.

Both are at risk from a hypervisor escape as well, but I generally consider Xen to be a somewhat better inspected and harder to escape from target than Virtualbox or VMWare Workstation, just because there's less to Xen. It's a far smaller codebase, and when you're using hardware virtualization with paravirtualized devices (virtio-type interfaces), there's just not as much surface exposed for attack. It's not impossible, but I would generally consider VMWare/Virtualbox somewhat softer targets to escape from than Xen.

Again, does any of this matter for casual use? No. But if you're going to use Tor for things that have actual consequences, it may very well matter a lot, and at that point, fully understanding the various threats and how they've been used over the years may be a matter of your freedom.

For whatever it's worth, I try to add Tor traffic where I can, just to help with the noise factor.

Re: Security Vulnerability in Tor Browser

#117
post #27

Earlier quoted context omitted.

I've always assumed that Tor was a top target for 3 letter agencies. In that sense, there is so much attention on it that it's kinda pointless.

For any such agency, a handful of Tor nodes gives your own agents a useful secure channel. An overwhelming majority of nodes would give you good insight into what other users are doing, but it's very hard to get such a majority since of course all your competitors think the same. Putting in place a handful of nodes to benefit your own agents is very possible, so that's what you do.

You can just hack into existing nodes. There are few enough nodes that accessing a large proportion of them is easily within the budget of a state security agency.

Re: Security Vulnerability in Tor Browser

#118
post #57
post #50

Earlier quoted context omitted.

"Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." https://news.ycombinator.com/newsguidelines.html (Not sure a rhetorical question to make some vague accusation counts as a substantive comment)

It's not a "vague accusation", onion routing was developed by the US Naval Research Academy ("NRL", a 3 letter government agency). See https://en.wikipedia.org/wiki/Tor_(network)#History for more detail.

The entire Internet has its roots in the US military, as does ASCII.
Post reply on HN