Earlier quoted context omitted.
How does this work? I would expect a generic resolution like 1920x1080 to convey much less identifiable information that some random 1583x1176 that the user might resize tor browser window to.
The idea is to not change the window size at all from the default. If this advice is followed, you minimize the possible information leak. In your example, 1583x1176 tells us that your system is capable of rendering at least that size. Given the unusual numbers, we further suspect you're not maximized on a system capable of an 1176px tall browser (much fewer of those than 1920x1080). While not uniquely identifying, i…
Javascript exploit actively used against TorBrowser
121–130 of 138 posts
Re: Javascript exploit actively used against TorBrowser
#122Earlier quoted context omitted.
Background for the uninitiated: https://www.eff.org/deeplinks/2016/09/playpen-story-fbis-unp...
Unrelated, but kudos on the arbitrary hash use on the Wordpress auto updater last week.
That was a few months ago. We had to go through the disclosure process via HackerOne etc.
I'm really lucky to be working with people like Matt and others on the team.
Re: Javascript exploit actively used against TorBrowser
#123Earlier quoted context omitted.
Exit nodes will also steal any unencrypted passwords and put malware in any binaries you download. It's been happening for years. In China the "regular internet" intercepts http and inserts javascript malware to create a DDOS botnet.
Yes, but I'm not talking about downloading exes or logging onto gmail (and definitely not putting credentials on a site using HTTP) or anything. I'm talking about going anywhere on Tor can infect you.
Re: Javascript exploit actively used against TorBrowser
#124Earlier quoted context omitted.
But its worse on Tor. Regular internet has a few protections: 1. Google safe browsing 2. AdBlocking 3. Websites try to keep their reputation. Tor exit nodes, on the other hand, have no reputation (and if one gets sullied, spin up another) and costs money.
I have one question: the list of exit nodes is public, we can know at any time the circuit's complete list of servers. Does something prevents us from rating tor exit nodes according to their "transparency" and add this rating in the consensus file? Does anybody already worked on that? I cannot find anything on the internet…
My impression from talking to people working on this a few years ago was that they wanted to be a little bit secretive about exactly what they scan for, in order to make it harder for malicious exit operators to anticipate the scans or to distinguish the scans from end-user traffic. There was a suggestion this is an activity that anybody can engage in: if you can think of an attack against Tor users that you know how to detect, you can write your own client that tests for that thing (modifying the path selection algorithm to ensure that you test every exit node!) and then start running your tests. People will be interested in your results.
Re: Javascript exploit actively used against TorBrowser
#125Earlier quoted context omitted.
Exit nodes will also steal any unencrypted passwords and put malware in any binaries you download. It's been happening for years. In China the "regular internet" intercepts http and inserts javascript malware to create a DDOS botnet.
Yes, but I'm not talking about downloading exes or logging onto gmail (and definitely not putting credentials on a site using HTTP) or anything. I'm talking about going anywhere on Tor can infect you.
Re: Javascript exploit actively used against TorBrowser
#126Earlier quoted context omitted.
This likely points to this being an FBI "network investigative technique".* I'm really curious where this attack was injected, as that also means that that .onion is also compromised. My guess? Some darknet market. * Sure, this could be some type of awkward false flag, but it seems unlikely to my gut.
It's on a CP site (giftbox). The exploit got loaded on the confirmation page after logging in.
Re: Javascript exploit actively used against TorBrowser
#127I've quit using TOR. It seems to have been targeted by law enforcement and now this.
(Using Tor does change who can attempt to attack you with such bugs -- and maybe who is motivated to.)
Re: Javascript exploit actively used against TorBrowser
#128Earlier quoted context omitted.
This likely points to this being an FBI "network investigative technique".* I'm really curious where this attack was injected, as that also means that that .onion is also compromised. My guess? Some darknet market. * Sure, this could be some type of awkward false flag, but it seems unlikely to my gut.
It's on a CP site (giftbox). The exploit got loaded on the confirmation page after logging in.