Earlier quoted context omitted.
True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…
uBlock Origin allows most of those things when it's opted in: https://github.com/gorhill/uBlock/wiki/Dynamic-filtering
Security Vulnerability in Tor Browser
121–130 of 156 posts
Re: Security Vulnerability in Tor Browser
#122Earlier quoted context omitted.
Anything with JavaScript leaks. You can fingerprint a computer just based on Canvas.
https://en.wikipedia.org/wiki/Canvas_fingerprinting#Mitigati... > Tor Browser notifies the user of canvas read attempts and provides the option to return blank image data to prevent fingerprinting. > Canvas Defender, a browser add-on, spoofs Canvas fingerprints. > The LibreWolf browser project includes technology to block access to the HTML5 canvas by default It doesn't seem to be the case that anything with javascri…
Re: Security Vulnerability in Tor Browser
#123Earlier quoted context omitted.
True, disabling Javascript and surfing the (mainstream) web is deep in the no-fun zone, maybe just above "using Lynx as a day-to-day browser". :D But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains hav…
Is uMatrix being maintained again?
Re: Security Vulnerability in Tor Browser
#124It's a JavaScript engine bug and JS is disabled by default. Still important, but I question whether anyone who enables JS in Tor is worth compromising.
>JS is disabled by default This isn't true any more.
Re: Security Vulnerability in Tor Browser
#125A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
If you read the the DOJ indictments of Tor users what they have in common is that they stepped out of those bounds
There _was_ a period where Firefox (hence: the Tor Browser) was terrible and 0days were cheap (which is why most of the darkweb switched up to using VM's behing their browsers), but those days are over[0]
I can't recall a recent indictment where the adversary in the USA broke Tor Browser. If you are a dissident in Turkey, Syria or Russia .. you're more than safe using the Tor Browser bundle.
The NSA aren't burning 0days in Firefox and VM's on 99.9% of Tor users - if you're in that other 0.01% then good luck to you[1], your threat model is very different to those looking to obfuscate from oppressive regimes.
As somebody with an infosec background, this is where I feel the industry fails in the sense of "perfect is the enemy of good" - there is no such thing as perfect (I bet most who preach against Tor Browser wouldn't be able to come up with a model that is) - the practical advice today is, and always has been, use Tor (Browser), use Tails, use Whonix
[0] I used ungoogled-chromium in that period, until an DNM administrator during a chat told me he could spot me in his acccess logs
Re: Security Vulnerability in Tor Browser
#126Fixed in: Firefox 100.0.2, Firefox ESR 91.9.1, Firefox for Android 100.3, Thunderbird 91.9.1
https://www.mozilla.org/en-US/security/advisories/mfsa2022-1...
Re: Security Vulnerability in Tor Browser
#127A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…
Re: Security Vulnerability in Tor Browser
#128Earlier quoted context omitted.
> YouTube, Twitter and Instagram We clearly have very different lifestyles and values. For me that's the dank basement of the internet,
That's perfectly fine. It however does not matter for the large majority of people who use those top 100 or even top 100,000 websites or even top 1,000,000 websites, and do not have the education, skill or time to learn about all the alternatives, if there are even any. It doesn't matter for the people living under repressive regimes who want to inform themselves on foreign news sites, access foreign NGO sites, or ev…
With respect, this is hacker news. When I converse with people here I do so with a different expectation of intellect and curiosity. There are voices here who excuse technological abuses by appeal to the ignorance of "the masses" - completely missing that there is a different spirit going on in the sub-text of innovation and entrepreneurialism here. If, as you claim, the majority are using defective technologies, then that is a bigger problem, not something to be celebrated. They deserve better and it's our job to help them get that.
Re: Security Vulnerability in Tor Browser
#129> The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.
> For example, after you visit a malicious website, an attacker controlling this website might access the password or other sensitive information that you send to other websites afterwards during the same Tails session.
This makes it relatively tame.
Re: Security Vulnerability in Tor Browser
#130Earlier quoted context omitted.
For any such agency, a handful of Tor nodes gives your own agents a useful secure channel. An overwhelming majority of nodes would give you good insight into what other users are doing, but it's very hard to get such a majority since of course all your competitors think the same. Putting in place a handful of nodes to benefit your own agents is very possible, so that's what you do.
You can just hack into existing nodes. There are few enough nodes that accessing a large proportion of them is easily within the budget of a state security agency.