Live data from Hacker News

Tor executive director hints at Firefox integration

dailydot.com

21–29 of 29 posts

Re: Tor executive director hints at Firefox integration

#21
For anyone interested in exclusively using Tor on Android immediately, check out orWall, a root-requiring proxy that blocks all regular traffic by default and allows app-specific access of your choosing to exit via Tor. Only on F-Droid market for now, but coming to Play Store soon.

https://orwall.org/

Re: Tor executive director hints at Firefox integration

#22
post #5

It would be so great if Mozilla integrated Tor. Beyond the curse of success mentioned in the article, it would really lower the burden on the Tor developers, who have had to support a lot of patches from Firefox that Mozilla have been slow to merge. My main concern is that this will be hidden behind an option or an "extreme private" mode -- Tor seems too high-latency for the typical use-case of private browsing (imag…

I hadn't heard of Exit Enclaves before, when I looked it up in the docs [0] it appears that they are not going to be supported in versions > 0.2.3.x. [0] https://trac.torproject.org/projects/tor/wiki/doc/ExitEnclav... :

This is news to me, and certainly disappointing.

Re: Tor executive director hints at Firefox integration

#23
post #18

Earlier quoted context omitted.

> My main concern is that this will be hidden behind an option or an "extreme private" mode To add to your point, effectively using Tor means disabling JavaScript.

Why do you say that? According to the Tor Project FAQ for their browser bundle, they leave JavaScript enabled. The only problem they mention is that selectively allowing scripts via NoScript permissions leaks information, so it's an all-or-nothing decision with regards to third-party scripts for any given site and they choose to make the default the one that breaks fewer sites. (And really, you're still free to block…

Tor has been exploited in the past in ways which only affected those who kept JavaScript enabled [1]. I actually love JavaScript, and the doors it can open for trustworthy developers, but I don't think a deep cover journalist or whistleblower should be browsing with it.

[1] https://blog.torproject.org/blog/tor-security-advisory-old-t...

Re: Tor executive director hints at Firefox integration

#24
I suspect this will start hitting problems when users discover that lots of sites break in unexpected or mysterious ways when run in "Super Private Mode" or whatever they call it. Tor is blocked or treated suspiciously by a LOT of different sites. It's not at all a free upgrade.

Re: Tor executive director hints at Firefox integration

#25
Wonderful news. I am particularly looking forward to having torified connection in a browser with some continuity and customization. The bundles are stripped of customizations and I find it inconvenient to bring along bookmarks and chosen extensions manually at every upgrade of the bundle.

I realize it's often for good reason that the bundles are minimalistic, but I see no fundamental reason why I should have to relinquish bookmarks and personal settings to stay anonymous, and it would be great if this could spur a greater drive to make it clear what extensions are safe or new browser architecture that would make it safe to use add-ons in general with Tor.

Re: Tor executive director hints at Firefox integration

#26
post #5

It would be so great if Mozilla integrated Tor. Beyond the curse of success mentioned in the article, it would really lower the burden on the Tor developers, who have had to support a lot of patches from Firefox that Mozilla have been slow to merge. My main concern is that this will be hidden behind an option or an "extreme private" mode -- Tor seems too high-latency for the typical use-case of private browsing (imag…

I hadn't heard of Exit Enclaves before, when I looked it up in the docs [0] it appears that they are not going to be supported in versions > 0.2.3.x. [0] https://trac.torproject.org/projects/tor/wiki/doc/ExitEnclav... :

Well, that sucks. DuckDuckGo run a Tor exit enclave. I hope this doesn't put them off running an exit node, even if only to their own servers: https://duckduckgo.com/privacy

Re: Tor executive director hints at Firefox integration

#27
post #18

Earlier quoted context omitted.

Why do you say that? According to the Tor Project FAQ for their browser bundle, they leave JavaScript enabled. The only problem they mention is that selectively allowing scripts via NoScript permissions leaks information, so it's an all-or-nothing decision with regards to third-party scripts for any given site and they choose to make the default the one that breaks fewer sites. (And really, you're still free to block…

Tor has been exploited in the past in ways which only affected those who kept JavaScript enabled [1]. I actually love JavaScript, and the doors it can open for trustworthy developers, but I don't think a deep cover journalist or whistleblower should be browsing with it. [1] https://blog.torproject.org/blog/tor-security-advisory-old-t...

So, that's not Tor being exploited, that's just a Firefox bug that was used to get at Tor users because they're more interesting targets. It wasn't a case of JavaScript making Tor less private or less secure except in that it was JavaScript making everything less private and secure, and Tor doesn't protect you from that because Tor isn't a security tool.

Re: Tor executive director hints at Firefox integration

#28
post #27

Earlier quoted context omitted.

Tor has been exploited in the past in ways which only affected those who kept JavaScript enabled [1]. I actually love JavaScript, and the doors it can open for trustworthy developers, but I don't think a deep cover journalist or whistleblower should be browsing with it. [1] https://blog.torproject.org/blog/tor-security-advisory-old-t...

So, that's not Tor being exploited, that's just a Firefox bug that was used to get at Tor users because they're more interesting targets. It wasn't a case of JavaScript making Tor less private or less secure except in that it was JavaScript making everything less private and secure, and Tor doesn't protect you from that because Tor isn't a security tool.

Right, the Tor browser bundle was exploited. The context of this thread is browser usage of Tor.
Post reply on HN