Live data from Hacker News

A Guide to Not Getting Hacked

motherboard.vice.com

61–70 of 84 posts

Re: A Guide to Not Getting Hacked

#61
post #52

Earlier quoted context omitted.

Is tor browser inside whonix good? Would you recommend a different browser inside of whonix instead?

It is explicitly warned not to use the Tor Browser under Whonix because the browser starts its own instance of Tor while Whonix already funnels every network request through its gateway Tor and Tor over Tor is supposedly undefined behaviour. So you have to go the additional step of disabling Tor Browser from starting its bundled Tor... Or under Whonix just use any normal browser like Firefox.

> any normal browser like Firefox.

This is very bad advice. Do not use Firefox. It is not as secure as Chrome.

Re: A Guide to Not Getting Hacked

#62
post #52

Earlier quoted context omitted.

Is tor browser inside whonix good? Would you recommend a different browser inside of whonix instead?

It is explicitly warned not to use the Tor Browser under Whonix because the browser starts its own instance of Tor while Whonix already funnels every network request through its gateway Tor and Tor over Tor is supposedly undefined behaviour. So you have to go the additional step of disabling Tor Browser from starting its bundled Tor... Or under Whonix just use any normal browser like Firefox.

That's not what I see on https://www.whonix.org/wiki/Tor_Browser

It explicitly says "There is no Tor over Tor scenario in the Whonix environment." when using their modified Tor Browser.

Re: A Guide to Not Getting Hacked

#63
post #12

> Do use antivirus I think the standard advice from the security community is to not use any antivirus at all and maybe only Windows Defender if you're on windows. The advice to use Tor browser is also terrible. The Tor browser is based on an older version of Firefox ( currently version 52 vs 57 for upstream Firefox ) and so might contain known bugs. On a side note what does the security community think about Qubes O…

> The advice to use Tor browser is also terrible. Mozilla uses tracking scripts in Firefox, which in some versions (such as Firefox Beta, Developer Edition, and Nightly) can not even be disabled (If you go to about:config, you’ll notice that toolkit.telemetry.enabled is "locked:true"). So Mozilla themselves suggests that if you do not trust Google Analytics to hold up their agreements with Mozilla, you should instead…

Isn't it datareporting.healthreport.uploadEnabled (still unlocked and visible in the "options" -> "privacy & security" panel) that controls the upload, and toolkit.telemetry.enabled is only about whenever something is collected or not?

Either way, thanks for the pointer. Didn't knew that setting was revamped.

Re: A Guide to Not Getting Hacked

#64
post #47

Earlier quoted context omitted.

libpurple suffers from very poor code quality, leading to tons of exploitable vulnerabilities. Just as you would expect when writing C parsers for lots of complicated protocols.

> libpurple suffers from very poor code quality, leading to tons of exploitable vulnerabilities. Just as you would expect when writing C parsers for lots of complicated protocols. Is this your personal feeling or do you have something to back this up? A quick look at the source code suggests it's basically like any other glib based program.

These are just public ones:

https://www.cvedetails.com/vulnerability-list/vendor_id-6938...

Filter by CVSS > 6, note the number of execs. Enjoy.

Re: A Guide to Not Getting Hacked

#65
post #17

Earlier quoted context omitted.

Why else is it terrible?

It also recommends running an antivirus on desktop, using a VPN, using tor browser, pidgin and goes as far as discussing android as a viable option. The “lock up your SIM” part is simply ridiculous too, this has never ever stopped anyone. This article is terrible because it has clearly been written by non-experts who should not be writing any security guides.

Interesting. I'm not an security expert, but believe locking SIM card with a PIN code is a reasonably good idea to ensure in case of a stolen smartphone (non-targeted) it would be more likely thrown out as useless rather than used for any nefarious purposes.

Or I'm wrong?

Re: A Guide to Not Getting Hacked

#66
post #41

Everything that's in this piece that's true is on the Tech Solidarity guide. What isn't, is false. https://techsolidarity.org/resources/basic_security.htm In particular: * Do NOT install antivirus on your computers. Antivirus software is absurdly dangerous. The closest you'll come to benign AV is Microsoft's, but that's an asymptotic kind of safety. * Do NOT go out of your way to funnel your traffic through a commerc…

Do NOT EVER use Tor Browser.

Is that a general recommendation against Tor? Or would you recommend another tool to someone who wants to use Tor? Tails?

One advantage of Tor Browser is the standardization. When using the Tor Browser, you look just like every other user of the Tor Browser.

Re: A Guide to Not Getting Hacked

#67
post #61

Earlier quoted context omitted.

It is explicitly warned not to use the Tor Browser under Whonix because the browser starts its own instance of Tor while Whonix already funnels every network request through its gateway Tor and Tor over Tor is supposedly undefined behaviour. So you have to go the additional step of disabling Tor Browser from starting its bundled Tor... Or under Whonix just use any normal browser like Firefox.

> any normal browser like Firefox. This is very bad advice. Do not use Firefox. It is not as secure as Chrome.

An example: https://stackoverflow.com/questions/42195095/https-is-secure...

Re: A Guide to Not Getting Hacked

#68
post #66
post #41

Everything that's in this piece that's true is on the Tech Solidarity guide. What isn't, is false. https://techsolidarity.org/resources/basic_security.htm In particular: * Do NOT install antivirus on your computers. Antivirus software is absurdly dangerous. The closest you'll come to benign AV is Microsoft's, but that's an asymptotic kind of safety. * Do NOT go out of your way to funnel your traffic through a commerc…

Do NOT EVER use Tor Browser. Is that a general recommendation against Tor? Or would you recommend another tool to someone who wants to use Tor? Tails? One advantage of Tor Browser is the standardization. When using the Tor Browser, you look just like every other user of the Tor Browser.

I don't think Tor is a good idea in general, but my categorical "never" is about the browser bundle.

Re: A Guide to Not Getting Hacked

#69
post #17

Earlier quoted context omitted.

It also recommends running an antivirus on desktop, using a VPN, using tor browser, pidgin and goes as far as discussing android as a viable option. The “lock up your SIM” part is simply ridiculous too, this has never ever stopped anyone. This article is terrible because it has clearly been written by non-experts who should not be writing any security guides.

Interesting. I'm not an security expert, but believe locking SIM card with a PIN code is a reasonably good idea to ensure in case of a stolen smartphone (non-targeted) it would be more likely thrown out as useless rather than used for any nefarious purposes. Or I'm wrong?

SIM card PINs are not discussed in the article. Instead they recommend asking your telcos support rep to attach a note to your account to prevent sim swapping, which doesn't work.

Re: A Guide to Not Getting Hacked

#70
post #62

Earlier quoted context omitted.

It is explicitly warned not to use the Tor Browser under Whonix because the browser starts its own instance of Tor while Whonix already funnels every network request through its gateway Tor and Tor over Tor is supposedly undefined behaviour. So you have to go the additional step of disabling Tor Browser from starting its bundled Tor... Or under Whonix just use any normal browser like Firefox.

That's not what I see on https://www.whonix.org/wiki/Tor_Browser It explicitly says "There is no Tor over Tor scenario in the Whonix environment." when using their modified Tor Browser.

Thanks. I stand corrected. I didn't realise they supplied their own modified Tor Browser...
Post reply on HN