Live data from Hacker News

Security Vulnerability in Tor Browser

darknetlive.com

61–70 of 156 posts

Re: Security Vulnerability in Tor Browser

#61
post #15

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

For everyday browsing I use NoScript, and rarely allow JS to run (I don't have JS right now!). With Tor, JS is always disabled, 100% of the time. Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.

Most important of all porn doesn’t work

Re: Security Vulnerability in Tor Browser

#62
post #53

Earlier quoted context omitted.

> Lets be real, you need to be using JavaScript for the internet to be functional, Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security envir…

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

> YouTube, Twitter and Instagram

We clearly have very different lifestyles and values. For me that's the dank basement of the internet,

Re: Security Vulnerability in Tor Browser

#63
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

This is deeply misleading and based on old data. > A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Tor Browser ships updates as soon as new ESR versions come out. > Firefox is already not one of the most hardened browser engines. That might've been true in the past, it's…

FYI I’m seeing a 404 from that last link.

Is this the intended link?

https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browse...

Re: Security Vulnerability in Tor Browser

#64
post #5

Earlier quoted context omitted.

Or don't use JS, which has long been a best practice with Tor. > The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Nonsense. I was hired freelance to create a web forum for someone who wanted it to run on Tor and making everything work without JavaScript was the top requirement. The guy wanted an option to enable JS for those who were willing to trust it, but it was disabled by default and I designed all parts of the forum to run without JS.

Re: Security Vulnerability in Tor Browser

#65
post #4
post #2

A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Firefox is already not one of the most hardened browser engines. Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to…

What about the Brave browser in a private window? That used Tor but theoretically also has some added protection because of the browser. I’d love to hear your thoughts.

Brave browser has a notoriously bad history with their tor implementation. Would not trust [1].

Brave’s Tor mode, introduced in 2018, was sending requests for .onion domains to DNS resolvers, rather than private Tor nodes. A DNS resolver is a server that converts domain names into IP addresses. This means the .onion sites people searched for, with the understanding those searches would be private, were not. In fact, they could be observed by centralized internet service providers (ISPs).

[1] https://www.coindesk.com/tech/2021/02/22/brave-browser-was-e...

Re: Security Vulnerability in Tor Browser

#66

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

Nonsense. I was hired freelance to create a web forum for someone who wanted it to run on Tor and making everything work without JavaScript was the top requirement. The guy wanted an option to enable JS for those who were willing to trust it, but it was disabled by default and I designed all parts of the forum to run without JS.

No one said it's possible to design a site without JavaScript, just that for the vast majority of the internet, including sites user's rely on, it's unusable without it enabled.

Re: Security Vulnerability in Tor Browser

#67

Earlier quoted context omitted.

Lets be real, you need to be using JavaScript for the internet to be functional, even within Tor. Anybody claiming they regularly use the internet with JS disabled is just lying for some sort of feel of superiority.

You say that on a website where you don't need JavaScript either.

Rumor is that there are dozens of websites that work without JavaScript.

Re: Security Vulnerability in Tor Browser

#68

Earlier quoted context omitted.

This is deeply misleading and based on old data. > A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project. Tor Browser ships updates as soon as new ESR versions come out. > Firefox is already not one of the most hardened browser engines. That might've been true in the past, it's…

FYI I’m seeing a 404 from that last link. Is this the intended link? https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browse...

Thanks, corrected.

Re: Security Vulnerability in Tor Browser

#69
post #53

Earlier quoted context omitted.

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

> YouTube, Twitter and Instagram We clearly have very different lifestyles and values. For me that's the dank basement of the internet,

No post body was provided.

Re: Security Vulnerability in Tor Browser

#70
post #59
post #53

Earlier quoted context omitted.

Wow, talk about proving the parent's point. I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft). YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login. I think you are incorrect with your "nonsense" judgement, as this top-10 sampling…

If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?” I also prefer w3m and find most of the web much better as text only, switching over to another browser when I want video or some other JS feature. Or I can use something like youtube-dl to fetch a video. And there’s much more out there than the top 100 websites.

> If I told you I don’t listen to the Billboard top 100 songs, would you say “nonsense, you don’t listen to music?”

No, but the reponse is more like: I only listen to Indie, Billboard isn't music.

The vast majority of internet traffic, e.g., the most popular sites, mostly require JS. If you only visit obscure indie-rock sites, then fine, but we're talking about the masses, not the small niche exceptions.

Post reply on HN