Live data from Hacker News

Tor Browser 10

blog.torproject.org

81–90 of 106 posts

Re: Tor Browser 10

#81

Is it worth it running the Tor Browser without Tor itself if I wanted a Firefox version without Mozilla, pocket and tracking?

I use GNU Icecat [1]. It is Firefox ESR rebranded, without Mozilla, tracking, pocket, etc. Please note that it does come with some fairly opinionated addons. LibreJS blocks all nonfree javascript for example. You can of course disable these addons if you find them too cumbersome.

[1] https://www.gnu.org/software/gnuzilla/

Re: Tor Browser 10

#82

Earlier quoted context omitted.

Yeah they need to hack or infiltrate Github, or get a warrant for your data.

Good thing Microsoft isn’t voluntarily in the PRISM progra-

Taking bets on "Microsoft was nudged into buying GitHub by one of the three letter clubs" being revealed one day

Re: Tor Browser 10

#83
post #78

Earlier quoted context omitted.

We’re all on many lists. What matters is where you rank on it.

I would think that not being on any of lists would be so suspicious on its own, it would warrant adding to a list.

Mumble mumble, Bertrand Russell, mumble...

Re: Tor Browser 10

#84

Earlier quoted context omitted.

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

Obviously your web browser doesn't know if this is "just" some Wix brochureware site where you don't actually care about security or if it's a bank or your webmail or the passport office. So to keep browser users safe we need to deliver the security they expect all the time. The rule has to be consistent, either the rule is "TLS 1.0 is no good, stop that" or it's "TLS 1.0 is fine, First Bank of Springfield can keep r…

Well that's fine, but banks and Gmail (and even Wix sites) will advertise TLS 1.2+ and be just dandy as the web browser will choose the latest and greatest.

But what harm does allowing 1.0 if you want to read a static HTML web page from 2001 about the Cowboy Bebop anime series?

Re: Tor Browser 10

#85

Earlier quoted context omitted.

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

My understanding is that the general argument is that if we all require security for comedy browsing, the traffic of the people who require better security is better because it’s less conspicuous? See also declaring your personal pronouns as someone who thinks they will never be misgendered, or using Tor for normal browsing

As I stated: I'm not against crypto in general (even for "comedy browsing") as it helps against mass surveillance. I'm just not sure as to what disabling 1.0 in the browser does.

People who really care can enable 1.2+ on their servers and the browser will use it, but someone who just has a site up 'for fun' could be cut off.

In some ways it motivates people to not even bother with HTTPS because it now because higher maintenance to keep up with all the settings. This could actually encourage just leaving HTTP, which could be worse.

Re: Tor Browser 10

#86

Earlier quoted context omitted.

For general day-to-day browser of random websites for amusement, is there a particular reason why we should care? I'm not against more crypto generally to help reduce mass surveillance, but how many Wix / Square Space / free WP/Blogspot sites actually need to have TLS 1.2+?

The reason is that encrypted websites are a bit harder to hack and inject malicious code into. In particular MITM attacks are much harder to pull off - such as those by airport/mall free wifis. Using the latest version of TLS makes us safe from hacking.

Using TLS in general, regardless of version, makes us safe(r) from hacking as it prevent injection.

What how does disabling 1.0 specifically do?

Re: Tor Browser 10

#87
post #72
post #68

Earlier quoted context omitted.

Maybe in the west that'd be true- since we can freely trade information over the public internet, TOR doesn't have much utility. Let's say you're in a more totalitarian government that censors more information- TOR might look like a practical solution there, and might have people using it for more practical purposes.

> since we can freely trade information over the public internet No we can’t.

Don't be pedantic, you're doing it right now.

Re: Tor Browser 10

#88
post #49

If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

If your adversary was a state, they probably control most of the exit nodes you connect to.

Re: Tor Browser 10

#89
post #72

Earlier quoted context omitted.

> since we can freely trade information over the public internet No we can’t.

Don't be pedantic, you're doing it right now.

He's right, it is a pretty big if, since storage space and compute power are basically free for NSA/CIA (and they have shown they don't care about privacy laws or the 4th amendment) you can safely assume all your traffic and data is stored away somewhere for future usage against you. If you're in Europe you are probably a bit safer.

Re: Tor Browser 10

#90
post #88
post #49

If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

If your adversary was a state, they probably control most of the exit nodes you connect to.

Depends on which state is your adversary I guess?

US or someone from 5 eyes? Yes for sure!

Algeria? You're probably safer

Post reply on HN