Earlier quoted context omitted.
"If"? Are there any Tor users who don't need to worry about leaking their IP address? Then why do they use Tor in the first place? The Tor project itself seems to promote Tails much more than Whonix, which seems very odd to me.
After thinking about this, I agree with your point, but it's past me being able to edit my original comment to address this issue there. OK, now you have an IP. Now what? You get a warrant and search the place. What do you find? A computer, maybe an amnesic virtual machine. No actual access to the website/onion in question. IMO Tails promotes better opsec when using Tor - you don't leave any traces behind of your bro…
Javascript exploit actively used against TorBrowser
91–100 of 138 posts
Re: Javascript exploit actively used against TorBrowser
#92I feel like Tor Browser should just spin up a fresh VM with a minimal Linux distribution and fullscreen Tor browser, with the VM's only networking tunneled through Tor. I think Hyper-V can do graphics as well and it looks like bhyve added some sort of graphics support earlier this year, but xhyve has none. Not sure if there are any other lightweight hypervisors that support graphics (or maybe just use a protocol like…
> fullscreen Tor browser Tor recommends not going full-screen, since window size can be used as one of several identifiers.
Re: Javascript exploit actively used against TorBrowser
#93As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…
Is the situation with Firefox this dire, when compared to Chrome? Can anyone corroborate? This realization may be enough for me to finally switch, if so.
None of this would have helped Tor/TBB, because it's based on an older Firefox branch, with no sandbox at all. This means most vulnerabilities are exploitable and lead to a total compromise. There's relatively few of those and they get fixed very quickly, but if you use Tor you are likely specifically targeted so any hole is very serious.
Parent sounds so bad because he seems to grade security by seeing how many CVE's the developer publishes, ignores the fact that browser exploits are often done by exploiting attack surface outside the browser (because all browsers are - relatively speaking to other software - secure), and conflating Chrome vs Chromium.
This particular bug is bad (it's a 0day - a security exploit found by bad guys before Mozilla or security researchers found it) but a lot of the buzz here is because such problems are rather rare these days, and because it's targeting Tor.
Re: Javascript exploit actively used against TorBrowser
#94As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…
> When was the last time there was a reliable, public Chrome exploit with a sandbox escape? The only one I can think of was the Hacking Team exploit, which used a Windows kernel 0day to escape the sandbox. Don't forget that it's not just the sandboxing and Chrome/Chromium based browsers can mitigate entire classes of bugs thanks to win32k lockdown. A recent example was a Flash bug which required access to some of the…
Re: Javascript exploit actively used against TorBrowser
#95Earlier quoted context omitted.
After thinking about this, I agree with your point, but it's past me being able to edit my original comment to address this issue there. OK, now you have an IP. Now what? You get a warrant and search the place. What do you find? A computer, maybe an amnesic virtual machine. No actual access to the website/onion in question. IMO Tails promotes better opsec when using Tor - you don't leave any traces behind of your bro…
You look at this from the privacy perspective of someone who wants to hide something within the constraints and confines of a working - and at least somewhat ethical - legal and judiciary framework. The original use case for Tor is for people who actually need to be able to use the net and hide. If their location and they get it with the equivalent of their local government's "search warrant", it's more likely a raid…
> If their location and they get it with the equivalent of their local government's "search warrant", it's more likely a raid, interrogation, threats, harassment, censorship, and possibly torture and death.
This is not who is primarily using Tor. 1/5 directly connecting users of Tor are in the United States. See:
https://metrics.torproject.org/userstats-relay-table.html
This doesn't change even for bridge users:
https://metrics.torproject.org/userstats-bridge-table.html
So, the majority of Tor users are in places I think we'd consider have somewhat working judiciary frameworks. And I'm highly skeptical of even the American judiciary framework, if you read some of my past posts.
You are correct, my original threat model was those Tor users and their use cases; if they are in FVEY territory they are probably already lost as Tor does not protect against "passive global adversaries" that FVEY IC has proven to be and may be able to be probabilistically deanonymized as was shown in the Snowden slides. [1]
Yes, I admit I should have been thinking more deeply, and my original advice isn't good enough. I have a tendency to not think things through fully before posting here, and then I edit/evolve my thoughts as time goes on, as one does in a verbal discussion.
Like you stated, clearly there are situations in which users rely on Tor for more than simple anonymity. They are already misguided in using the Tor Browser Bundle for this purpose. Use Qubes or Whonix on dedicated hardware, follow the grugq's "Opsec for Hackers" [1]. If the threat of information is torture and death, Tor alone is not going to save you from your adversary. Your threat model requires a hell of a lot more precautions than anonymity over the wire. You need to assume your tools are compromised and defend in depth as much as possible to make yourself a lot, lot harder to track.
If you are using Tor Browser Bundle on Windows, you fucked up already. If you are only using Tor Browser Bundle, you fucked up too. If you are using Tor on your home connection, nope. If your device leaks identifying information to your access points (MAC addresses, hostnames), negative. If you are not using FDE on the device when they come for you, you are toast, etc etc.
If your adversary is a powerful nation state or an organization with the ability to purchase exploits to use against you and they are willing to fuck you up physically, you have a big problem and you need bigger solutions. No anonymity project will be enough. You need to frustrate your adversary as much as possible and realize that your security comes from making you very expensive to track down, and hope they don't care enough. You are playing the game where you are angering the bear and attempting to be faster than the other guy, so that the other guy who didn't care as much is the one that is eaten.
If they do care enough to come for you, and they have the resources to break a lot of layers to get to you, and you do not have any meatspace power to fight or flee, you are highly unlikely to win.
If that's the "whole different ball game" you are playing and are just using TBB, you will lose. If your adversary is that strong or you have your life to lose, and you are likely being targeted, it is clear at this point that Tor Browser Bundle should be considered harmful without a better strategy of defense in depth.
[1] https://www.theguardian.com/world/interactive/2013/oct/04/to...
Re: Javascript exploit actively used against TorBrowser
#96Earlier quoted context omitted.
The same vulnerability apparently also exists in Firefox, which Tor Browser is based on.
But its worse on Tor. Regular internet has a few protections: 1. Google safe browsing 2. AdBlocking 3. Websites try to keep their reputation. Tor exit nodes, on the other hand, have no reputation (and if one gets sullied, spin up another) and costs money.
Oh is it? The exploit for upstream Firefox on Windows is now completely public, free of charge. How is that worse on Tor, where most people using it have idea that JS and 3rd party connections should be blocked?
Re: Javascript exploit actively used against TorBrowser
#97Earlier quoted context omitted.
Is the situation with Firefox this dire, when compared to Chrome? Can anyone corroborate? This realization may be enough for me to finally switch, if so.
There's no questioning that Chrome's sandbox implementation is ahead of Firefox: they've been shipping it for several years, whereas Firefox only got its first one out in Firefox 50 (for content! They had a Flash sandbox and DRM/media decoder sandbox for longer), with the more strict ones being in the Nightly/Dev Edition branches. It's possible the real Firefox is not vulnerable to this exploit because of that, but w…
By counting CVEs alone, Chrome would be the least secure since it has more CVEs than any other browser thanks to Google's bug bounty and fuzzing, most of them harmless.
What I counted were real-world browser exploits which is an excellent measure of security.
> such problems are rather rare these days
In Chrome, yes. They happen rather often with Firefox.
> conflating Chrome vs Chromium
Their security features are identical. It's the same code.
Re: Javascript exploit actively used against TorBrowser
#98Earlier quoted context omitted.
What's their biggest struggle with it? PS, if you're ever on the US West Coast or in Singapore, drop me a DM. I'll buy you a drink someplace.
Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…
Re: Javascript exploit actively used against TorBrowser
#99I feel like Tor Browser should just spin up a fresh VM with a minimal Linux distribution and fullscreen Tor browser, with the VM's only networking tunneled through Tor. I think Hyper-V can do graphics as well and it looks like bhyve added some sort of graphics support earlier this year, but xhyve has none. Not sure if there are any other lightweight hypervisors that support graphics (or maybe just use a protocol like…
> fullscreen Tor browser Tor recommends not going full-screen, since window size can be used as one of several identifiers.
I would expect a generic resolution like 1920x1080 to convey much less identifiable information that some random 1583x1176 that the user might resize tor browser window to.
Re: Javascript exploit actively used against TorBrowser
#100As much as I love Mozilla and their philosophy, it has to be said that - if you have any sort of worries about security - using Firefox is a bad choice and borderline reckless. It lacks even basic exploit mitigations that other browser have had for years now (most importantly a feature-complete sandbox). Right now, Firefox is just a single process with zero separation of privileges. Any bug in the rendering code is a…
Last time I checked, it was just for process separation and did not provide any security guarantees. It's a separate project from e10s (though it depends on it): https://wiki.mozilla.org/Security/Sandbox Chromium had a fair bit of sandbox escapes during the first years, and there's no reason to believe this is going to be different with Firefox. I agree. Note that people still find sandbox escapes against Chrome anyw…
See my reply below. Counting exploits, not CVEs. By CVE count, Chrome would be the worst.