Live data from Hacker News

Tor Browser disabled NoScript, but can't update

lists.torproject.org

91–100 of 125 posts

Re: Tor Browser disabled NoScript, but can't update

#91
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

Certificates can be renewed or revoked that's literary a switch. That the apparatus before or after switch is more complicated is irrelevant.

Re: Tor Browser disabled NoScript, but can't update

#92
post #86
post #74

Earlier quoted context omitted.

Not sure of the Firefox implementation; just pointing out revocation isn't necessarily straightforward.

The way I understand it is: certificate revocation is handled by checking OCSP servers, and OCSP servers can be programmed so they give different answers depending on the IP address of whomever is asking. In other words, it should be possible to disable all addons for a selected user by targeting him by IP address.

That is such a massive security flaw, and if any other company had such a power over my browser experience I would drop their product immediately.

Mozilla, you've really been testing my patience for the last two years.

Re: Tor Browser disabled NoScript, but can't update

#93
post #2

If Mozilla hadn't locked down Firefox so much, the fix could have been as simple as going into about:config and flipping a switch to allow unsigned plugins.

And if only my company would allow me to FTP into our servers directly I could hotfix a problem in production much faster.

...which is to say, it's a trade-off, and though you can disagree with the weight Mozilla assigned to the pros and cons, their reasoning was valid.

Re: Tor Browser disabled NoScript, but can't update

#94
I remember saying over and over again that using Firefox for the TOR browser was a horrible idea.

Use curl -H "" and links --dump. Until we have something sane that's really the only safe way to browse TOR if you actually have something to hide.

(There's dillo and other things like the absolutely horrifying browser I've been writing but that hardly even supports forms right now heh. but I'm worried about connecting stuff like that to stuff like TOR)

Re: Tor Browser disabled NoScript, but can't update

#95
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

If I'm not mistaken, then very well could revoke the intermediate certificate if they wanted. This wasn't a case of that, but it seems it could happen.

Does the intermediate have an OCSP URL, and/or does the CA that signed it have a CRL URL?

One or both would need to be true for a normal revocation to have any effect.

Re: Tor Browser disabled NoScript, but can't update

#96
post #86
post #74

Earlier quoted context omitted.

Not sure of the Firefox implementation; just pointing out revocation isn't necessarily straightforward.

The way I understand it is: certificate revocation is handled by checking OCSP servers, and OCSP servers can be programmed so they give different answers depending on the IP address of whomever is asking. In other words, it should be possible to disable all addons for a selected user by targeting him by IP address.

Seems that Firefox skips revocation checks for CA certs [1].

[1] https://wiki.mozilla.org/CA/Revocation_Checking_in_Firefox

Re: Tor Browser disabled NoScript, but can't update

#97
post #49

> Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim Am I the only one annoyed by people pushing this "they flicked a switch" narrative? No. They provided shitty software that didn't work under certain conditions (in this case date related) and thus broke your shitty software. A third party having remote control capability is something entirely different.

Letting a certificate expire is the same as flicking a switch IMO. Mozilla is a real organization with full time paid staff, things like this don't just slip through the cracks, especially when the 'fix' is to let Mozilla run spyware on your computer.

Your comment has a lovely silver lining: You believe it’s impossible for Mozilla to make such a mistake by accident! Anyone would be cheered to hear that, if presented positively; so I hope my callout of this can help the Mozilla folks working on this smile a little at the faith in them it shows.

Re: Tor Browser disabled NoScript, but can't update

#98
post #30
post #24

Earlier quoted context omitted.

It's a dumb comment. There was a ton of malware being distributed as add-ons that came packaged with other installers. This solved that issue.

Burning down London stopped the plague too.

The Great Fire burned central London long after the plague had moved to the poorer outer areas of the city, where it continued to die out gradually unaffected by the fires elsewhere.

Re: Tor Browser disabled NoScript, but can't update

#99
post #94

I remember saying over and over again that using Firefox for the TOR browser was a horrible idea. Use curl -H "" and links --dump. Until we have something sane that's really the only safe way to browse TOR if you actually have something to hide. (There's dillo and other things like the absolutely horrifying browser I've been writing but that hardly even supports forms right now heh. but I'm worried about connecting s…

OTOH the more people who use Tor, the more anonymous everyone on the network is, so having a usable version is important.

https://www.freehaven.net/anonbib/cache/usability:weis2006.p...

People with heightened privacy concerns can always use Whonix or Tails instead.

Re: Tor Browser disabled NoScript, but can't update

#100
post #88

Earlier quoted context omitted.

Letting a certificate expire is the same as flicking a switch IMO. Mozilla is a real organization with full time paid staff, things like this don't just slip through the cracks, especially when the 'fix' is to let Mozilla run spyware on your computer.

I think almost anyone who has worked at real organisations with full-time paid staff can tell you that things do slip through the cracks. At least I can.

I do security for a large Enterprise. You'd be surprised how unorganized some of this shit is.
Post reply on HN