There are cases where using the Tor Browser makes sense, but it's a terrible blanket recommendation. If you're not actively trying to hide your identity, using it will make you less secure than you would otherwise be.
Is it? Please provide references.
> and you mark yourself out as an interesting target/
Yeah that seems likely.
> Using Chrome over Tor is strictly better from a privacy viewpoint than using Chrome on its own.
Is it? If Chrome leaks any local information this is not true. NB I do not know if Chrome does so but please refer to https://blog.torproject.org/blog/bittorrent-over-tor-isnt-go... for an example of what I am getting at.
> If privacy is your absolute priority, the Tor Browser reduces the number of cases of information leakage but still requires you to have the discipline to avoid any other methods of leaking your identity.
Yes. But Tor Browser is released specifically to help you manage this. Information leakage through the web browser is amazingly easy - and it doesn't take logging onto a website to be finger printed (Chrome over Tor is probably a fairly unique fingerprint on its own). Why not find out for your self how unique at https://panopticlick.eff.org/
> If you understand all the issues around that then you probably also understand enough to ignore Tptacek and use it anyway.
No comment.
> But if you don't, using the Tor Browser leaves you in a worse position than you'd otherwise be in - you're less secure and you're probably leaking PII anyway.
Doubt it but again citations needed.
> There are cases where using the Tor Browser makes sense,
agreed.
> but it's a terrible blanket recommendation. Citation needed.
> using it will make you less secure than you would otherwise be. Citation needed.
Sandboxing alone justifies this.
> If Chrome leaks any local information this is not true.
Leaking information over Tor is no worse than leaking it over non-Tor, and in general cases Chrome isn't directly sending information that allows a single site to identify you.
> Chrome over Tor is probably a fairly unique fingerprint on its own
What's your threat model? That's a serious question.
> Leaking information over Tor is no worse than leaking it over non-Tor, and in general cases Chrome isn't directly sending information that allows a single site to identify you.
More like: Leaking local information over Tor is equivalent to not using Tor, and in general cases the user has no control over what data Chrome is sending.
The OS is in no position to sandbox multiple tabs running in the same browser good grief
> More like: Leaking local information over Tor is equivalent to not using Tor
This isn't even slightly true
> in general cases the user has no control over what data Chrome is sending.
Nor do they have any control over what data the Tor Browser is sending. At some point you have to trust that your software is doing what it's supposed to do.
If privacy is an absolute priority for you, then yes, run Tor Browser. But be aware that in return for privacy you're giving up security. For most people that tradeoff will result in less privacy in the long run. If someone isn't in a position to make an informed choice, a blanket "Use Tor" recommendation may do much more harm than good.
Who said anything about tabs?
>> More like: Leaking local information over Tor is equivalent to not using Tor
> This isn't even slightly true
There is no middle ground. There are two states here. Anonymous and not anonymous. Once one is not anonymous they are not anonymous. If one leaks one's local IP one is not anonymous. If one leaks one's voice data one is not anonymous.
> At some point you have to trust that your software is doing what it's supposed to do.
I agree. The thing is that Tor Browser is supposed to be limiting data leakage whilst Chrome is supposed to be sending data to Google.
If all your tabs run in the same process, any vulnerability triggered by malicious content in one tab has access to all the content in any other tab. Sandboxing the brower process makes it more difficult for that to result in taking over your entire system, but in this case merely taking over the browser is sufficient.
So no, OS-level sandboxing isn't sufficient. And if you don't understand that, you should not be making assertions about security.
1) Chrome over Tor? I've read that they don't integrate well (but I know very little about it).
2) Chrome to a (secure) VPN? How does a typical end user find a secure VPN?
3) ?
A good point. Though in fairness, that's why I included Chrome over a VPN as an option.
> The information stored on their computer is far more sensitive than the list of sites they visit.
Not that it invalidates your points, but I wonder how true this one statement is. First, remember that in addition to metadata Tor hides content (which may be redundant in the case of HTTPS-secured websites, but that's not a bad thing). Also, a journalists' metadata could tell you a lot about the who, what, when, where, why and how they are researching, and expose sources.
What is more valuable, knowing who a journalist is talking to and when, or knowing what was said? IM very HO, I think the former.