Mozilla CTO: "Maybe we should just adopt, support, and bundle Tor in Firefox..."
twitter.com
twitter.com
If they can somewhat manage to keep the user experience not complete disappointment this will be the biggest steps forward to a broader privacy adoption.
All those tools such as PGP, TrueCrypt, VPNs, have completely failed to reach beyond a bunch of paranoid geeks. Mozilla has the key towards achieving a mass scale adoption.
Implementing this would most likely at least double the current amount of TOR users, making this a complete nightmare for the NSA and their associates.
If Mozilla were to incorporate a "Tor Browsing Mode" analogous to "Private Browsing Mode" that "just worked" and didn't leak data, then Tor use would explode. Even just 0.1% of firefox's userbase would make a huge difference.
Aside from all that, if you don't significantly modify your browsing habits, all you've now done is increase your interestingness to the NSA et al. and made your browser run slower and use more RAM.
So, there is a bit more involved than running an executable.
https://www.torproject.org/projects/torbrowser.html.en
I'm probably still missing a few layers of security if I want to order a pound of purple kush or a hitman or something though (right?)
As far as it being slow to load sites, there will always be a high latency when using Tor. It’s the nature of onion routing. If Tor becomes more popular, I’m hoping there will be a way to donate to high bandwidth exit nodes to keep the network performance up.
I think a more helpful move in response to the exploit would be working towards having tor base their bundle on more up to date versions of firefox.
https://blog.torproject.org/blog/new-tor-browser-bundles-and...
The number of affected users must be due to not upgrading. Does the tor bundle automatically update?
The problems Tor would bring users in terms of slow connection, risk from malicious exit nodes etc. would outweigh any benefit for most people. Combine this with the fact that to gain anonmyity from Tor you'd need to (at least) disable JS and session cookies, which many ordinary users will consider to break their browsing experience, and you'll find that really all this idea would do is put a lot more load on the Tor network. That's assuming a 'default on' option.
Perhaps an 'anonymous mode' version of 'private browsing' which switches the browser to a more secure configuration (like the Tor browser) and proxies through Tor would mitigate some of these problems.
If you had noticed from the tweets, it appears that Mozilla has been slow to adopt Tor's patches.[1][2] Making Tor a supported feature would greatly alleviate this situation.
[1] https://www.torproject.org/projects/torbrowser/design/#firef...
[2] https://www.torproject.org/projects/torbrowser/design/#firef...
Maybe not common knowledge, but if you do search queries of those types, your ads in Youtube, Google, and other areas are likely to change. Their business model is to target ads based on previous searches. If you then share the network with other family members, those ads will pop up on their screens to.
- many users would get malware-injected web pages from shady exit nodes (they would become a much more interesting target for phishing/other malware than they are now)
- it would no longer be practical for web sites to block Tor as a defence against excessive scraping, spam posts, fake reviews (currently most Tor traffic to "normal" web sites is of that kind)
b) as someone who does her mindless random browsing through tor that sounds wonderful.
If this is implemented:
1. Firefox, with its insane public reach, can substantially heighten the awareness of privacy issues.
2. Government will have to get creative to subdue a highly popular heavyweight like Mozilla.
And as already mentioned, it might be the best response, as of yet, to the NSA fallout. It can potentially seriously alter the power balance between the Big Brother and us, people.
What I'd also love to see (but am a little uncertain on how to implement) is tab isolation for sessions- I don't want the Facebook like button on <x site> to read my Facebook login on my other tab. Right now I can use incognito windows and Chrome extensions to achieve that, but it's messy.
Having it built in, and defaulting to On when you open a private browsing window would be nice though.
More relays and endpoints would be needed, but I wonder how kind of support could be gathered if Tor was publicized in such a way.
What would be smart, which we are looking at: adopting, supporting, and bundling Tor (opt-in). As I tweeted.
It is 'support' as in activism in the vain of "Know your rights" first-run messages Firefox runs, 'etc. It frustrates me when the solutions hacker types come up with either exclusively revolve around code or are not well thought out (like this suggestion).
edit: seems to be already fixed in ESR 17.0.7
A VPN will protect from a MITM attack, obscuring the resources you're accessing and the data exchanged to an observer. However, it does not anonymize you from the VPN provider, who can still disclose your information or be compelled to provide it. (you undoubtedly had to pay for that VPN with a legal name and payment information.)
Tor not only protects against MITM, but obscures the requester such that if an interested party can either force information from, or controls the endpoint, they cannot discover who the requester is.*
(* Provided that the requester is not divulging information in the form of cookies or other personally identifying information. If Mozilla were serious about providing native Tor functionality in Firefox, they'd no doubt provide it as part of the browser "Private" mode.)
Edit: This link doesn't cover VPNs, but gives a good idea of how different services provide security at different levels. VPNs obscure the "site.com" along the route, while the location in all locations as shown as the VPN provider, and not the end user. However, because the VPN provider knows the identity of the user, it can potentially disclose this info. A Tor endpoint does not know this. https://www.eff.org/pages/tor-and-https
I used Bytesized-Hosting, which allows you to pay for their VPS with bitcoins. I only had to provide a username, password, and a junk email address. AirVPN, among other VPN providers, also allow you to pay with Bitcoins, which can be anonymized over TOR for that particular transaction. I am not sure how much it helps protect the conifdentiality of the user, but many VPNs also claim to delete their OpenVPN logs immediately after a session has ceased. Though, I suppose if a three letter agency wanted dirt on someone, this policy would be easy enough to circumvent.
However, for most, it's an inconvenience that presents a barrier to entry. (Judgements aside.)
As for logs, it would be great to believe that they would be true to their word. However, that requires placing trust in the service provider. While I would give the benefit of the doubt in that most probably are true to their policy, I wouldn't want the weak link in my security chain to be the faith that my VPN provider isn't logging.
Regardless, since they are hosting the connection, they can discern the user. The capability exists, even if they promise not to use it. Removing the capability eliminates this source of worry.
Going back to the original post and kishor's comment, he/she highlights the point that regarding the technical solutions available, there's a range between having the most security solution, and the fastest and most convenient. Tor, VPN+anonymized payment and other methods will provide a greater degree of protection than say, using your credit card to simply buy a VPN.
At the end of the day, one needs to assess their security requirements against the degree of inconvenience they're willing to endure. Are they at risk of a nation-state ruthlessly pursuing them by any means? If so, then every protection is needed. If it just needs to be made difficult enough to protect against a cursory inspection, then a VPN might suffice. As with all security discussions, The likelihood and potential impact of the threat determines the degree of mitigations one needs.
I should have listened to the little voice telling me to change "undoubtedly" to some other "likely, but not definitely" term.
I'd be curious to know how often that works.
Regardless, I suspect most don't do that.
"Show me all VPN startups in country X, and give me the data so I can decrypt and discover the users.
*~These events are easily browseable in XKEYSCORE"*
http://www.extremetech.com/wp-content/uploads/2013/08/xkeysc...