901614 – Adopt Tor as a feature in Firefox
bugzilla.mozilla.org
bugzilla.mozilla.org
Even enthusiasts mix up the anonymity offered with Tor with security.
I can almost guarantee that this will do waaaay more harm than good. People will enable this and think they are safe while they are suddenly routing all their cleartext through an untrusted third party (that is, very often, malicious).
At the very least a lot of passwords will be gathered (alongside email in a lot of cases) in insecure and unencrypted forums etc. And since most people have the same password for unencrypted forums as their email, facebook and twitter...
For this to work it will have to be an option buried deep and before enabling it you'd have to have a huge nag box (the size of a blue screen) that clearly shows the dangers of this. And although many have tried I haven't seen any implementation of such a nag box that actually works (forces the user to think and not just press "OK"/"YES"). And even if it did work people won't understand it, at most they will understand that "okay, this is risky" but they have no way of evaluating that risk since they have no idea what they really are enabling.
That said, Tor inbuilt into firefox would be awesome. I just can't imagine it doing more good than harm.
For example, while I visited the US it happened at 2 motels I stayed at for their network to insert ads in the web pages I was visiting. So they where not only snooping my traffic, but going further into altering it. Also, go to any conference or gathering of people, create an open Wifi hotspot (like, with your phone) and then enjoy all the cookies and passwords flowing through, from all the clueless people that connect to it.
Truth of the matter is, websites should be secure by default. Those that aren't represent a huge security risk. Fortunately many of the big ones are (e.g. GMail, Twitter, Facebook, etc...)
Also see:
I interpreted tjoff's argument to be that the average Tor exit node is more malicious than any of the other average ways for proxies to be dangerous. In other words, yes coffee shops could be dangerous, but they are most often safe, whereas if you're getting routed through a bunch of exit nodes over a period of time (is that even how it works?) you stand a much greater chance of running into malice.
Would love to hear someone address that claim as I understood it.
If the connection is encrypted, then you have to trust the certificate authority, the browser and the service provider. If the connection is unencrypted, then in addition to the above, you have to trust that nobody is listening on that connection and that's a really tough pill to swallow, even if nothing bad happened to you in the past (just like with car accidents, it needs to happen only once to mess up your life).
If you don't think bad things happen all the time in the wild, see this story of Ashton Kutcher's Twitter account being hacked while attending TED: http://www.huffingtonpost.com/2011/03/02/ashton-kutcher-twit...
Totally false claim. I would bet my ass that there is higher probability to have your traffic sniffed by tor exit nodes than by regular ISP's. At least for short-term malicious purposes, like email snooping and credit cards.
(For more long-term malicious purporses, NSA etc., you can't be really sure.)
Totally false claim. The biggest nodes on the tor network is run by established tor enthusiasts, and the largest portion of traffic is routed through them. Social pressure makes those people unlikely to put the node in jeopardy by sniffing exit traffic.
However, there is not much that would deter a coffee shop employee against sniffing the wi-fi, or for that matter, making them care to secure the router against would-be-attackers.
As such, I would be that there is a higher probability to have your traffic sniffed when visiting the local coffee shop, than by a tor exit nodes.
These issues are trivial compared to the bigger issue at play: the right to read and to write without exception.
That is what is at stake here.
Exits sniffing passwords for plain-text forums is a minor concern compared to the bigger issues at play. I'd like to point out that it's trivial to test for this too...(create some plaintext accounts on forums, post there, then run a honeypot server with your own email address and see if you get a login, do this automatically for each exit) However the time commitment isn't so trivial: If you wrote such a program it would be appreciated, please yell loudly about it on the tor-talk list if you do! Tor works by and large by people following some basic principles, like "if you think it should be done, do it".
You could also see the issues with plaintext passwords on HTTP sites and password reuse as a problem of user education. If you're not up for writing software, why not open a bug and suggest some wireframed ideas for how a UI could look to prevent password reuse? There is a whole bunch of ways to contribute.
There are literally 100's of problems like this Mozilla or Tor could get help with... get involved instead of ahead of time saying "This can almost guarantee that this will do waaaay more harm than good." I hope to see your responsible posting of these concerns to a bug tracker. A lot of what gets done in FOSS projects like Tor really is just a bunch of people who've decided "hey, if I don't do this, who will?".
As for doing more harm than good: I can't possibly see how this does more harm than NSA domestic surveillance.
Won't work. People have too many accounts to be able to remember unique passwords. A large percentage of mundane users won't understand these things and will just be nagged all the time that they cannot log into their accounts with this new Firething.
You'd need to warn them before they even start typing a password in on an http page.
This does require the browser to know which passwords are which, though, at which point it might as well be entering them for you (and only being willing to do that over https).
The lack of a proposed solution does not make the identification of a problem worthless. Writing code is as much part of the process of solving problems with software as identifying those problems is. When a problem is largely a social one, rather than a technical one, identifying the problem and making people aware of its existence is often the bigger part of the process.
Tor guarantees anonymity. It succeeds at that. There is no technical problem. There is no code to write. This could lead you to think there's a problem with scope, that maybe Tor should guarantee security too. Unfortunately, the design of Tor is not compatible with that goal: if your plain text data goes through an exit node, then by definition, that exit node gets to see what the data is. A bug report titled "Tor does not provide secure communication" would get closed faster than you can say "won't fix". And rightfully so.
There is, however, a social problem, as stated by the OP: many people actually expect security. This is a problem that can only be solved by educating as many people as possible that this is the wrong expectation to have, which is what the OP is contributing to by making this post. This is very much in the spirit of "if you think it should be done, do it".
Doesn't it fail at anonymity if the entire internet is being monitored?
If OP has ever used Tor, he would know that the performance hit is so huge, that no-one in there right mind is going to leave it on by default, if that's even an option. In OPs myopic view, he's missing the fact the the added benefit built in anonymity to all FF Users far outweighs this hypothetical security risk.
No it does not, it is always best to use a seperate browser for tor because your browser & OS fingerprint is significant
https://panopticlick.eff.org/index.php?action=log&js=yes
And that is ignoring the fact that most people will continue to login to the HN and facebook accounts.
I always thought that one possible way around this would be for websites to generate the passwords for their users, essentially forcing them to use some sort of password storage (either in the browser, or LastPass, or whatever-you-want). So one would register with just an email address/username and then be shown a generated password à la O5O1zn8H3zEGNjf1Ly8v to store in the browser’s password manager.
Of course, this only works if people only ever use the service from devices they own and I have absolutely no idea how common internet café/public library users are nowadays.
It seems like a more modular approach than using Facebook or Google to sign into third party sites, but similarly secure in terms of exposing passwords.
One extension, of course, would be for websites to somehow signal to browser ‘Hey, please store this password/username for this website’, but I’m not sure whether that's necessary.
It cuts both ways. I don't understand why you meta-comment, instead of going fixing those things yourself.
Whereas if I'm just telling people "this is no good, it needs fixing" then not only am I not helping, I'm not persuading other people to help either.
The main premise is wrong too: "if I'm just telling people "this is no good, it needs fixing" then not only am I not helping, I'm not persuading other people to help either.".
Lots of things that are no good NEED to be pointed out. Project members don't magically see all of them.
Either because they don't have that particular use case themselves, or because they haven't thought it that way, or they think it's not important but the users think otherwise, or they have invested too much in some design that they cannot admit it's flawed, etc.
Pointing things out helps making those flaws visible, helps start a discussion, makes the opinion of potential or actual users known, etc etc.
Telling people to go and help is very secondary to that. I don't think many people ever got motivated because of some second-hand meta-comment from someone not even involved in the project.
How about false sense of security? Zero improvement in security plus baseless confidence that you are now secure sounds like a step backwards to me! It's already suspected that NSA has been working around Tor for years now. Wasn't there an article recently stating that the NSA (or was in the CIA...?) control 2/3 of Tor exit nodes?
But the thing is that thous TOR exit points (just like Proxies) can inject all kinds of JS on the sites they display and while some people run NoScript or similar browser extensions most do not.
And giving out your username/password combinations for scriptkiddies and criminals and allowing them to run any JS on sites you visit does hell of a lot more short term damage than any government surveillance, losing all of your possessions in an identity theft or just getting phony bills is way worse for your average consumer than having their Facebook chat logged.
Tor is a good tool when used properly, but slapping it on to everything isn't what the tool was made for.
So wouldn't the fix for this be to have the browser warn/refuse to send cleartext over Tor?
As for TLS, something like http://convergence.io/ would be a nice thing to add by default.
That avoids the "password collection"/MITM attack?
It would push for more secure practices, and would complement Mozillas current efforts with Persona. Site that do not use https, Persona, OpenID, google/facebook/microsoft/what-ever-authentication-system is a problem, but better served by some form of detection mechanism. incognito mode could simply try detect the common exceptional cases, and then provide a user warning. As such, user would report the warning to the forum/wp admin, and the web would improve as an result.
Second, the tor exist node are not more risky than using local ISP, coffee shops, or a business/school network. Who is more likely to secure the network routes against malicious attacks: a underpaid janitor, restaurant worker, teacher, or a several year established tor enthusiast? Most tor traffic flow through the biggest and most established nodes, and those has a lot to loose from sniffing the network. Can the same be said about the person behind the counter at the local coffee shop?
$ iceweasel --enable-tor
The option --enable-tor will route _all_ traffic generated by Iceweasel through
possibly-malicious TOR exit nodes. Please read http://example.com/TOR for more
information on how TOR works and then type "Enable TOR" to continue launching
Iceweasel with TOR enabled.
Awaiting Input: <user types Enable TOR + Enter>
<Iceweasel starts>
Sure, people could build scripts with expect or so, but I would assume this to deter most unknowing users from enabling TOR accidentally (idea stolen from apt-get’s ‘Yes, do as I say!’).try this: https://www.torproject.org/projects/torbrowser.html.en
Tor is unsafe to use unless you understand how it works and use it selectively and carefully. Selectively and carefully is not a way I would describe the average persons browsing technique.
To continue, please type the following phrase in the text box:
I UNDERSTAND THAT ENABLING THIS FEATURE WILL CAUSE HACKERS TO STEAL ALL MY MONEY
Type the phrase: _______________________________________________________
[Ok] [Cancel]
Page 2: Which of the following are true? [multiple choice answers about the feature]
User friendly? More like user hostile... But that is what is needed.
Maybe, the relay code could be bundled into Firefox, and there could be a toggle for "make me into a relay"
I love this independent of any other step. Would make using and running hidden services much more attractive.
One at least needs to have JavaScript disabled when on Tor or you'll easily be compromised and Firefox 23 now ships with JavaScript always-on.
http://boingboing.net/2013/08/04/anonymous-web-host-shut-dow...
Of course, it increases the surface area of attack for exploits, but is there something else I'm missing?
[1] The version numbers are here https://blog.torproject.org/blog/new-tor-browser-bundles-and... Note: these version numbers were not vulnerable to the exploit, patched in June & note the day the exploitation took place (August)
[2] Background on deterministic builds and binary verification http://lwn.net/SubscriberLink/564263/1ab0ab93a900ecea/
It's on by default, as it always has been. And the option to turn it off was removed from the main options dialog. This is for sensible reasons -- many users turn it off either accidentally, or without understanding what it means ("this must be that insecure Java thing I keep hearing about") which breaks many websites.
But the 0.01% of people who like to browse without JS enabled can still do so via about:config -- look for "javascript.enabled". Or they can use an add-on. Or they can wait a version or two (I'm not sure the exact timeline) whereupon you'll be able to disable it via the developer tools UI.
> It's on by default, as it always has been.
You're being overly pedantic and I'm sure you knew what I meant when I said it ships always-on.
Disagree.
> He's a Firefox developer, the clarifications are interesting
That's good. Then he ought to recall what's in the release notes for Firefox 23: http://www.mozilla.org/en-US/firefox/23.0/releasenotes/
> "Enable JavaScript" preference checkbox has been removed and user-set values will be reset to the default
Our ip-address at home ended up on a blacklist. Eventually the ban was lifted but my wife was not happy for a couple of days ...
I wonder if there are other services (IRC, MMO, etc...) that adopt a NO TOR policy.
But still though. If they make Tor a feature in Firefox what is stopping any user from checking that box?
I imagine it can be a tough call for web site operators who want to support anonymity, but also don't want to deal with the bad apples who will use it to create grief.
A browser accesses that network, it is the weakest and least point in that setup.
Because tor has no gui? Use vidalia (see https://www.torproject.org/projects/vidalia.html.en).
There are so many ways to track an individual, independent of the network, with java-script, extensions, addons, plugins, client-side-caching that even if tor becomes a feature in firefox, the slightest unmitigated problem, even your behavior may compromise your privacy.
http://www.reddit.com/r/onions/comments/1l15hx/10_steps_to_m...
Without that, you're just the Titanic happily floating across the ocean without making sure you've got enough lifeboats if something goes wrong. Should failure always mean death? Is it too much to ask to insist on a firewall safety net to block non-Tor connections when the next bug is found in the Tor Browser Bundle (or whatever)?
I'm all for making .onion sites reachable, as long as that's the only thing this new feature promises to do. It would make *.onion sites mainstream, which is good for everybody. Strength in numbers, heard immunity, get lost in the crowd - that's precisely what Tor relies on to achieve its most basic goals. Taking Tor mainstream with support in Firefox would mean there would be more Tor users for the seriously privacy-paranoid to hide behind.
I'm not convinced that supporting tor is also not supporting criminal activity, such as child pornography and money laundering.
I don't want software on my computer that I don't need and I don't like. If Firefox wants to dive deep into controversial and politically complicated topics, that's their right, but I don't have to have them on my computer or support that.
ToR is infrastructure, and a utility for the masses. It's up to people on how they want to use it. Why is it worse than the internet?
You're certainly free to continue telling every server your client machine's location and your ISP about every server to which you connect. But that's not going to help children or fight any crime.
To me, possibly the best thing we can do to protect our children today is to enable them to grow up with a shred of privacy, without the baggage of an unknowable amount of juvenile internet browsing history following them into adulthood to be sold and traded by evil men who would be their masters. That's the industrial scale child exploitation, that is.
When the non-anonymous web first became popular and was used for child pornography and money laundering (as it still is) - did you object to using it? USPS or FedEx can also be used to (trivially) ship contraband material, even anonymously.
I'm far more concerned about companies like Facebook tracking and recording my every activity than I am the NSA or law enforcement - I'm boring to the NSA, but my product research and online purchasing behaviors are pure gold to the corporate world.
A bit tongue in cheek, but lets be serious - there is no technology in existence that can't be exploited by bad people. Tor is a tool, it can be used for good or for naughty or for boring. Like most every other online tool or protocol out there.
Sure, Tor can be used for nefarious purposes, child pornography and money laundering - but so can the regular mail, the telephone, the internet, public roads or in general pretty much every piece of technology. Is that a reason for wholesale surveillance and abolishment of privacy? I don't think so.
It's easy enough to set Tor up with Firefox yourself. Perhaps all that is needed is an easy to understand and access Tor guide. Perhaps the first page you see upon loading Firefox after installing or updating is a, "We recommend you use Tor for a safer browsing experience" and then give some scenarios where Tor should and shouldn't be used.
The thing to note is that these issues were fixed and Firefox is still a competitive, solid browser.
The argument of turning around someone's opinion and asking how they would fix and maintain the problem is an exhausted counterargument that has no validity. It wasn't the Mozilla team didn't have the smarts to fix the memory leaks, it's the fact they denied there was even a problem for so long. It's all about prioritising what you work on. So if I had any involvement in Mozilla and Firefox's development, I would be prioritising what's important and what isn't.
This place has really changed. You can't give your opinion on something without being down-voted into oblivion, even if your opinion is well-intentioned and constructive. My comment wasn't negative, it was my opinion. I didn't bash anyone, I'm sick of this place misconstruing other peoples comments (a frequent occurrence from what I've noticed).
Setting it up so it's actually not leaking information that would identify you is hard-to-impossible. See the things the Tor Browser Bundle ends up doing (including changes to C++ Gecko code!).