111 karma · joined August 24, 2015
Using the Tor network is one part of internet anonymity, serving to conceal where you are. But using the Tor network does no good if the application helpfully adds X-My-Actual-IP-Address: 123.45.67.8 to every HTTP request, and browsers tend to do a lot of things like that which we have to play whack-a-mole with. What we implement in Brave is somewhere between (a) naively just setting a SOCKS proxy, like you can do in vanilla Firefox or Chromium, and (b) mimicking everything about the Tor Browser and following the Tor Browser Design Document to the letter (https://2019.www.torproject.org/projects/torbrowser/design/). So, while you are right that there's more to Tor and that we're not the Tor Browser (and that's why we are careful to say 'private windows with Tor' and not 'Tor windows', per agreement with the Tor Project about branding), there's also more to what Brave does than just setting a SOCKS proxy like in Firefox or Chromium and leaving it at that.
-yan (author of blog post)
See discussion at https://trac.torproject.org/projects/tor/ticket/17423
I may write a blog post later about this, but here are a few that come to mind (only counting things that have demos or have been observed in the wild):
* css-visited browser history sniffing (fixed several years ago): http://dbaron.org/mozilla/visited-privacy * HSTS unique-subdomain combination supercookies: http://www.radicalresearch.co.uk/lab/hstssupercookies * lcamtuf's cache timing attack: http://lcamtuf.coredump.cx/cachetime/ * webrtc local ip leak: https://diafygi.github.io/webrtc-ips/ * panopticlick: https://panopticlick.eff.org/ * evercookie: http://samy.pl/evercookie
In case anyone's interested, slides are up at https://zyan.scripts.mit.edu/presentations/toorcon2015.pdf and talk recording at https://www.youtube.com/watch?v=kk2GkZv6Wjs
I didn't set up analytics to figure out how accurate results are for the average person; having manually checked with a few people's browsers, I'd say the accuracy rate is ~75%.
The attack scenario described in the post is (1) attacker writes some plausible-looking patches to an existing library like jQuery, (2) attacker convinces library maintainer to merge the patches, (3) someone builds the library with a buggy minifier, which creates the actual backdoor.
Not convinced that HTTP2 will eradicate minifiers; it makes bundling files less useful, but minifying still gets rid of bytes. Then again, I'm not a web performance expert. :)