2,631 karma · joined March 20, 2017
Given its open source nature that would be exceedingly difficult.
> The Tor network was deemed the culprit of anonymity and secure connections not long ago. We all know how it went.
What are you talking about? Tor is still the uncontested king of low-latency anonymity networks.
For more information on Snowflake check: https://snowflake.torproject.org/
> ... construct unikernels for secure, high-performance network applications across a variety of cloud computing and mobile platforms. Code can be developed on a normal OS such as Linux or macOS, and then compiled into a fully-standalone, specialised unikernel that runs under a Xen or KVM hypervisor.[1]
[0] : https://github.com/mirage/qubes-mirage-firewall
[1] : https://mirageos.org/
https://community.torproject.org/relay/setup/snowflake/stand...
Or by installing the browser addon: https://snowflake.torproject.org
https://www.eff.org/files/2022/07/07/hachette_v._internet_ar...
I don't think this is the most solid argument, but I really hope that line of thinking is deemed sufficient for not loosing in this legal case.
Concerns about Javascript are rooted in two avenues:
1. Fingerprinting concerns.
2. Zero-day exploits against Firefox.
The reason we feel that leaving Javascript enabled trumps these concerns is:
1. We want enough people to actually use Tor Browser such that it becomes less interesting that you're a Tor user. We have plenty of academic research and mathematical proofs that tell us quite clearly that the more people use Tor, the better the privacy, anonymity, and traffic analysis resistance properties will become.
In fact, my personal goal is to grab the entire "Do Not Track" userbase from Mozilla. That userbase is probably well in excess of 12.5 million people: http://www.techworld.com.au/article/400248/
I do not believe we can capture that userbase if we ship a JS-disabled-by-default browser.
2. Exploitable vulnerabilities can be anywhere in the browser, not just in the JS interpreter. We disable and/or click-to-play the known major vectors, but the best solutions here are providing bug bounties (Mozilla does this; we should too, if we had any money) and sandboxing systems (Seatbelt, AppArmor, SELinux).
[1] : https://lists.torproject.org/pipermail/tor-talk/2012-May/024...
> A reminder that Tor Browser might be one of the least safe browsers you can run: it's a fork of Firefox, meaning that its maintainers have to coordinate and port patches from the mainline project.
Tor Browser ships updates as soon as new ESR versions come out.
> Firefox is already not one of the most hardened browser engines.
That might've been true in the past, it's hard to argue for it now.
> Meanwhile, the fork you'll be running is specifically designed to hide sensitive traffic, and collapses all those users into a single version for exploits to target.
The overwhelming majority of exit traffic now is using HTTPS and Tor Browser ships with HTTPS Everywhere to avoid SSL Striping attacks (in fact the next version of the Tor Browser will have the HTTPS-Only mode enabled by default, it's already being tested in the alpha release), so how will those evil exit node burn those exploits?
> I'm ambivalent about Tor, but if you're using Tor, don't use the Browser Bundle.
First off, the "Tor Browser Bundle" is a deprecated name. If you're not using the Tor Browser you're making yourself both insecure (it ships with a smaller attack surface, no WebGL for example) and fingerprintable defeating thus the full privacy advantages of the Tor Browser. There is simply no other alternative.
You can read the Tor Browser design documentation (though old) to get a rough sketch of what it's trying--and what it's not trying--to achieve: https://2019.www.torproject.org/projects/torbrowser/design/
Further reading in case you think VPNs are the solution: https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browse...
There are many anecdotal reports about people seeing shorter eyeballs as measured by an autorefractor while doing the reduced lens method, one example that I recall is this one from cliffgnu[1].
For LASIK the real thing that isn't communicated is that it doesn't address the root of the problem which is that the eyeball gets longer, it only works as if someone carved glasses on your cornea.
https://addons.mozilla.org/en-US/firefox/addon/torproject-sn...
https://chrome.google.com/webstore/detail/snowflake/mafpmfcc...
* Revolt - FOSS and self-hostable, still a long time before reaching feature parity https://github.com/revoltchat
* Guilded.gg - closed source alternative https://www.guilded.gg/
Better yet just install the Snowflake addon (available for both Firefox and Chrome), so it becomes more of a set-and-forget thing.
No, only controlling the guard and exit nodes is necessary.
> If the latter, can you configure Tor to use more than one middle relay node, depending on your threat model?
Tor makes dozens of circuits in a typical use. You never stick to a single circuit. In the Tor Browser you have first party stream isolation so you get a different circuit (and hence different middle and exit nodes) for each first party domain that you visit.