5 ms·
I often wonder why Tor is bundled within Firefox, would it not be easier to release an app that changes the proxy settings / network routing at a system level?
by robinduckett 10y ago
I often wonder why Tor is bundled within Firefox, would it not be easier to release an app that changes the proxy settings / network routing at a system level?
That would let you use your preferred browser, rather than being forced to use the browser Tor chose to bundle.
- iokanuon 10y agoTor is not bundled with a browser. Tor Browser is, but Tor Browser is not Tor, it's a browser with Tor built-in and extra privacy features, such as NoScript.
- joosters 10y agoThe problem is that many user settings and add-ons would defeat the privacy protections in Tor. For example, Javascript and Flash, as well as many other browser features. By bundling a separate browser, Tor can provide sensible defaults to protect users.
- viktorelofsson 10y agoMy guess is so it makes it harder to fingerprint people. If I remember correctly the advice is to not resize the browser window, etc.
- valarauca1 10y agoThis. The default tor browser ensures most tor users look identical so malicious services cannot finger print individual users. It disables a small group of firefox features which make finger printing extremely trivia (RPC Chat, GPU access). In most cases of people being de-anonimized on TOR they're normally running an alternative browser, or out of date TORbrowser.
- draugadrotten 10y ago> out of date TORbrowser. isn't everyone using TOR today using tomorrow's out of date TORbrowser? Meaning that traffic today can be recorded and analysed for vulnerabilities tomorrow.
- valarauca1 10y agoNo. Its really hard to open an RPC chat session on packet logs. Or request GPU diagnostic information after the connection is terminated. Most finger printing isn't just write/response times. Latency is a bad indicator of individuality. It's a lot more in depth and requires actively speaking to that browser and noting what features it does/doesn't present, how those features are unique, and how long certain tasks take to process. Each individual piece of data is small (generally, some browser features make ID trivial), and common. But building up several can give you some confidence in an identity.
- tosseraccount 10y agoMozilla is funded by Baidu, Yahoo and Yandex which get their revenue from advertising. Advertisers tend to love targeting, not anonymity. Mozilla Foundation's funders probably have some influence on Firefox's functionality. https://en.wikipedia.org/wiki/Mozilla_Foundation#Financing https://en.wikipedia.org/wiki/Mozilla_Foundation#Financing
- rubyfan 10y agoIt is likely that some other application on your system will phone home and in essence make you a named user... think email, iCloud synchronization, anything you do on Windows 10, etc. In theory by bundling Tor with a browser that has sane defaults and then sand boxing that from the rest of your applications, one can isolate specific communications to Tor with lower potential exposure.
- Maakuth 10y agoThere is so much more to staying anonymous in the web than just the transport layer. With all the tracking cookies you have in your browser, it doesn't matter if you use Tor or not. There's an array of privacy-enhancing extensions shipping with the browser bundle and you generally use a clean browser profile with it as well.
- onecooldev24 10y agoAlso you wont be able to access .onion sites.
- y7 10y agoI don't think this is true. See https://www.torproject.org/docs/faq.html.en#AccessHiddenServices https://www.torproject.org/docs/faq.html.en#AccessHiddenServ... any SOCKS4a capable browser should work.
- creatonez 10y agoYou don't need torbrowser to resolve onion sites. Onion sites work fine through the SOCKS proxy, and this is often done with IRC clients.
- auganov 10y agoTor is not enough to ensure even mediocre privacy. Just proxying everything through Tor would give people a very false sense of security (and break UDP amongst others). There are VMs that do that but still wouldn't recommend that to someone that doesn't understand tor and networking. Even inside such a VM you'd still use Torbrowser. It combines Tor and app-level security/privacy measures in an accessible way.
- vox_mollis 10y agoTor is not enough to ensure even mediocre privacy. I'm curious why you believe this, outside a few watering hole attacks, and the (now-patched) CMU attack. Given a known-good entry guard, where is Tor broken?
- ashitlerferad 10y agoI suggest you look into the fact that browsers now cater to web app capabilities before they cater to user privacy.
- auganov 10y agoNot broken. Exit nodes. One has to assume all unencrypted TCP traffic will be recorded and potentially modified (MTIMed). Consider we have that system wide tor proxy instead of the torbrowser bundle. Now exit node operators get all your TCP traffic. It's fine if one knows what they're doing[0], but if that was the default way for the average user to get on Tor? A privacy and security disaster IMO. Not only would we not provide mediocre privacy, we'd actually endanger people. [0] and you've got proper stream isolation, which I'm not sure how possible it is system-wide with unmodified software
- schoen 10y agoThe parent commenter is referring to application-layer attacks, which is why the Tor Project deprecated things like TorButton in favor of a dedicated Tor Browser, and why they discourage things like having a router that sends all traffic over Tor by default (because random applications will reveal trackable identifiers!). https://www.usenix.org/legacy/event/leet11/tech/full_papers/LeBlond.pdf https://www.usenix.org/legacy/event/leet11/tech/full_papers/... https://www.torproject.org/projects/torbrowser/design/ https://www.torproject.org/projects/torbrowser/design/ There's probably a more specific statement from the Tor Project that I'm forgetting at the moment that sets forth the idea that you should only use Tor with Tor-aware client software (that controls what privacy leakages may occur at the application layer).
- deleted 10y ago[deleted]
- sixothree 10y agoMaybe check out Whonix
- homero 10y agoThere's a tor gateway and a version with two vms
- tshtf 10y agoThe Tor Browser Bundle doesn't ship the standard version of Firefox! Several privacy-enhancing patches are applied to the ESR release of Firefox for TBB releases. This is because the Mozilla Foundation refused to accept the Tor Project's commits to enhance privacy in the browser. There are also tickets in Tor's TRAC issue tracker for Chrome. Once again, using Chrome securely would require several patches to source.
- mconley 10y ago> This is because the Mozilla Foundation refused to accept the Tor Project's commits to enhance privacy in the browser. Actually, I'm pretty sure this is untrue. I'm reasonably certain we're actively working with the Tor Browser developers to get their patches merged into core (but preffed off) so that they don't have to maintain a stack of patches on top of Firefox. (Disclaimer: Mozilla employee)
- defiancedigital 10y agoI remember Vidalia (https://blog.torproject.org/blog/plain-vidalia-bundles-be-discontinued-dont-panic https://blog.torproject.org/blog/plain-vidalia-bundles-be-di...)