4 ms·
Tor Browser 7.0a4 is released
- libeclipse 9y agoCould someone more knowledgeable than me comment on what Selfrando is, how it's useful, and how it works.
- dublinben 9y agoI recommend reading the linked blog post about it. [0] [0] https://blog.torproject.org/blog/selfrando-q-and-georg-koppen https://blog.torproject.org/blog/selfrando-q-and-georg-koppe... There is also a research paper [1] and accompanying video [2]. [1] https://people.torproject.org/~gk/misc/Selfrando-Tor-Browser.pdf https://people.torproject.org/~gk/misc/Selfrando-Tor-Browser... [2] https://www.youtube.com/watch?v=IikpczzNyas https://www.youtube.com/watch?v=IikpczzNyas
- TazeTSchnitzel 9y agotl;dr seems to be a more advanced form of ASLR?
- notlambda 9y agoi think it's ASLR with more entropy by skimming through the paper, but most exploits have read primitives or infoleaks anyways so i don't see how more entropy affects them. If i am right it protects against attackers guessing the ASLR slide, but that's very unreliable and no FBI grade exploit should ever do that.
- jerheinze 9y agoSee "Real-world Exploits against the Tor Browser" pages 9-10 where they conclude, > The reason is that these function pointers are only accessed through an indirection layer, i.e., memory objects on the heap contain a pointer to a virtual table which is located in the code or data section of the application and contains a number of pointers to virtual functions. Since the attackers can only disclose the virtual table pointer, but not the virtual table itself, as it is not on the heap, they cannot disclose gadget addresses. Note that, when only ASLR is applied, the address of the virtual table is randomized with the same offset as the ROP gadgets. Therefore, such an attack can bypass ASLR but not selfrando. > We therefore conclude that selfrando can thwart most real-world exploits. Attackers can only succeed in rare cases where they can disclose the complete heap and data section. [1] : https://people.torproject.org/~gk/misc/Selfrando-Tor-Browser.pdf https://people.torproject.org/~gk/misc/Selfrando-Tor-Browser...
- libeclipse 9y agoThat blog post is pretty much useless in terms of information, but that linked presentation is pretty informative. Cheers.
- dataking 9y agoselfrando contributor here. it is correct that selfrando is intended as an improvement over ASLR by randomizing code at the function level (vs. module level). this improves resilience to information leaks somewhat, but with mitigations like these, there are no silver bullets. selfrando github repo: https://github.com/immunant/selfrando https://github.com/immunant/selfrando feel free to open an issue or write us at team@immunant.com cheers!
- irresolute 9y agoI'm waiting for version 8 because of my religion.
- Proof 9y agoCould be a while.
- jjawssd 9y agoHow do the Tor project developers continue the development of Tor without the interference and corruption efforts of state level actors?
- beardog 9y ago1. Tor is open source. Any backdoor attempts in the source would require careful hiding. Shutting down the Tor Project would just result in someone else picking it up. 2. The US Navy funded (maybe still does) Tor. Tor is useful for western allies & spies 3. Many of the developers live in western nations. While western nations like the US do have intel agencies who are interested in messing with Tor, it doesn't seem to have gotten to the point of shutting down the Tor Project or directly attacking their infrastructure much if at all, especially since Tor benefits the military as well.
- secfirstmd 9y agoYep. IIRC one of the Snowden documents even mentioned GCHQ and other organisations using Tor for their own purposes.
- remx 9y agoYep. Tor is just a great big eye for the NSA and GCHQ. For them it doesn't matter if scoundrels use it, as long as they can use it too.
- jerheinze 9y ago> IIRC one of the Snowden documents even mentioned GCHQ and other organisations using Tor for their own purposes. I think you're referring to this presentation about hidden services by the GCHQ [1] where they state, 'Until then... Doesn't stop us from using them' I wonder what they may have to say about the soon coming next-gen onion services. [1] : https://www.eff.org/files/2015/01/26/20141228-speigel-analytics_on_security_of_tor_hidden_services_0.pdf https://www.eff.org/files/2015/01/26/20141228-speigel-analyt... (page 25)
- jerheinze 9y ago
- kapauldo 9y agoFor the over 40 crowd https://read.feedly.com/html?url=https%3A%2F%2Fblog.torproject.org%2Fblog%2Ftor-browser-70a4-released&theme=white&size=medium https://read.feedly.com/html?url=https%3A%2F%2Fblog.torproje...
- awake 9y agojavascript:(function()%7Bvar%20currentURL%20%3D%20encodeURIComponent(window.location)%3Bwindow.location%20%3D%20%60https%3A%2F%2Fread.feedly.com%2Fhtml%3Furl%3D%24%7BcurrentURL%7D%26theme%3Dwhite%26size%3Dsmall%60%7D)()) bookmarklet code to do that for you on any web page not sure how to format this better
- unexistance 9y agonot over 40 yet BUT I do love readability-enhancements like this :D * use Firefox 'Reader View'; OR * use this outline.com bookmarklet javascript:(function()%7Bwindow.location.href%20%3D%20'https%3A%2F%2Foutline.com%2F'%20%2B%20window.location.href%7D)()
- red023 9y agoI think its terrifying that Firefox has so many build in things that make it easy to track people. Yet they claim to be so much about users privacy ... I think most of the stuff tor browsers does should actually be in firefox by default. Excluding Tor itself and noscript enabled by default.