5 ms·
The issue I have with Tor Browser is the greater chance of 0day exploits for Tor Browser existing/being held onto, when compared to browsers like Chrome that ha
by kreativ_py 5y ago
The issue I have with Tor Browser is the greater chance of 0day exploits for Tor Browser existing/being held onto, when compared to browsers like Chrome that have much greater resource for security.
Remember, Zerodium revealed a 0day in all Tor Browser v7 and under once v8 had been released
https://twitter.com/Zerodium/status/1039127214602641409 https://twitter.com/Zerodium/status/1039127214602641409
- noobermin 5y agoIgnoring of course, the blantant tracking that Google itself engages in.
- jokowueu 5y agoChromium then ?
- noobermin 5y agoThe entire point of tor is for very secure end-to-end encryption to the point that certain professionals (state actors and even criminals) use it for their purposes. Chromium is a general purpose browser that does not do that. You can't compare them because zero-days isn't the only relevant detail to compare here.
- beebeepka 5y agoRecommending chrome over tor browser due security concerns. What are the chances this very specific comment was made in good faith?
- Proven 5y ago
- tasha0663 5y ago> What are the chances this very specific comment was made in good faith? That's irrelevant, per the guidelines. > Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
- beebeepka 5y agoWhat is your point? 1. I responded to the strongest possible interpretation based on what was said. 2. How is that irrelevant? If, for whatever reason, your goal is to conceal conflict or negatives in general, I suggest you pick on someone else.
- mdp2021 5y agoThe guidelines mandate you to assume good faith (you must observe them to participate here). This means (not exclusively) that you have to first answer yourself to that doubt you expressed vis-a-vis the post that originated it, and attempt finding an acceptable interpretation of the original post. Your reply shall reflect that. (If your «strongest possible interpretation» clashes with the assumption of good faith, you will have to think again, and longer. Surely, your reply will reflect that.) Contextually, for example: the poster did not recommend a non-identity concealing product over an identity concealing product /in general/ - the poster noted that the way the identity concealing product is developed/distributed, it is easier for exploitable bugs to be fixed comparatively later - the user must be aware of this. Also: > conceal conflict No. "Manage conflict productively", to achieve some result. «For whatever reason»: efficiency, efficacy, productivity, civilization, enthalpy (fighting entropy), "keeping the place in good order".
- stavros 5y agoHe's doubting the intentions of the author, he's not attacking a straw man. I don't see a problem there.
- quickthrower2 5y ago
- dobin 5y agoTor Browser is just an old version of Firefox, with lots of known vulnerabilities. FBI is well known to take over Tor hidden services and exploit the visitors with a 0-day/1-day, which makes it easy to de-anonymize them. Privacy depends on security. Firefox is about 3-5 years behind security level of Chrome (Sandbox, Fuzzing efforts, hardening efforts, source code reviews, etc.).
- easrng 5y agoThat's not true, it's based on Firefox ESR which does get security patches, just not new features between major versions.
- chuckSu 5y ago
- southerntofu 5y agoThis is FUD. Neither Chrome nor Firefox are any good for *security*, as they both regularly get pwned at every hacking contest there is. Tor Browser is a different beast, because although it's based on Firefox, its attack surface is infinitely smaller than that of Firefox. When running in Safest mode, it's essentially just rendering HTML/CSS/images: anything that involves convoluted decoding (video, webfonts, scripts) is disabled. Treating your web browser as an environment for declarative pages is best practice for security: no matter how many layers of sandboxing you'll use, people will find holes. So apart from a few bypasses like the parent comment explained, TBB is decades ahead any other browser's security level out there (except for your favorite CLI browser over Tor which has roughly the same properties).