3 ms·
This has been eloquently addressed by Tor veteran Mike Perry:[1] Concerns about Javascript are rooted in two avenues: 1. Fingerprinting concerns. 2. Zero-day
by jerheinze 4y ago
This has been eloquently addressed by Tor veteran Mike Perry:[1]
Concerns about Javascript are rooted in two avenues:
1. Fingerprinting concerns.
2. Zero-day exploits against Firefox.
The reason we feel that leaving Javascript enabled trumps these concerns
is:
1. We want enough people to actually use Tor Browser such that it
becomes less interesting that you're a Tor user. We have plenty of
academic research and mathematical proofs that tell us quite clearly
that the more people use Tor, the better the privacy, anonymity, and
traffic analysis resistance properties will become.
In fact, my personal goal is to grab the entire "Do Not Track" userbase
from Mozilla. That userbase is probably well in excess of 12.5 million
people:
http://www.techworld.com.au/article/400248/ http://www.techworld.com.au/article/400248/
I do not believe we can capture that userbase if we ship a
JS-disabled-by-default browser.
2. Exploitable vulnerabilities can be anywhere in the browser, not just
in the JS interpreter. We disable and/or click-to-play the known major
vectors, but the best solutions here are providing bug bounties (Mozilla
does this; we should too, if we had any money) and sandboxing systems
(Seatbelt, AppArmor, SELinux).
[1] : https://lists.torproject.org/pipermail/tor-talk/2012-May/024227.html https://lists.torproject.org/pipermail/tor-talk/2012-May/024...