8 ms·
I'm surprised that they haven't bundled Arti, their Rust-based tor client implementation. I will say I am thankful for Tor Browser, but any JavaScript-enabled b
by encryptluks2 4y ago
I'm surprised that they haven't bundled Arti, their Rust-based tor client implementation. I will say I am thankful for Tor Browser, but any JavaScript-enabled browser seems like the wrong choice for privacy and security.
- ravenstine 4y agoI've basically come to the same conclusion having attempted to use a lot of Tor Browser's default config in Firefox. Most of it is a good idea, but trying to be untrackable while JavaScript is turned on seems futile. Every single browser's APIs are leaky as hell. No matter how many things are turned off or obfuscated, there's always a few unique-ish details that are exposed that create a fingerprint. There was one point where my anti-fingerprinting tactics did appear to fool Panopticlick, but that apparently didn't last long. Fingerprinting and anti-fingerprinting are a cat and mouse game, and much worse so than just ad-blocking because there's more at stake than just being annoyed by banners. There's also way too many websites doing everything, and I mean everything with JS. Fricking blog sites half the time display nothing more than a motionless loading spinner if you don't have JS turned on. And if you turn JS on well good luck because lots of things want to use <canvas> to render things that don't even strictly need it, and you're really not going to casually enable canvas for certain things? Even the list of fonts is a decent metric for fingerprinting, yet that's rarely taken seriously because even privacy experts seem to believe that every website needs to display its own fonts for "brand identity." Though I would stay away from Tor anyway, if I were to use it, JS would have to be turned off entirely.
- rodric 4y agoMy default browser is Librewolf with JavaScript turned off. If a page fails to load correctly, I reopen it in Firefox private browsing mode (or, if it still fails, Chrome incognito mode). If it’s a site I expect to come back to in future, I bookmark it in Firefox and assign it its own container using the Multi-Account Containers extension.
- bawolff 4y agoSecurity is always a compromise between competing concerns. A browser that cannot browse a significant chunk of the internet doesn't get used and helps nobody.
- Aisen8010 4y agoI installed the Tor Browser to access the Z Library a few days ago. I guess I shouldn't complain, but the downloads are very slow (I'm not sure if the problem is in my end).
- Synaesthesia 4y agoIn general connecting over Tor or I2p is slow.
- edgyquant 4y agoTor works by proxying through (at least) 3 PCs before hitting the open web. The problem is that you’re trying to download big files which is not a use case for tor. It’s specifically for browsing the web anonymously.
- ehPReth 4y agoWas it always 7? I seem to remember it being like 3-4?
- super256 4y agohttps://i.imgur.com/h1vlxNh.png https://i.imgur.com/h1vlxNh.png
- makerofspoons 4y agoConnecting to hidden services it's 6 hops, reaching out to the internet it's 3 hops.
- bauruine 4y agoFor a circuit to clearnet it's 3. Guard --> Middle --> Exit. For a onion service it's 6 and the connection is a bit more complicated [0]. The speed varies from very fast to unbearable depending on your circuit and how bad the ddos is at that moment. [1] You can try to create a new and hopefully faster circuit by clicking on the onion symbol on the left in the address bar. [0] https://github.com/mikeperry-tor/vanguards/blob/master/README_TECHNICAL.md#onion-service-overview https://github.com/mikeperry-tor/vanguards/blob/master/READM... [1] https://status.torproject.org/issues/2022-06-09-network-ddos/ https://status.torproject.org/issues/2022-06-09-network-ddos...
- capableweb 4y ago1) Arti is basically a prototype at this point, including it already would be reckless, 2) Arti is a client for the Tor protocol, and including it in the browser wouldn't have any impact if JavaScript ships enabled/disabled by default in Tor Browser, 3) if you really want to, you can easily change the "Security Level" in Tor Browser to disable JavaScript for all websites by default. As an alternative for the last point, turn the Security Level to "Safest" or however it's worded, then use the included NoScript addon to enable it for just sites that just won't work without JavaScript. You get functional web + JS disabled in most places where you can.
- nibbleshifter 4y agoArti isn't ready for production use yet. Its a long ways away from being usable in TBB or as a full drop in for tor itself. I think in a years time that will change.
- dinosaurdynasty 4y agoArti doesn't even support hidden services yet.