5 ms·
That [title] is a weird thing to take as main message from that advisory. The Firefox exploit that was used would have worked on Linux just as well; it was simp
by computer 13y ago
That [title] is a weird thing to take as main message from that advisory. The Firefox exploit that was used would have worked on Linux just as well; it was simply only targeted at Windows this time.
I agree that switching away from Windows is generally a good idea, but only a hardware-based router, or a software based VM isolation solution like Whonix or Qubes OS would have defended the user in this case. Even Tails, the Tor live USB distribution could have gotten owned by this exploit, had the NSA/FBI/hackers chosen to target them.
- rmrfrmrf 13y agoI was surprised that Windows was the target OS -- I had figured that most Tor users were using Tails at this point. I'm sure that whoever targeted the user group they meant to capture, though, had a good idea of their general usage patterns. Wouldn't disabling JavaScript have also prevented this exploit? I don't know if FireFox still runs JavaScript through an interpreter if the user has disabled it; I'd assume not, but it wouldn't come as a shock to me if it did.
- computer 13y agoDisabling javascript would have prevented the exploit. The Tor browser bundle contains NoScript, but has it set to allow javascript by default. I think this is because it makes it more accessible to non-technical users. Before this issue they even advised _not_ to disable javascript, since that would make you stand out more amongst Tor users.
- mseidl 13y agoNoscript blocks by default in the browser bundle...
- jlgaddis 13y agoNot in recent versions (the idea being that users w/ JavaScript disabled "stand out" more from typical users).
- mseidl 13y agoMy noscript is on by default on the linux version. I _never_ touched it.
- jlgaddis 13y ago"Why is NoScript configured to allow JavaScript by default in the Tor Browser Bundle? Isn't that unsafe?" https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEnabled https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEna...
- marcosdumay 13y agoI was surprized that the NSA/FBI/whatever-3-other-letters had to use an exploit to gather that data from Windows users.
- qbrass 13y agoIf they didn't need one, they know better than to admit it.
- quantumpotato_ 13y agoYou might have high security. The average TOR user probably doesn't.
- computer 13y agoAnd that's why it's all the more important that Tor ships only very-secure-by-default software, including disabling javascript by default, even when that will confuse some new users. I believe this issue has caused the Tor people to realize this more than ever, and think/hope that some priorities and tools within the project will change as a result.
- Torgo 13y agoConsumers of child pornography are probably inclined to save the images. TAILS would be a lot more invconvenient since it doesn't save anything. With TBB you can save things you download to your desktop. Combine this with Windows being a dominant platform. I guess you could do this with TAILS and a usb stick though.
- doctorfoo 13y agoHow exactly does a hardware based router help? Is the idea that TOR is running on separate hardware, and despite the local system being compromised, the attacker can't "phone out" to find the real IP address?
- wfn 13y agoI think that's the idea. All connections would be routed via Tor. Additionally, the local system wouldn't know the external IP address (would only know the eventual Tor exiting IP address.) It's possible to virtualize Tor (without running a dedicated router) so that it, too, doesn't know the external IP address. You can do this, as an example, in FreeBSD jails, and instruct the firewall to NAT all connections from/to the jail in which Tor is running. Of course, having a dedicated hardware router running Tor is even safer.
- jlgaddis 13y agoYes, exactly. Using a separate router it's possible to transparently force all traffic through the Tor network.
- Torgo 13y agoDoes the Qubes Tor container egress filter non-Tor traffic? If it does not, it would still be susceptible to a linux-specific version of this same attack.