4 ms·
So the way to fix this is to get involved and write some software instead of commenting in a forum as if software is a static problem. Why not open a bug report
by ordinary 13y ago
So the way to fix this is to get involved and write some software instead of commenting in a forum as if software is a static problem. Why not open a bug report? Maybe we can prevent password reuse by the browser taking a hash of the password being entered in a form and comparing it against other password hashes locally?
The lack of a proposed solution does not make the identification of a problem worthless. Writing code is as much part of the process of solving problems with software as identifying those problems is. When a problem is largely a social one, rather than a technical one, identifying the problem and making people aware of its existence is often the bigger part of the process.
Tor guarantees anonymity. It succeeds at that. There is no technical problem. There is no code to write. This could lead you to think there's a problem with scope, that maybe Tor should guarantee security too. Unfortunately, the design of Tor is not compatible with that goal: if your plain text data goes through an exit node, then by definition, that exit node gets to see what the data is. A bug report titled "Tor does not provide secure communication" would get closed faster than you can say "won't fix". And rightfully so.
There is, however, a social problem, as stated by the OP: many people actually expect security. This is a problem that can only be solved by educating as many people as possible that this is the wrong expectation to have, which is what the OP is contributing to by making this post. This is very much in the spirit of "if you think it should be done, do it".
- maqr 13y ago> Tor guarantees anonymity. It succeeds at that. Doesn't it fail at anonymity if the entire internet is being monitored?
- slacka 13y agoI fails to see how HTTPS Everywhere + a nag whenever a form is detected on a HTTP page doesn't make this a complete non-issue. OP is not giving Mozilla any credit. If OP has ever used Tor, he would know that the performance hit is so huge, that no-one in there right mind is going to leave it on by default, if that's even an option. In OPs myopic view, he's missing the fact the the added benefit built in anonymity to all FF Users far outweighs this hypothetical security risk.
- 15charusername 13y ago>Tor guarantees anonymity. No it does not, it is always best to use a seperate browser for tor because your browser & OS fingerprint is significant https://panopticlick.eff.org/index.php?action=log&js=yes https://panopticlick.eff.org/index.php?action=log&js=yes And that is ignoring the fact that most people will continue to login to the HN and facebook accounts.