|
|
Subscribe / Log in / New account

Attackers wield Firefox exploit to uncloak anonymous Tor users (ars technica)

Attackers wield Firefox exploit to uncloak anonymous Tor users (ars technica)

Posted Aug 6, 2013 9:53 UTC (Tue) by tialaramex (subscriber, #21167)
In reply to: Attackers wield Firefox exploit to uncloak anonymous Tor users (ars technica) by pabs
Parent article: Attackers wield Firefox exploit to uncloak anonymous Tor users (ars technica)

The stance from browser vendors is that the "private" mode is only supposed to prevent embarrassing scenarios where, e.g. autocomplete takes your daughter to your favourite porn site, or your spouse accidentally opens a tab with all the hotel details for the surprise anniversary weekend away you just booked. The messages displayed when you activate this mode in various popular browsers align with that.

It's like password masking, using rot13 on the stored password doesn't make it difficult for bad guys to find the original password but it means someone who happens to glance at the config file is much less likely to come away with "MoonMoonForPresident" seared into their memory. Or think of it like the lock on a typical bathroom door. Can I open the lock from the "wrong" side with the tools in my pocket? Yes I can. But people don't, because they don't want to walk in someone using the toilet, the feeble lock is a prompt to remind us of a social convention and nothing more.

TOR is a big deal, to get any benefit users have to understand what it is and is not doing, and what that means for how they use a browser. Just labelling it "Super private mode" would be false advertising. Not to mention that then obviously TOR will be incredibly slow for everyone so they'll presumably switch it back off again and pronounce the whole thing a "waste of time".


to post comments

Attackers wield Firefox exploit to uncloak anonymous Tor users (ars technica)

Posted Aug 6, 2013 10:01 UTC (Tue) by pabs (subscriber, #43278) [Link]

Looks like Mozilla are considering integrating the TBB into Firefox now:

https://twitter.com/BrendanEich/status/364265592112414720


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds