Register ICMag Forum Menu Features
You are viewing our:
in:
Forums > Talk About It! > Hobbies and Interests > Computers > Critical: Read this if you use Tor Browser

Thread Title Search
Click to visit Herbies Seeds
Post Reply
Critical: Read this if you use Tor Browser Thread Tools Search this Thread
Old 01-12-2011, 07:24 AM #1
spurr
Banned

Join Date: Aug 2010
Location: https://www.scirus.com/ & https://www.google.com/schhp?hl=en
Posts: 2,431
spurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nice
Exclamation Critical: Read this if you use Tor Browser

Hello,

Over the past week it has become apparent there is a pretty big bug (anonymity concern) in TorBrowser, due to the non-toggle state most people use it under.

Follow the directions below, NOW, if you use TorBrowser:


Easiest fix:
Make sure to toggle TorButton off, then back on, at least once. This allows for TorButton to set some critical configs that otherwise are not set (i.e., disable geo-location feature in Firefox, etc).

Then type "about:config" (without quotes) in your Firefox URL bar, accept the warning, and type the following in the config bar to make sure it worked (for images of this process see my post here: link)
  1. geo.enabled > should be set to "false"
  2. network.dns.disablePrefetch > should be set to "true"
  3. browser.cache.offline.enable > should be set to "false"

Better fix:
Download the current release of TorBrowser, i.e., 01-09-2011; Linux = v.1.1.2, Mac = v.1.0.9, Win = v.1.3.16. Those builds manually set config options (as a dirty work-around) so TorButton does not need to be toggled at least once.

Then type "about:config" in your Firefox URL bar, accept the warning, and type the following in the config bar to make sure it worked (for images of this process see my post here: link)

  1. geo.enabled > should be set to "false"
  2. network.dns.disablePrefetch > should be set to "true"
  3. browser.cache.offline.enable > should be set to "false"


Refs:


  1. https://blog.torproject.org/blog/new...dle-packages-1
  2. https://trac.torproject.org/projects/tor/ticket/2338
  3. https://gitweb.torproject.org/torbro...onfig/prefs.js

Be safe, be anonymous!
spurr is offline Quote


4 members found this post helpful.
Old 01-12-2011, 07:26 AM #2
spurr
Banned

Join Date: Aug 2010
Location: https://www.scirus.com/ & https://www.google.com/schhp?hl=en
Posts: 2,431
spurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nice
@ all who use Tor:

Please make it a daily habit, or at least a few times a week, to check the Tor blog for important info that may be relevant to you (such as critical bug fix notices, etc.): https://blog.torproject.org/blog/
spurr is offline Quote


Old 01-12-2011, 07:38 AM #3
sackoweed
I took anger management already!!!! FUCK!!!

sackoweed's Avatar

Join Date: Oct 2006
Location: malmac the upper right corner of the globe
Posts: 9,282
sackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant futuresackoweed has a brilliant future
will check on this.. thanx peace n pufs..

sacKO
__________________
Jack & Jill went up the hill both with a buck and a quarter. Jill came down with 650 bucks.

Can't never did anything

click the link!
sackO goes toe 2 toe with!?
sackoweed is offline Quote


Old 01-12-2011, 07:47 AM #4
spurr
Banned

Join Date: Aug 2010
Location: https://www.scirus.com/ & https://www.google.com/schhp?hl=en
Posts: 2,431
spurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nice
Glad to help
spurr is offline Quote


Old 01-12-2011, 08:21 AM #5
Stress_test
I'm always here when I'm not someplace else

Stress_test's Avatar

Join Date: Oct 2010
Posts: 2,527
Stress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of lightStress_test is a glorious beacon of light
Quote:
New Details Support Tor Spying Theory

You’ll recall the story about the Swedish security researcher who stumbled upon unencrypted embassy e-mail traffic that was passing through five Tor exit nodes he set up. The researcher, Dan Egerstad, told me before the Swedish feds raided his apartment that he was certain that others were grabbing such traffic through Tor exit nodes in the same way that he was. Government and intelligence agencies were presumed to be some of the spies tapping into the Tor network.

Well the TeamFurry researchers decided to examine the configuration of a few Tor exit nodes to see what they might be up to and found some interesting results — exit nodes that were configured to accept only unencrypted IMAP, AIM, VNC, Yahoo IM and MSN Messenger traffic, among a few other things, and to reject all other traffic.

Another node set up in Germany was configured to accept only unencrypted telnet, POP3, and nntp traffic. Here’s a look at one of the configurations:


accept *:143 <- Accept unencrypted IMAP traffic to anywhere
accept *:5190 <- Accept unencrypted AIM traffic to anywhere
accept *:5050 <- Accept unencrypted Yahoo IM traffic to anywhere
accept *:5900 <- Accept unencrypted VNC traffic to anywhere
accept *:5901 <- Accept unencrypted VNC traffic to anywhere
accept *:1863 <- Accept unencrypted MSN Messenger traffic to anywhere

reject *:* <- reject all other traffic.

Of course there’s no telling who the exit node owners are (bored hackers, industrial spies or intelligence agencies) or what they’re doing for sure, but as TeamFurry notes, the configurations sure look suspicious.

They also found another exit node in Germany that appears to be doing man-in-the-middle attacks on HTTPS connections.
See also:

* Tor Researcher Who Exposed Embassy E-mail Passwords Gets Raided by Swedish FBI and CIA

* Rogue Nodes Turn Tor Anonymizer Into Eavesdropper’s Paradise
* Embassy E-mail Account Vulnerability Exposes Passport Data and Official Business Matters
* Tor Torches Online Tracking
__________________
"I would.

I'd really like to meet an honest man.
But I'd have to lie to him cause I smoke pot."
______________________________ ______

First Outdoor Guerrilla Grow 2011
Understanding Ph.
Ingenious $4 Walmart Cloner.
SOG's DIY micro-cloning factory tutorial. (Very well illustrated and explained).
Handy site for the Gardener
(A wealth of information for any gardener).
Sometimes when I'm really medicated, I can really crack me up.
Stress_test is offline Quote


1 members found this post helpful.
Old 01-12-2011, 08:37 AM #6
spurr
Banned

Join Date: Aug 2010
Location: https://www.scirus.com/ & https://www.google.com/schhp?hl=en
Posts: 2,431
spurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nicespurr is just really nice
@ stress test,

I am curious, why did you post that? I am curious because it has nothing to do with my thread. That is not to say what you posted in not important. What you posted is why Tor (and any proxy to the Internet), should be used with HTTPS whenever possible. No one should be using ICmag without HTTPS, with or without using Tor.

In a perfect world there would be no HTTP, it would all be HTTPS, and of course, SSL would be much more secure.
spurr is offline Quote


Old 01-12-2011, 12:17 PM #7
Nadicus_Maximus
Member

Nadicus_Maximus's Avatar

Join Date: Jan 2011
Posts: 188
Nadicus_Maximus will become famous soon enoughNadicus_Maximus will become famous soon enough
Spurr, Thanks for a most tasty post. One can never be too safe. Viva la TOR
Nadicus_Maximus is offline Quote


Old 01-16-2011, 04:24 AM #8
wantaknow
ruger 500

wantaknow's Avatar

Join Date: Apr 2004
Location: usa
Posts: 2,100
wantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of lightwantaknow is a glorious beacon of light
i am very glad he posted that info ,all info is needed to to make good decisions ,
__________________
Free leonard peltier now,
wantaknow is offline Quote


Old 01-16-2011, 07:08 PM #9
Strainhunter
Tropical Outcast

Strainhunter's Avatar

Join Date: Oct 2009
Location: Tropical Island
Posts: 2,937
Strainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to allStrainhunter is a name known to all
- edit -

Never mind I figured it out!

__________________
.


Something every grower "on the grid" should be aware of:


Smart Meters - a few common misconceptions cleared up here.


Last edited by StrainHunter; 01-16-2011 at 10:43 PM..
Strainhunter is offline Quote


Old 01-16-2011, 10:12 PM #10
WaywardBob
paranormal peripherals

WaywardBob's Avatar

Join Date: Jan 2007
Location: CA
Posts: 314
WaywardBob will become famous soon enoughWaywardBob will become famous soon enough
this post is coming from someone who doesnt know much about browers and all that configuration stuff...

from the title, it sounded like Tor Browser is a program itself, but reading on thru ur post it sounds like Tor Browser is an addon for firefox? can someone please clarify this for me
__________________
WaywardBob, over and out.

An ICE plant, 1000w, 180 days, and a 10 gallon pot -- Harvested
WaywardBob is offline Quote


Post Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT +2. The time now is 12:57 PM.


Visit Sensi Seeds For all your Genetic Needs!


This site is for educational and entertainment purposes only.
You must be of legal age to view ICmag and participate here.
All postings are the responsibility of their authors.
Powered by: vBulletin Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.