A significant release of the specialized Tor Browser 11.0 has been announced, which transitions to the ESR version of Firefox 91. The browser focuses on ensuring anonymity, security, and privacy, with all traffic routed exclusively through the Tor network. Direct access via the system's standard network connection is impossible, which prevents tracking of the user's real IP address (if the browser is compromised, attackers may gain access to system network settings, so to fully block potential leaks, products like Whonix should be used). Tor Browser builds are prepared for Linux, Windows, and macOS. The release of a new version for Android is delayed.
To provide additional protection, Tor Browser includes the HTTPS Everywhere extension, allowing encryption of traffic on all sites where possible. To mitigate threats from JavaScript-based attacks and to block plugins by default, the NoScript extension is included. To combat traffic blocking and inspection, fteproxy and obfs4proxy are utilized.
For establishing an encrypted communication channel in environments that block any traffic except HTTP, alternative transports are offered, which, for example, allow circumventing attempts to block Tor in China. To protect against tracking user movement and isolating specific characteristics of individual visitors, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, WebAudio, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or limited, as well as telemetry submission tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, "link rel=preconnect", modified libmdns.
In the new version:
- The code base has transitioned to Firefox 91 ESR and the new stable branch tor 0.4.6.8.
- The user interface reflects significant design changes proposed in Firefox 89. Icon graphics have been updated, the style of various elements has been unified, the color palette has been revamped, the tab bar design has been changed, the menu has been restructured, the built-in menu '...' in the address bar has been removed, and the design of information panels and modal dialogs with warnings, confirmations, and requests has been altered.

Specific interface changes for Tor Browser include an upgrade of the Tor network connection screen design, display of selected node chains, security level selection interfaces, and error pages for onion connections. The 'about:torconnect' page has been redesigned.

- A new module TorSettings has been implemented, which contains functionality responsible for changing the specific settings of Tor Browser in the configurator (about:preferences#tor).
- Support for old onion services based on the second version of the protocol has been discontinued, which was declared obsolete a year and a half ago. Attempting to open an old 16-character onion address will now result in an error message "Invalid Onion Site Address." The second version of the protocol was developed about 16 years ago and, due to the use of outdated algorithms, can no longer be considered secure in modern conditions. Two and a half years ago, in release 0.3.2.9, users were introduced to the third version of the protocol for onion services, notable for switching to 56-character addresses and providing more reliable protection against data leaks through servers directories, an expandable modular structure, and the use of SHA3, ed25519, and curve25519 algorithms instead of SHA1, DH, and RSA-1024.

Source: opennet.ru



