Release of Tor Browser 13.0

A significant release of the Tor Browser 13.0 has been formed, transitioning to the ESR branch of Firefox 115. The browser focuses on providing anonymity, security, and privacy, with all traffic routed exclusively through the Tor network. Direct access via the current system's standard network connection is not possible, which prevents tracking the user's real IP address (in the event of a browser compromise, attackers could access system network parameters, so to completely block potential leaks, products like Whonix should be used). Tor Browser builds are prepared for Linux, Android, Windows, and macOS.

For added protection, the Tor Browser includes the "HTTPS Only" setting, allowing for encrypted traffic on all websites where possible. To mitigate threats from JavaScript attacks, the NoScript extension is included to block plugins by default. Fteproxy and obfs4proxy are used to combat traffic blocking and inspection.

For establishing an encrypted communication channel in environments that block any traffic except HTTP, alternative transports are offered, which, for example, allow circumventing attempts to block Tor in China. To protect against tracking user movement and isolating specific characteristics of individual visitors, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, WebAudio, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or limited, as well as telemetry submission tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, "link rel=preconnect", modified libmdns.

In the new version:

  • The transition to the Firefox 115 ESR codebase and the stable branch of Tor 0.4.8.7 has been completed. During the transition to the new version of Firefox, an audit of changes made since the release of the Firefox 102 ESR branch was conducted, and security- and privacy-sensitive patches were disabled. Among other changes, code for string-to-double conversion was replaced, the recent links sharing feature was disabled, the API for saving PDFs was turned off, the service and interface for automatically hiding cookie confirmation banners were removed, and the text recognition interface was eliminated.
  • Icons have been updated, and the application logo has been refined while maintaining overall recognizability.
    Release of Tor Browser 13.0
  • A new implementation of the homepage ("about:tor") has been proposed, notable for adding a logo, simplifying the layout, and retaining only the search bar and the "onionize" toggle for accessing DuckDuckGo via the onion service. The rendering of the homepage has improved support for screen readers and tools for people with disabilities. A bookmarks panel has been included. The issue of the "red screen of death," which occurred due to a failure in checking the connection to the Tor network, has been resolved.

    Now:

    Release of Tor Browser 13.0

    Previously:

    Release of Tor Browser 13.0
  • The size of the new windows has been increased, now selecting a more user-friendly aspect ratio by default for wide-screen users. To prevent the leakage of information about screen and window sizes in Tor Browser, a letterboxing mechanism is implemented, adding margins around the content of web pages. In previous versions, as the window size changed, the active area size changed in increments of 200×100 pixels but was limited to a maximum resolution of 1000×1000, which created issues with some sites displaying horizontal scroll bars or presenting tablet and mobile versions due to insufficient width. To address this issue, the maximum resolution has been increased to 1400×900 and the step-based resizing logic has been altered.
    Release of Tor Browser 13.0
  • A new package naming scheme has been implemented, following the pattern `${ARTIFACT}-${OS}-${ARCH}-${VERSION}.${EXT}`. For example, the build for macOS was previously distributed as "TorBrowser-12.5-macos_ALL.dmg", but now it appears as "tor-browser-macos-13.0.dmg".
  • When the "Safest" mode is selected for searching through DuckDuckGo, a version of the site without JavaScript is now used.
  • Enhanced protection against leaks through WebRTC.
  • URL parameters used for tracking movements have been cleaned up (for example, mc_eid and fbclid parameters used when clicking on links from Facebook pages are removed).
  • The setting javascript.options.large_arraybuffers has been removed.
  • On the Linux platform, the setting browser.tabs.searchclipboardfor.middleclick has been disabled.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster