After five months of development significant release of a specialized browser , focusing on ensuring anonymity, security, and privacy. All traffic in Tor Browser is routed only through the Tor network, and direct access via the current system’s normal network connection is impossible, which prevents tracking the user’s real IP address (in case of a browser compromise, attackers can access the system's network parameters, so to completely block potential leaks, products such as ). Tor Browser builds for Linux, Windows, macOS, and Android.
To ensure additional protection, it includes an extension , allowing traffic encryption on all sites wherever possible. To reduce the threats from attacks utilizing JavaScript and blocking plugins by default, an extension is included . To combat traffic blocking and inspection, the following are used and .
To establish an encrypted communication channel in environments that block any traffic except HTTP, alternative transports are offered, which allow, for example, to bypass attempts to block Tor in China. To protect against user tracking and to prevent the highlighting of characteristics specific to individual visitors, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or restricted, and telemetry sending tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, and "link rel=preconnect" have been disabled, along with modified libmdns.
In the new release:
- The transition to a new significant release has been completed. and the ESR branch ;
- The separate ‘Onion Button’ has been removed from the toolbar. Functions for viewing the traffic path through the Tor network and requesting a new chain of nodes used for traffic forwarding in Tor are now available through the ‘(i)’ button at the beginning of the address bar;
- The ‘New Identity’ button has been moved from the ‘Onion Button’ to the toolbar, allowing for a quick reset of settings that websites can use to track user identification (the IP changes by establishing a new chain, clearing cache contents and internal storages, and closing all tabs and windows). A link to change identity has also been added to the main menu, along with a link to request a new chain of nodes;
- The ‘letterboxing’ identification blocking technique has been activated, adding margins between the window frame and displayed content in each tab to prevent tying to the visible area size. Margins are added with the calculation of adjusting the resolution to values that are multiples of 128 and 100 pixels horizontally and vertically. If the user arbitrarily resizes the window, the visible area size becomes a factor sufficient for identifying different tabs in one browser window. Adjusting the visible area to a standard size prevents such identification;
- The Torbutton and Tor Launcher extensions are integrated directly into the browser and are no longer displayed on the ‘about:addons’ page. Tor-specific connection settings through bridge nodes and proxies have been moved to the standard browser configurator (about:preferences#tor). This includes the ability to request a list of bridge nodes or manually specify bridge nodes in the standard configurator when censorship circumvention is needed where Tor is blocked.
- When selecting security levels safer and safest, asm.js is now disabled by default;
- The Pocket indicator has been removed and is now integrated directly into Firefox;
- Support for bridge nodes based on the meek_lite transport has been added, simplifying access to Tor in countries with strict censorship (using tunneling through the Microsoft Azure cloud platform);
- The Android version now supports Android 10 and the ability to create x86_64 builds for Android (previously only ARM architecture was supported).
Source: opennet.ru
