After six months of development significant release of a specialized browser , which continues the development of functionality based on the ESR branch . The browser focuses on ensuring anonymity, security, and privacy, with all traffic routed solely through the Tor network. Direct access via the current system's standard network connection is impossible, which prevents tracking the user's real IP (in the case of a browser compromise, attackers may access system network parameters, so to fully block possible leaks, products such as ). Tor Browser builds for Linux, Windows, macOS, and Android.
To ensure additional protection, it includes an extension , allowing traffic encryption on all sites wherever possible. To reduce the threats from attacks utilizing JavaScript and blocking plugins by default, an extension is included . To combat traffic blocking and inspection, the following are used and .
To establish an encrypted communication channel in environments that block any traffic except HTTP, alternative transports are offered, which allow, for example, to bypass attempts to block Tor in China. To protect against user tracking and to prevent the highlighting of characteristics specific to individual visitors, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or restricted, and telemetry sending tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, and "link rel=preconnect" have been disabled, along with modified libmdns.
In the new release:
- A website availability indicator has been implemented, displayed in the address bar when viewing a regular web page. Upon the first visit to a site also accessible via an onion address, a dialog appears offering to automatically switch to the onion site when opening the web version in the future. Information about availability via an .onion address is transmitted by the website owner using HTTP headers. .
- Owners of hidden services who wish to restrict access to their resources can now set a set of keys for access control and authentication. Users can save the provided access key on their system and use the Onion Services Authentication interface in "about:preferences#privacy" to manage keys.

- Security indicators in the address bar have been enhanced. The focus has shifted from indicating a secure connection to signaling security issues. Secure onion connections are now not highlighted and are marked with a standard gray icon. If an insufficient level of connection protection is detected while accessing an onion service, the connection indicator is crossed with a red line. An additional warning in the form of an exclamation mark icon is displayed when mixed-content resources are detected on the page.
- Separate error pages have been added for connection errors to onion services (previously, the standard Firefox error pages, the same as for web pages, were shown). New pages include additional information for diagnosing the reasons for being unable to connect to the hidden service, allowing insights into problems with the address, service, client, or network infrastructure.
- For easier access to onion sites, an experimental feature for binding symbolic names has been provided, addressing issues with remembering and searching for onion addresses. To simplify access, in collaboration with the Freedom of the Press Foundation (FPF) and the Electronic Frontier Foundation (EFF), a prototype name catalog based on the HTTPS Everywhere extension has been developed. Currently, symbolic names for SecureDrop onion services are available for testing: theintercept.securedrop.tor.onion and lucyparsonslabs.securedrop.tor.onion.
- Third-party component versions have been updated, including
NoScript 11.0.26,
Firefox 68.9.0esr,
HTTPS-Everywhere 2020.5.20,
NoScript 11.0.26, Tor Launcher 0.2.21.8, and
Tor 0.4.3.5. - The Android version now includes a warning about potential proxy bypass when launching external applications. Issues with obfs4 usage have been resolved.
Source: opennet.ru

