A DNS leak has been identified in Brave revealing information about onion sites being opened in Tor mode.

A DNS leak has been identified in the Brave web browser that reveals information about onion sites accessed in private browsing mode, where traffic is routed through the Tor network. Fixes for this issue have already been integrated into the Brave codebase and will be included in the next stable update.

The cause of the leak was an ad blocker that has been suggested to be disabled while using Tor. Recently, advertising networks have been circumventing ad blockers by loading ad blocks using a subdomain native to the site, which requires a CNAME record to be created on the site's DNS server pointing to the ad network host. Consequently, the ad code is formally loaded from the same primary domain as the site, hence avoiding block. domain, which leads to evasion of blocking. To detect such manipulations and identify the associated host via CNAME, ad blockers perform additional name resolution in DNS.

In Brave, normal DNS queries while opening a site in private mode passed through the Tor network, but the ad blocker resolved CNAME through the primary DNS server, resulting in a leak of information about the accessed onion sites to the provider's DNS server. Notably, Brave's private browsing mode based on Tor is not marketed as guaranteeing anonymity, and users are warned in the documentation that it does not replace the Tor Browser but merely uses Tor as a proxy.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster