Roskomnadzor has officially made changes to the unified register of banned websites, blocking access to www.torproject.org. All IPv4 and IPv6 addresses of the main site of the project have been added to the register, but additional sites not linked to the distribution of Tor Browser, such as blog.torproject.org, forum.torproject.net, and gitlab.torproject.org, remain accessible. The blocking also does not affect official mirrors, such as tor.eff.org, gettor.torproject.org, and tb-manual.torproject.org. The version for the Android platform continues to be distributed through the Google Play store.
The blocking was carried out based on an old decision by the Saratov District Court, made back in 2017. The Saratov District Court recognized the distribution of the Tor Browser on www.torproject.org as illegal, as it allows users to access sites containing information included in the Federal list of extremist materials banned from distribution within the territory of the Russian Federation.
Thus, by the court's decision, the information contained on www.torproject.org has been deemed prohibited for distribution within the territory of the Russian Federation. This decision was entered into the register of banned websites in 2017, but for the past four years, the entry had been marked as not subject to blocking. Today, the status was changed to 'access is restricted.'
Notably, the changes to activate the blocking were made within hours after a warning was posted on the Tor project’s website regarding the situation with blocks in Russia, which mentioned that the situation could quickly escalate into a full-scale blocking of Tor in the RF and described possible ways to circumvent the block. Russia ranks second in the number of Tor users (approximately 300,000 users, or about 14% of all Tor users), second only to the USA (20.98%).
In case of a network blockage, rather than just a site blockage, users are advised to use bridge nodes. The address of a hidden bridge node can be obtained at bridges.torproject.org, by sending a message to the Telegram bot @GetBridgesBot, or by emailing bridges@torproject.org with an empty subject and the text 'get transport obfs4' through services like Riseup or Gmail. To help bypass restrictions in the RF, enthusiasts are encouraged to participate in creating new bridge nodes. Currently, there are about 1600 such nodes (1000 can be used with the obfs4 transport), of which 400 have been added in the last month.
Additionally, it is worth noting the release of the specialized distribution Tails 4.25 (The Amnesic Incognito Live System), based on a Debian package base and designed for secure anonymous web access. Anonymous access in Tails is provided by the Tor system. All connections, except traffic through the Tor network, are blocked by a packet filter by default. To store user data in the data persistence mode between launches, encryption is employed. A 1.1 GB iso image has been prepared for use in Live mode.
In the new version:
- The versions of Tor Browser 11.0.2 (the official release has not yet been announced) and Tor 0.4.6.8 have been updated.
- Included is a utility with an interface for creating and updating backups of persistent storage, which contains user-modifiable data. Backups are saved to another USB drive with Tails, which can be considered a clone of the current storage device.
- A new entry 'Tails (External Hard Disk)' has been added to the GRUB boot menu, allowing Tails to be launched from an external hard drive or one of several USB drives. This mode can be used when the standard boot process ends in an error indicating that the live system image cannot be found.
- A shortcut has been added to restart Tails in case the Unsafe Browser is not enabled in the system login welcome screen.
- Error messages regarding connections to the Tor network have been enhanced with links to documentation providing recommendations for resolving common issues.
Also worth mentioning is the corrective release of the Whonix 16.0.3.7 distribution, aimed at providing guaranteed anonymity, security, and protection of private information. The distribution is based on Debian GNU/Linux and uses Tor for anonymity. A unique feature of Whonix is its division into two separately installable components: Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation, featuring the Xfce desktop. Both components are delivered within a single bootable image for virtualization systems. Network access from the Whonix-Workstation environment is only possible through the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only the use of fake network addresses.
This approach protects the user from leaking real an IP address in the event of a web browser hack and even when exploiting a vulnerability that grants the attacker root access to the system. Hacking the Whonix-Workstation would allow an attacker to obtain only fake network parameters, as the real IP and DNS parameters are hidden behind the network gateway, which routes traffic only through Tor. The new version includes updates to Tor 0.4.6.8 and Tor Browser 11.0.1, and an optional setting for filtering outgoing IP addresses using a whitelist, outgoing_allow_ip_list, has been added to the firewall of Whonix-Workstation.
Source: opennet.ru
