Release of Tor Browser 10.5

After ten months of development, a major release of the specialized browser Tor Browser 10.5 has been presented, which continues to build on the functionality based on the ESR branch of Firefox 78. The browser is focused on ensuring anonymity, security, and privacy, with all traffic being redirected solely through the Tor network. It is impossible to connect directly via the standard network connection of the current system, which prevents tracking the real IP address of the user (in the event of a browser hack, attackers may access system network parameters, so to completely block potential leaks, products like Whonix should be utilized). Tor Browser builds are prepared for Linux, Windows, and macOS.

To provide additional protection, Tor Browser includes the HTTPS Everywhere extension, allowing encryption of traffic on all sites where possible. To mitigate threats from JavaScript-based attacks and to block plugins by default, the NoScript extension is included. To combat traffic blocking and inspection, fteproxy and obfs4proxy are utilized.

For establishing an encrypted communication channel in environments that block any traffic except HTTP, alternative transports are offered, which, for example, allow circumventing attempts to block Tor in China. To protect against tracking user movement and isolating specific characteristics of individual visitors, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, WebAudio, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or limited, as well as telemetry submission tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, "link rel=preconnect", modified libmdns.

In the new version:

  • Among the built-in bridge gateways used for connecting in locations where Tor blocking is applied, a new gateway called "Snowflake" has been added, which utilizes volunteer-run proxy networks.serversFunctionally, Snowflake is similar to flash proxies, but it addresses NAT issues. Interaction with the proxy is carried out via the P2P protocol WebRTC, which supports bypassing address translators.

    Currently, there are about 8,000 proxies actively running across various networks worldwide every day. The maintenance of a large network of proxy servers is facilitated by the fact that running your own proxy does not require a server application; it is sufficient to install a special browser extension on the user's system. At the initial connection, the technique of 'domain fronting' is used, allowing HTTPS requests with a fake host specified in the SNI and the actual requested host name transmitted in the HTTP Host header within the TLS session (for example, content delivery networks can be used to bypass blocks).

    Release of Tor Browser 10.5
  • A notification has been added regarding the discontinuation of support for old onion services based on the second version of the protocol, which was declared obsolete a year ago. The complete removal of the code related to the second version of the protocol is expected in the fall. The second version of the protocol was developed about 16 years ago and cannot be considered secure in modern conditions due to the use of outdated algorithms. Two and a half years ago, in version 0.3.2.9, users were offered the third version of the protocol for onion services, notable for transitioning to 56-character addresses, improved leak protection through directory servers, an expandable modular structure, and the use of SHA3, ed25519, and curve25519 algorithms instead of SHA1, DH, and RSA-1024.
    Release of Tor Browser 10.5
  • The interface for the first connection to the Tor network has been improved, moving it from the panel to the main screen and implemented as a new service page 'about:torconnect'. The browser now automatically detects operation from censored networks and offers bridge gateways to bypass blocking.
    Release of Tor Browser 10.5
  • On the Linux platform, build capabilities with Wayland support have been provided.
  • Updated versions of NoScript 11.2.9, Tor Launcher 0.2.30, libevent 2.1.12.
  • Support for CentOS 6 has been discontinued.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster