Release of Tor Browser 11.0.2. Tor site blocking extension. Possible attacks on Tor.

The release of the specialized Tor Browser 11.0.2 has been introduced, focusing on anonymity, security, and privacy. When using Tor Browser, all traffic is routed exclusively through the Tor network, making direct access through the system's regular network connection impossible, which prevents tracking the user's real IP address (in case of a browser breach, attackers could gain access to network system parameters, hence products like Whonix should be used to fully block potential leaks). Builds of Tor Browser are prepared for Linux, Windows, and macOS.

To provide additional protection, Tor Browser includes the HTTPS Everywhere extension, which enables traffic encryption on all sites where possible. To reduce the threat from JavaScript exploitation and to block plugins by default, the NoScript extension is bundled. Alternative transports are used to combat traffic blocking and inspection. To protect against the extraction of visitor-specific features, APIs such as WebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, WebAudio, Permissions, MediaDevices.enumerateDevices, and screen.orientation are disabled or limited, and telemetry submission tools, Pocket, Reader View, HTTP Alternative-Services, MozTCPSocket, "link rel=preconnect", and a modified libmdns are also disabled.

The new version has synchronized with the code base of Firefox 91.4.0, which fixed 15 vulnerabilities, 10 of which are marked as critical. Seven vulnerabilities were caused by memory handling issues, such as buffer overflows and accessing already freed memory areas, and could potentially allow the execution of an attacker's code when specially crafted pages are opened. Some TTF fonts that caused text rendering issues in the interface elements on Fedora Linux have been excluded from the Linux build. The setting "network.proxy.allow_bypass" that controls the activity of the proxy API misuse protection in extensions has been disabled. A new gateway "deusexmachina" is used by default for obfs4 transport.

Meanwhile, the story of the Tor block in the Russian Federation continues. Roskomnadzor has changed the mask of blocked websites in its registry. domains from "www.torproject.org" to "*.torproject.org" and expanded the list of IP addresses subject to blocking. As a result of this change, most subdomains of the Tor project were blocked, including blog.torproject.org, gettor.torproject.org, and support.torproject.org. The forum.torproject.net, hosted on Discourse infrastructure, remains accessible. Partially accessible are gitlab.torproject.org and lists.torproject.org, which initially became inaccessible but were later restored, likely after a change of IP addresses (gitlab is currently directed to host gitlab-02.torproject.org).

At the same time, no blocks were noted for the Tor network gateways and nodes, as well as for the host ajax.aspnetcdn.com (Microsoft CDN), used in the meek-asure transport. Apparently, experiments with blocking Tor nodes were halted after the Tor website was blocked. A complex situation arises with the mirror tor.eff.org, which continues to operate. The thing is, the mirror tor.eff.org is tied to the same IP address, which is used for the domain eff.org of the EFF (Electronic Frontier Foundation), so blocking tor.eff.org would lead to a partial blockage of the well-known human rights organization's website.

Release of Tor Browser 11.0.2. Tor site blocking extension. Possible attacks on Tor.

Additionally, it is worth mentioning the release of a new report on possible attempts to conduct de-anonymization attacks on Tor users, linked to the KAX17 group, identified by specific dummy contact emails in the node parameters. During September and October, the Tor project blocked 570 potentially malicious nodes. At its peak, the KAX17 group managed to bring the number of controlled nodes in the Tor network to 900, hosted by 50 different providers, which accounts for approximately 14% of the total number of relays (in comparison, in 2014, attackers managed to gain control of nearly half of the Tor relays, and in 2020, 23.95% of exit nodes).

Release of Tor Browser 11.0.2. Tor site blocking extension. Possible attacks on Tor.

The placement of a large number of nodes controlled by a single operator allows for the de-anonymization of users using a Sybil attack. This can be conducted if attackers have control over the first and last nodes in the anonymity chain. The first node in the Tor chain knows the user's IP address, while the last knows the IP address of the requested resource, which enables de-anonymization of the request by adding a specific hidden label in the packet headers on the entry node side, which remains unchanged throughout the entire anonymity chain, and analyzing this label on the exit node side. If attackers control exit nodes, they can also modify unencrypted traffic, for instance, by removing redirects to HTTPS versions of sites and intercepting unencrypted content.

According to representatives of the Tor network, most of the nodes removed in the fall were only used as intermediate nodes and were not used for handling incoming and outgoing requests. Some researchers note that the nodes belonged to all categories, with the probability of encountering an entry node controlled by the KAX17 group being 16%, while for an exit node it was 5%. However, even if this is the case, the overall probability of a user simultaneously hitting both an entry and an exit node from the group of 900 KAX17-controlled nodes is estimated at 0.8%. Direct evidence of KAX17 nodes being used for attacks is lacking, but such attacks cannot be ruled out.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster