Ukukhishwa kwe-Tor Browser 11.0.2. Isandiso sokuvimbela isayithi le-Tor. Ukuhlaselwa okungenzeka ku-Tor

Ukukhishwa kwesiphequluli esikhethekile, i-Tor Browser 11.0.2, kwethulwe, kugxilwe ekuqinisekiseni ukungaziwa, ukuphepha kanye nobumfihlo. Lapho usebenzisa i-Tor Browser, yonke ithrafikhi iqondiswa kabusha kuphela ngenethiwekhi ye-Tor, futhi akunakwenzeka ukufinyelela ngokuqondile ngokuxhumeka kwenethiwekhi okujwayelekile kohlelo lwamanje, olungakuvumeli ukulandelela ikheli le-IP langempela lomsebenzisi (uma isiphequluli sigqekeziwe, abahlaseli. ingakwazi ukufinyelela kumapharamitha enethiwekhi yesistimu, ngakho-ke ukuze iphelele Ukuze uvimbele ukuvuza okungenzeka, kufanele usebenzise imikhiqizo efana ne-Whonix). Ukwakhiwa kwe-Tor Browser kulungiselelwe i-Linux, iWindows ne-macOS.

Ukuze unikeze ukuvikeleka okwengeziwe, Isiphequluli Se-Tor sihlanganisa isengezo se-HTTPS Yonke indawo, esikuvumela ukuthi usebenzise ukubethela kwethrafikhi kuwo wonke amasayithi lapho kungenzeka khona. Ukunciphisa usongo lokuhlaselwa kwe-JavaScript futhi uvimbe ama-plugin ngokuzenzakalela, isengezo se-NoScript sifakiwe. Ukulwa nokuvinjwa nokuhlolwa kwethrafikhi, kusetshenziswa okunye ukuthutha. Ukuze uvikele ekugqanyisweni kwezici eziqondene nesivakashi, iWebGL, WebGL2, WebAudio, Social, SpeechSynthesis, Touch, AudioContext, HTMLMediaElement, Mediastream, Canvas, SharedWorker, WebAudio, Permissions, MediaDevices.enumerateDevices, kanye nama-API anqunyelwe ukuqondiswa kwesikrini angama-API .amathuluzi okuthumela i-telemetry, i-Pocket, Reader View, I-HTTP Alternative-Services, MozTCPSocket, "link rel=preconnect", ilungiswe yi-libmdns.

Inguqulo entsha ivunyelaniswa nesisekelo sekhodi yokukhishwa kweFirefox 91.4.0, elungise ubungozi obuyi-15, okuyi-10 kubo kumakwe njengokuyingozi. 7 ubungozi bubangelwa izinkinga zenkumbulo, njengokuchichima kwebhafa kanye nokufinyelela ezindaweni zememori esezikhululiwe kakade, futhi kungase kuholele ekusebenziseni ikhodi yomhlaseli lapho kuvulwa amakhasi aklanywe ngokukhethekile. Amanye amafonti e-ttf ayengafakwanga ekwakhiweni kweplathifomu ye-Linux, ukusetshenziswa kwayo okuholele ekuphazanyisweni kokunikezwa kombhalo ezicini zokusebenzisana ku-Fedora Linux. Isilungiselelo esithi “network.proxy.allow_bypass” sikhutshaziwe, esilawula umsebenzi wokuvikela ekusetshenzisweni okungalungile kwe-Proxy API ngezengezo. Okokuthutha kwe-obfs4, isango elisha elithi "deusexmachina" linikwe amandla ngokuzenzakalela.

Phakathi naleso sikhathi, indaba yokuvimbela iTor eRussia Federation iyaqhubeka. I-Roskomnadzor ishintshe imaski yezizinda ezivinjiwe ekubhalisweni kwamasayithi avinjelwe isuka kokuthi “www.torproject.org” yaya kokuthi “*.torproject.org” futhi yandisa uhlu lwamakheli e-IP angaphansi kokuvinjwa. Ushintsho lubangele ukuthi izizinda eziningi zephrojekthi ye-Tor zivinjwe, okuhlanganisa i-blog.torproject.org, gettor.torproject.org, kanye ne-support.torproject.org. forum.torproject.net, esingethwe kungqalasizinda ye-Discourse, isatholakala. Okufinyeleleka kancane yi-gitlab.torproject.org kanye ne-lists.torproject.org, lapho ukufinyelela kwalahleka ekuqaleni, kodwa kwabuyiselwa, mhlawumbe ngemva kokushintsha amakheli e-IP (i-gitlab manje isiqondiswe kumsingathi gitlab-02.torproject.org).

Ngesikhathi esifanayo, amasango namanodi enethiwekhi ye-Tor, kanye nomsingathi i-ajax.aspnetcdn.com (i-Microsoft CDN), esetshenziswa ekuthuthweni kwe-miek-asure, ayengasavimbeki. Ngokusobala, izivivinyo zokuvimba izindawo zenethiwekhi ye-Tor ngemuva kokuvimba iwebhusayithi ye-Tor zimile. Kuvela isimo esinzima ngesibuko se-tor.eff.org, esiqhubeka nokusebenza. Iqiniso liwukuthi isibuko se-tor.eff.org siboshelwe ekhelini le-IP elifanayo elisetshenziselwa isizinda se-eff.org se-EFF (Electronic Frontier Foundation), ngakho ukuvimba i-tor.eff.org kuzoholela ekuvinjweni ingxenye ye-EFF. indawo yenhlangano eyaziwayo yamalungelo abantu.

Ukukhishwa kwe-Tor Browser 11.0.2. Isandiso sokuvimbela isayithi le-Tor. Ukuhlaselwa okungenzeka ku-Tor

Ukwengeza, singakuqaphela ukushicilelwa kombiko omusha ngemizamo engaba khona yokwenza ukuhlasela ukuze ukhiphe igama labasebenzisi be-Tor abahlobene neqembu le-KAX17, elikhonjwe ngama-imeyili athile okuxhumana angamanga kumapharamitha we-node. NgoSepthemba no-Okthoba, i-Tor Project ivimbe izindawo ezingaba yingozi ezingama-570. Ekuphakameni kwalo, iqembu le-KAX17 likwazile ukwandisa inani lama-node alawulwayo kunethiwekhi ye-Tor kuya ku-900, ephethwe abahlinzeki abahlukene abangu-50, okuhambisana cishe ne-14% yenani eliphelele lokudluliselwa (uma kuqhathaniswa, ngo-2014, abahlaseli bakwazile zuza ukulawula cishe uhhafu wama-Tor relays, futhi ngo-2020 ngaphezulu kwama-23.95% wama-node okukhiphayo).

Ukukhishwa kwe-Tor Browser 11.0.2. Isandiso sokuvimbela isayithi le-Tor. Ukuhlaselwa okungenzeka ku-Tor

Ukubeka inombolo enkulu yamanodi alawulwa u-opharetha oyedwa kwenza kube nokwenzeka ukususa igama labasebenzisi kusetshenziswa ukuhlasela kwesigaba se-Sybil, okungenziwa uma abahlaseli belawula amanodi okuqala nawokugcina ochungechungeni lokungaziwa. I-node yokuqala ochungechungeni lwe-Tor iyalazi ikheli lasesizindeni se-inthanethi lomsebenzisi, futhi elokugcina lilazi ikheli le-IP lesisetshenziswa esiceliwe, okwenza kube nokwenzeka ukuhoxisa isicelo ngokungeza ilebula ethile efihliwe kumahlokwana ephakethe. ohlangothini lwenodi yokufaka, ehlala ingashintshile kulo lonke uchungechunge lokungaziwa, nokuhlaziya le lebula ohlangothini lwenodi yokukhiphayo. Ngamanodi okuphuma alawulwayo, abahlaseli bangakwazi futhi ukwenza izinguquko kuthrafikhi engabetheliwe, njengokususa ukuqondisa kabusha ezinguqulweni ze-HTTPS zamasayithi kanye nokwamukela okuqukethwe okungabethelwe.

Ngokusho kwabamele inethiwekhi ye-Tor, iningi lama-node asusiwe ekwindla asetshenziswe kuphela njengama-node aphakathi nendawo, angasetshenziselwa ukucubungula izicelo ezingenayo neziphumayo. Abanye abacwaningi bayaqaphela ukuthi ama-node ayengezazo zonke izigaba futhi amathuba okufinyelela endaweni yokufaka elawulwa yiqembu le-KAX17 yayingu-16%, futhi ku-node yokukhipha - 5%. Kodwa noma ngabe lokhu kunjalo, khona-ke ithuba eliphelele lomsebenzisi ngesikhathi esifanayo lishaya ama-input nodes weqembu lama-node angu-900 alawulwa yi-KAX17 alinganiselwa ku-0.8%. Abukho ubufakazi obuqondile bokuthi ama-node e-KAX17 asetshenziselwa ukuhlasela, kodwa ukuhlasela okungenzeka okufanayo akunakugwenywa.

Source: opennet.ru

Engeza amazwana