Anyone have any good information on using ublock origin with tor browser? Does it compromise my anonymity?
It’s highly discouraged to add further add ons on Tor since you will be more easily fongerprintable.
The only thing you should change on Tor are security settings, nothing else.
It makes sense for it to have a built in ad-blocker. Any idea why they don’t do that?
Hi! It doesn’t make sense at all. Blocking ads & trackers is not a good approach to achieve privacy. It’s quite weak actually for many reasons…
First of all, because enumeration badness doesn’t work; it’s not possible to create a list of every possible “malicious domain”. And even if it was possible, websites could develop their own first party tracking and then share the information to third parties like Google or Facebook.
Second of all, because apps and websites can detect what domains are blocked, thus they -or malicious actors- will able to uniquely identify users more easily.
Third of all, because extensions add more attack surface since they use privileged script in order to work.
That’s why Tor doesn’t use any ad-blocker.
For more information about enumeration badness and browser tracking you can see here and here
Removed by mod
I can totally see how Madaidan can cause fear, uncertainty, and doubt. When I read, for example, his criticisms of Linux, I felt not only that, but also disappointment. You for sure have good reasons to dislike Madaidan and either GraphenOS or the Lemmy GrapheneOS community. But I don’t know them. Could you explain a bit why Madidan and GrapheneOS (or it’s Lemmy community) are problematic? Your answer would help me see what you see :)
Is important to understand that madaidan isn’t spreading any FUD or fear or doubts whatsoever.
His criticism toward Linux is justified and well written. People who actually work with Linux everyday can confirm that.
- Brad Spengler, the developer of the most extensive kernel hardening patchset in existence and inventor of many widely used exploit mitigations along with pipacs (including ASLR, W^X, CFI, etc.): https://grsecurity.net/10_years_of_linux_security.pdf
https://grsecurity.net/~spender/interview_notes.txt
https://nitter.net/grsecurity/status/1249850031357788162
https://nitter.net/spendergrsec/status/1308734202330963970
https://nitter.net/spendergrsec/status/1308762791734632454
- Kees Cook, Alexander Popov and more prominent Kernel Self-Protection Project members:
https://www.youtube.com/watch?v=v7_mwg5f2cE
- Daniel Micay, lead developer of GrapheneOS (formerly CopperheadOS), hardened_malloc, linux-hardened, etc.:
- Dmitry Vyukov, another prominent Linux security developer:
- Joanna Rutkowska, founder of QubesOS and author of many well-known security papers:
https://nitter.net/rootkovska/status/1136220742662664193
https://blog.invisiblethings.org/2011/04/23/linux-security-circus-on-gui-isolation.html
- Jon Oberheide, co-founder of Duo Security:
https://jon.oberheide.org/files/syscan12-exploitinglinux.pdf
- Solar Designer
https://www.openwall.com/lists/oss-security/2020/10/05/5
Now, that means that you should not to use Linux? Absolutely not. It’s not the point of the article. Madaidan itself uses Linux and he said many times how hate Wundows. The same goes for Firefox, he uses it as a daily driver. Basically, he uses the software he criticized, because those are simply security and technical analysys.
There is a huge difference between:
“I acknowledge that what madaidan has wrote is true, nonetheless I still keep to prefer Linux as my daily for x reasons”
“madaidan is spreading fud about Linux and other software because is a shill etc.”
And please, don’t listen to anonymousjoker. He is known as a troll in basically every privacy community.
Removed by mod
The only FUD around here is you @TheAnonymouseJoker@lemmy.ml
Removed by mod
Requesting is not begging, hence the purpose of c/community_requests
You seem like an angry person replying out of hate. I’m sorry for whatever it is that happened to you to be this way. It doesn’t give you a right to attack, harass and bully people.
Edit: your behavior is very much like an abuser in real life that gets off on verbally insulting people for your own sick and twisted kicks.
Removed by mod
It makes you a bit distinguishable from the people who don’t use an Ad-Blocker. It won’t be enough to identify you, but it does add to your digital fingerprint.
silly comments. Tails is using ublock orgin for Tor browser they ship with.
“Don’t use Tails it ruins your OP sec” lol.
A difference is that Tails includes the uBlock Origin extension, which removes advertisements. If an attacker can determine that you are not downloading the advertisements that are included in a webpage, that could reveal that you are a Tails user.
https://tails.boum.org/doc/anonymous_internet/Tor_Browser/index.en.html
Here’s the thing tho, u block might be good for your threat model. Depends what it is. any way if you are surfing clear web you got more serious opsec concerns.
Hi.
I think i didn’t explain myself because this is happened before.
The point of the comments I wrote are not aimed to say “don’t use ad-blockers” or “don’t use Linux” and so on. What I’m trying to do is “fight” the misinformation spread by certain people about these topic.
Now, while people should act according their own threat model, they should also be aware about the possible pro and cons about every software they eventually are going to use.
I’m not an expert, but in my understanding privacy is not something you can easily achieve. Browser need to carefully develop actual features designed to protect users’s privacy, like Tor browser does.
Installing a bunch of add ons aimed to “blocks ads & trackers” or *spoof user agent" will make you stand out more from the crowd.
Then if you’re comfortable with that it’s up to you. Again, there is a big difference between be aware about something and then act accordingly and be in denial mode and accuse people to spread misinformation beside the reliable sources linked.
I personally use ublock on my desktop browser because I don’t like to see a page filled with ads & tracker and I don’t care about stand out from the crowd.
Please, let me now whether I made that clear or not.
edit: I’m asking you because I tend to make typos since English is not my first language.
no it makes sense
Ok, thanks! :)
Removed by mod
i would say use it.
but if you want to blend in perfectly then you should be doing what most people do.Tails uses it so it souldnt affect your anonymity too much.
deleted by creator
Don’t do it it makes you stand out and ruins your opsec just use noscript