TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tor Browser 11.5: automatic censorship detection, HTTPS-Only by default and more

57 点作者 jerheinze将近 3 年前

5 条评论

fuglede_将近 3 年前
Here&#x27;s a small historical curiosity: In HTTPS Everywhere, the functionality used to be call &quot;Block all HTTP requests&quot; but when that functionality was changed (back in 2016 [0]) to not block connections to non-HTTPS hidden services, it was renamed to &quot;Block all unencrypted requests&quot;.<p>I just checked, and indeed Tor Browser 11.5 does not block non-HTTPS connections to hidden services, even when in &quot;HTTPS-Only&quot; mode. Thankfully.<p>[0]: <a href="https:&#x2F;&#x2F;github.com&#x2F;EFForg&#x2F;https-everywhere&#x2F;pull&#x2F;4370" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;EFForg&#x2F;https-everywhere&#x2F;pull&#x2F;4370</a>
i67vw3将近 3 年前
Any update on this <a href="https:&#x2F;&#x2F;blog.torproject.org&#x2F;domain-fronting-critical-open-web&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.torproject.org&#x2F;domain-fronting-critical-open-we...</a><p>As I get it, to connect to bridges (get data) it will use normal clearnet https. But, to avoid getting yourself flagged (at the time you are getting data about bridges), it will use moat and pretend to connect to Microsoft Azure servers to get the info about bridges. The blog post is from 2018, so is tor project still using azure, or did the whole &#x27;domain-fronting&#x27; feature get blocked from azure too just like AWS and google.
评论 #32108821 未加载
gravitate将近 3 年前
Great. I used to have HTTPS Everywhere extension installed in Tor Browser Bundle, with the EASE&#x2F;Encrypt All Sites Eligible toggle turned on to avoid browsing HTTP only sites during casual surfing. Some exit nodes are malicious and slurp up plaintext HTTP and there is the risk of leaking stuff with plaintext sites. With a native implementation of HTTPS-Only I don’t have to install an addon and it will force people to not browse HTTP sites, unless they turn it off which adds to the fingerprintability of the browser, so I would recommend against messing with the default setting.
Trouble_007将近 3 年前
Tor Browser 11.5 - July 7 2022 - Change Log (Text) : <a href="https:&#x2F;&#x2F;gitweb.torproject.org&#x2F;builders&#x2F;tor-browser-build.git&#x2F;plain&#x2F;projects&#x2F;tor-browser&#x2F;Bundle-Data&#x2F;Docs&#x2F;ChangeLog.txt?h=maint-11.5" rel="nofollow">https:&#x2F;&#x2F;gitweb.torproject.org&#x2F;builders&#x2F;tor-browser-build.git...</a>
midislack将近 3 年前
Does it still use the same guard node forever or did they fix that?