Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Privacy Guides
@privacyguides@mastodon.neat.computer  ·  activity timestamp 7 months ago

PSA: The Tor Browser Security Level slider cannot be relied upon without a full browser restart (per an anonymous community report and confirmed by Privacy Guides staff) - Make sure you are aware of this if you rely on this feature for your safety.

https://www.privacyguides.org/articles/2025/05/02/tor-security-slider-flaw/

#TorBrowser #Security #MullvadBrowser #Privacy #PrivacyGuides #Article

Privacy Guides

A Flaw With the Security Level Slider in Tor Browser

PSA: The security level slider in Tor Browser (and Mullvad Browser) does not fully apply until restarting the browser. This presents a high risk to people who switch from Standard to Safer security during a browsing session in order to protect themselves from browser exploits.
  • Copy link
  • Flag this post
  • Block
Privacy Guides
@privacyguides@mastodon.neat.computer replied  ·  activity timestamp 7 months ago

Following the publication of this article, the Tor Project emailed us the following statement.

[1]: https://gitlab.torproject.org/tpo/applications/wiki/-/wikis/
[2]: https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42572

The Tor Project is aware of this issue, and it is being tracked and actively addressed. Those interested can follow the discussion and progress [on GitLab (link in Mastodon post)]. In addition to a restart prompt, we’re also exploring broader improvements to the security level system, including aligning it more closely with Tor Browser's updated threat model and possibly delegating even more of its back-end to NoScript for additional flexibility. These improvements may be part of the upcoming 15.0 release cycle.
The Tor Project is aware of this issue, and it is being tracked and actively addressed. Those interested can follow the discussion and progress [on GitLab (link in Mastodon post)]. In addition to a restart prompt, we’re also exploring broader improvements to the security level system, including aligning it more closely with Tor Browser's updated threat model and possibly delegating even more of its back-end to NoScript for additional flexibility. These improvements may be part of the upcoming 15.0 release cycle.
The Tor Project is aware of this issue, and it is being tracked and actively addressed. Those interested can follow the discussion and progress [on GitLab (link in Mastodon post)]. In addition to a restart prompt, we’re also exploring broader improvements to the security level system, including aligning it more closely with Tor Browser's updated threat model and possibly delegating even more of its back-end to NoScript for additional flexibility. These improvements may be part of the upcoming 15.0 release cycle.
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login