Tor Browser 7.0.1 is now available from the Tor Browser Project page and also from our distribution directory.
This release features important security updates to Firefox.
This is the first minor release in the 7.0 series, updating Firefox to 52.2.0esr, Tor to 0.3.0.8, and HTTPS-Everywhere to 5.2.18. Additionally, we worked around an annoying freezing of Tor Browser which is due to a NoScript bug and made the security slider window slightly larger.
Here is the full changelog since 7.0:
- All Platforms
- OS X
- Bug 22558: Don't update OS X 10.7.x and 10.8.x users to Tor Browser 7.0
Comments
tenks
tenks
TOR is by far one of the…
TOR is by far one of the best internet tools i have ever come across, thank you guys, keep up the good work.
es una mierda mi antivirus…
es una mierda mi antivirus lo detecta como un virus con troyanos tr/atraps.gen2 mejor pongan una opcion para bloquear actualizaciones automaticas
using torbrowser 7.0.1 at…
using torbrowser 7.0.1 at ipcheck.info,, authentication shows in red [bad]
why is this? is cause for concern?
Should I use v6.5.2 or v7.0…
Should I use v6.5.2 or v7.0.1 with session authentication fail?
You should use version 7.0.1…
You should use version 7.0.1. Version 6.5.2 has known security vulnerabilities.
thx. so it's not a problem…
thx. so it's not a problem with Authentication red in ip-check.info?!
If you create a new identity…
If you create a new identity it will show a different authentication number. The site must have not noticed the update or something
We think this is a bug in…
We think this is a bug in the test which is not able anymore to detect our defense against that tracking method. See: https://trac.torproject.org/projects/tor/ticket/21756.
But I think that is real…
But I think there is real problem when I closed all tabs, cleaned cache web content, changed tor circuit and if I reloaded ipcheck.info it shows me the same unique ID number of authentication until I quit torbroser.
So where does the number…
So where does the number come from ?
Let's assume you have domain…
Let's assume you have domain A in your URL bar which embedds an iframe C doing the tracking trick ip-check.info deploys. In Tor Browser < 7 we did not allow A reading authentication credentials C tried to set which is why the ip-check test showed a green result. Think about forbidding 3rd party cookies which is basically the same. Now while this is blocking tracking across domains (e.g. if C were embedded in a different URL bar domain B as well) the downside is that it may break some sites, e.g. if A tries to access that information which is usually available.
In Tor Browser 7 we changed that by allowing A to access the HTTP auth saved by C which is all the ip-check test checks (and hence is showing you the scary warning now) BUT we prevented at the same time B from reading that value saved by C formerly while the user has been on A. Thus, tracking across domains (across A and B) is prevented, but the ip-check needs an update to take that into account. If you want to have a test, take the one Arthur has written in https://trac.torproject.org/projects/tor/ticket/21756#comment:2. It's not so fancy, yes, but it tests what is actually happening.
thanks for another great…
thanks for another great release! tracking mozilla's release cycle so closely is exciting and much appreciated
For some reason I cannot get…
For some reason I cannot get the Mac version of TOR 7.0.1 to download. Tried it multiple times with no success. The file directory page shows the file links are broken. I've been using the the 7.0.1a RC version for some time now without issue.
Which link is broken?…
Which link is broken?
The download links from the Tor Browser page should be working:
https://www.torproject.org/download/download-easy.html.en
Why does TB 7.0* need access…
Why does TB 7.0* need access to:
/proc/*/net/route r,
/proc/*/net/arp r,
How do you tell it does?…
How do you tell it does? What are you using, SELinux or what?
Debian Jessie, apparmor…
Debian Jessie, apparmor.
"Could not connect to control port"
"Failed to take control of Tor"
How do you tell it does?…
How do you tell it does? What are you using, SELinux?
My guess is https://bugzilla…
My guess is https://bugzilla.mozilla.org/show_bug.cgi?id=1240932. See https://trac.torproject.org/projects/tor/ticket/21727 for the ticket on our side.
has anybody had experience…
has anybody had experience with protonmail issues? since version 7.0 there are some performance problems. works still with older versions before 7.0
Yes, you should set the…
Yes, you should set the security slider to low to get it to work without issues.
It's because in the Medium settings JS JIT (Just-in-time compilation) is disabled.
Change security slider.
Change security slider.
see…
see
https://trac.torproject.org/projects/tor/ticket/22544
https://trac.torproject.org/projects/tor/ticket/22500
or try to get access to…
or try to get access to protonmail bridge
I think that since v7 some…
I think that since v7 some site don't work as they used to. For example, some images aren't loaded or the layout of some sites looks different.
Also, taking a screenshot using shift+F2 doesn't work the same as before, for example the dpr or the fullscreen switches don't work, and you don't get the option to select the path of the file.
It would be great if you…
It would be great if you could post some way to reproduce your issues.
I think that the first part…
I think that the first part was due to cloudflare messing things up, maybe more aggressively than how it used to.
The second part is easily reproduced, for example Shift+F2, then 'screenshot test.png --fullscreen'
Which operating system is…
Which operating system is that? FWIW there is no --fullscreen option it seems. I guess you mean --fullpage? Testing on a Linux box I have both options available. But, yes, there is no option to select the path to save the item. But that is not available with a vanilla Firefox as well it seems.
You are right, the option is…
You are right, the option is --fullpage and the bug appears on windows.
Tested on a Windows 7…
Tested on a Windows 7 machine both with normal Firefox and with Tor Browser 7: the result is the same for me. Both options are there, the fullpage mode is working and in both browsers there is no prompt for the path. What steps to reproduce your problem am I missing?
v7.0 & v7.0.1 - neither one…
v7.0 & v7.0.1 - neither one can I save any image files to disc. v6.5.2 works fine. No modifications or changes to the settings, whatsoever.
Anyone with this same issue?
How are you trying to do…
How are you trying to do that? Could you give us an example URL where that is not working anymore for you as well?
Maybe, but only with video…
Maybe, but only with video.
NoScript requires the video to be blocked, you mustn't have allowed a temporary permission for it, in order to successfully download the file. Otherwise, it may ask you where to save it but not actually download it. This is a regression by the way.
I tested downloading an image with high security settings and it worked. Have you changed any settings to TorBrowser or NoScript?
Have you steps to reproduce…
Have you steps to reproduce that regression?
Yes…
Yes.
1. Go to: https://gemmei.ftp.acc.umu.se/pub/debian-meetings/2016/miniconf_cambrid…, NoScript will display the video as a blocked object.
2. Click on the object and allow the video to play.
3. Right click "Save Video As...", choose a location, and accept.
4. Open "about:downloads" to verify the video isn't downloading.
5. Now, right click anywhere and under the NoScript menu click "Revoke Temporary Permissions".
6. Repeat step 1, you will presented with the blocked object. Right click on that object and choose "Save Link As...", accept.
7. Open "about:downloads" and verity the video is now downloading.
Interesting, thanks. Which…
Interesting, thanks. Which operating system are you on?
linux64, it would blow my…
linux64, it would blow my mind if this was linux specific, though.
And if I may, I'll sneak another minor bug report in, when running tor-browser with "./start-tor-browser.desktop --detach --log" two "tor-browser.log" files are created, one inside "tor-browser_en-US/", the current working directory, which is where it should be, and an empty one in the users home dir. That one shouldn't be there.
Thanks!
Hm, interesting. I just…
Hm, interesting. I just checked but I only get the first, intended one. Do I need to do something in particular to trigger the creation of the other log file starting with a clean, new Tor Browser?
I just did some testing, the…
I just did some testing, the problem is somewhere in "start-tor-browser.desktop".
This is what I did: extracted the tor-browser tarball into the home dir, changed the working directory to ~/tor-browser_en-US, ran "./start-tor-browser.desktop --log --detach". The extra empty log file was there. I also tried swapping '--log' and '--detach', and not changing the working directory from home, it still happened.
If I run "~/tor-browser_en-US/Browser/start-tor-browser --log --detach" directly, then only one log file is created.
I don't use *.desktop files so I may be way off, but isn't '--detach' implied? I don't know how options are being passed to 'start-tor-browser', if at all, but maybe it's running '--detach' twice?
I see, thanks for reporting…
I see, thanks for reporting and investigating. I've opened https://trac.torproject.org/projects/tor/ticket/22633.
But it works for the second…
But it works for the second time (or any? when extapphelper dialog appears :)
Okay, I've filed https:/…
Okay, I've filed https://trac.torproject.org/projects/tor/ticket/22616 for this problem. Thanks for reporting.
Avast(antivirus) flipped out…
Avast(antivirus) flipped out on tor after it updated to 7.0.1 for me, same with the 7.0.1 installer. (Both got were "IDP generic Infection") Now I can't even download the installer (Avast is blocking it), what do I do?
I think you should get rid…
I think you should get rid of Avast. If you really think you need some firewall/antivirus means use the Windows ones.
Cloudflare is going crazy…
Cloudflare is going crazy again?
Can't goto theregister.co.uk with tbb7.0.1, tested without javascript.
Is this the permanent state of affairs now?
I see this…
I see this.
"Please turn JavaScript on and reload the page.
DDoS protection by Cloudflare"
but I don't go to theregister regularly.
See this comment https:/…
See this comment https://blog.torproject.org/comment/268994#comment-268994
Everytime you post to blog…
Everytime you post to blog.torproject.org, it's loading endless. Striking and traceable?
It might be https://trac…
It might be https://trac.torproject.org/projects/tor/ticket/22530 but it is hard to say without knowing more about your Tor Browser settings.
Add new comment