Brave browser privacy bug reveals user’s dark web browsing history

by | Feb 22, 2021

style="display:block" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true">
 
 
 

 

 

Reading Time: 1 Minute

 

 

Brave has fixed a browser privacy issue that sends queries for the .onion domain to the public internet DNS resolver instead of via the Tor node. This exposes user access to dark web websites.

 

 

 

The bug has been fixed in a fix release (V1.20.108) It became available yesterday.

Brave has a built-in feature called “”.Private window with tor“It integrates Tor Anonymous networks can be connected to browsers to allow users to access .onion websites hosted on the darknet without exposing their IP address information to Internet service providers (ISPs), Wi-Fi network providers, and the website itself. will do so.Features added in June 2018..

This is achieved by relaying user requests for onion URLs over a volunteer-run network of Tor nodes. At the same time, keep in mind that this feature uses Tor as a proxy and does not implement most of the privacy protection provided by Tor Browser.

 

 
 

 

 

style=”display:block” data-ad-client=”ca-pub-6620833063853657″ data-ad-slot=”8337846400″ data-ad-format=”auto” data-full-width-responsive=”true”>

 

This is achieved by relaying user requests for onion URLs over a volunteer-run network of Tor nodes. At the same time, keep in mind that this feature uses Tor as a proxy and does not implement most of the privacy protection provided by Tor Browser.

However, according to a report first published in Ramble, a bug that disrupted the privacy of Tor mode in the browser could leak all .onion addresses accessed by users to the public DNS resolver.

 

 

“The ISP or DNS provider knows that the request made to a particular Tor site was made by IP,” he posted. read..

DNS requests are unencrypted by design. This means that you can track requests to access Brave’s .onion site, defeating the very purpose of the privacy feature.

 


See Also:
Offensive Security Tool: ScareCrow

 
 

style=”display:block” data-ad-client=”ca-pub-6620833063853657″ data-ad-slot=”8337846400″ data-ad-format=”auto” data-full-width-responsive=”true”>

 

This problem is in the browser CNAME An ad blocking feature that blocks third-party tracking scripts that use CNAME DNS records, otherwise spoofing first-party scripts to avoid detection by content blockers. That way, your website can cloak third-party scripts using subdomains of your main domain, which will automatically redirect you to your tracking domain.

Brave already had as part of it Prior knowledge After being reported on the bug bounty platform HackerOne on January 13, the Nightly release 15 days ago resolved the security issue.

The patch is Initial plan It will be rolled out in Brave Browser 1.21.x, but as a result of its release, the company has announced that it will push to a stable version of the browser released yesterday.

 

 

 

style=”display:block” data-ad-client=”ca-pub-6620833063853657″ data-ad-slot=”8337846400″ data-ad-format=”auto” data-full-width-responsive=”true”>

 

See Also: SolarWinds Supply Chain Hack – The hack that shone a light on the gaps in the cybersecurity of governments and big companies

 

Brave browser users can download and install the latest updates from Menu> About Brave> in the upper right corner.

 

 

 

style=”display:block” data-ad-client=”ca-pub-6620833063853657″ data-ad-slot=”8337846400″ data-ad-format=”auto” data-full-width-responsive=”true”>

 

 

style=”display:block” data-ad-client=”ca-pub-6620833063853657″ data-ad-slot=”8337846400″ data-ad-format=”auto” data-full-width-responsive=”true”>

 

Source: www.jioforme.com

 

 

 
(Click Link)

 

 

style="display:block" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true">

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.


Join our Community

Share This