{"id":1000815,"date":"2021-02-21T00:30:33","date_gmt":"2021-02-21T05:30:33","guid":{"rendered":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/brave-browsers-tor-feature-found-to-leak-onion-queries-to-isps-the-daily-swig\/"},"modified":"2021-02-21T00:30:33","modified_gmt":"2021-02-21T05:30:33","slug":"brave-browsers-tor-feature-found-to-leak-onion-queries-to-isps-the-daily-swig","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/brave-browsers-tor-feature-found-to-leak-onion-queries-to-isps-the-daily-swig\/","title":{"rendered":"Brave browsers Tor feature found to leak .onion queries to ISPs &#8211; The Daily Swig"},"content":{"rendered":"<p><p>    Jessica Haworth19 February 2021 at 14:27 UTC        Updated: 19 February 2021 at 21:33 UTC                                                        <\/p>\n<p>Developers are issuing hotfix<\/p>\n<\/p>\n<p>UPDATED Brave, the privacy-focused web browser, is exposing users activity on Tors hidden servers  aka the dark web  to their internet service providers, it has been confirmed.<\/p>\n<p>Brave is shipped with a built-in feature that integrates the Tor anonymity network into the browser, providing both security and privacy features that can help obscure a users activity on the web.<\/p>\n<p>Tor is also used to access .onion websites, which are hosted on the dark net.<\/p>\n<p>Earlier today (February 19), a blog post from Rambler claimed that Brave was leaking DNS requests made in the Brave browser to a users ISP.<\/p>\n<p>Read more of the latest privacy news<\/p>\n<p>DNS requests are unencrypted, meaning that any requests to access .onion sites using the Tor feature in Brave can be tracked  a direct contradiction to its purpose in the first place.<\/p>\n<p>The blog post reads: Your ISP or DNS provider will know that a request made to a specific Tor site was made by your IP. With Brave, your ISP would know that you accessed somesketchyonionsite.onion.<\/p>\n<p>Following the disclosure, well-known security researchers including PortSwigger Web Securitys James Kettle independently verified the issue using the Wireshark packet analysis tool.<\/p>\n<p>I just confirmed that yes, Brave browsers Tor mode appear to leak all the .onion addresses you visit to your DNS provider, Kettle tweeted, providing a screenshot for evidence.<\/p>\n<p>Security researcher James Kettle independently verified the Brave browser privacy issue<\/p>\n<p>Considering that the Tor Browser was specifically built to hide a users internet browsing from their ISP, the news has provoked a vociferous response online.<\/p>\n<p>Privacy my ass, wrote Twitter user @s_y_m_f_m, while other called the findings appalling.<\/p>\n<p>The issue has been present in the stable release since November 2020, and was reported in mid January, a Brave developer told The Daily Swig.<\/p>\n<p>INSIGHT Tor security: Everything you need to know about the anonymity network<\/p>\n<p>Since the time of publication, a Brave developer has confirmed that the browser will be releasing a hotfix for the issue.<\/p>\n<p>The issue is already fixed in nightly, the development build of the browser. The developer, @bcrypt on Twitter, wrote: Since its now public were uplifting the fix to a stable hotfix.<\/p>\n<p>Root cause is regression from cname-based adblocking which used a separate DNS query.<\/p>\n<p>The Daily Swig has reached out to Brave for comment, and will update this article accordingly.<\/p>\n<p>This article has been updated to include the information that a hotfix is being issued. An earlier version stated that the issue has been present since 2019, this has been corrected to 2020.<\/p>\n<p>YOU MAY ALSO LIKE BIND implements DNS-over-HTTPS to offer enhanced privacy<\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Link:<br \/>\n<a target=\"_blank\" href=\"https:\/\/portswigger.net\/daily-swig\/brave-browsers-tor-feature-found-to-leak-onion-queries-to-isps\" title=\"Brave browsers Tor feature found to leak .onion queries to ISPs - The Daily Swig\" rel=\"noopener\">Brave browsers Tor feature found to leak .onion queries to ISPs - The Daily Swig<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Jessica Haworth19 February 2021 at 14:27 UTC Updated: 19 February 2021 at 21:33 UTC Developers are issuing hotfix UPDATED Brave, the privacy-focused web browser, is exposing users activity on Tors hidden servers aka the dark web to their internet service providers, it has been confirmed. Brave is shipped with a built-in feature that integrates the Tor anonymity network into the browser, providing both security and privacy features that can help obscure a users activity on the web. Tor is also used to access .onion websites, which are hosted on the dark net <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/brave-browsers-tor-feature-found-to-leak-onion-queries-to-isps-the-daily-swig\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94875],"tags":[],"class_list":["post-1000815","post","type-post","status-publish","format-standard","hentry","category-tor-browser"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1000815"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=1000815"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1000815\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=1000815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=1000815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=1000815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}