Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Privacy Bug in Brave Browser Exposes Dark-Web Browsing History of Its Users
The Hacker News ^ | February 20, 2021 | Ravie Lakshmanan

Posted on 02/25/2021 5:41:01 AM PST by rarestia

Brave has fixed a privacy issue in its browser that sent queries for .onion domains to public internet DNS resolvers rather than routing them through Tor nodes, thus exposing users' visits to dark web websites.

The bug was addressed in a hotfix release (V1.20.108) made available yesterday.

Brave ships with a built-in feature called "Private Window with Tor" that integrates the Tor anonymity network into the browser, allowing users to access .onion websites, which are hosted on the darknet, without revealing the IP address information to internet service providers (ISPs), Wi-Fi network providers, and the websites themselves. The feature was added in June 2018.

This is achieved by relaying users' requests for an onion URL through a network of volunteer-run Tor nodes. At the same time, it's worth noting that the feature uses Tor just as a proxy and does not implement most of the privacy protections offered by Tor Browser.

But according to a report first disclosed on Ramble, the privacy-defeating bug in the Tor mode of the browser made it possible to leak all the .onion addresses visited by a user to public DNS resolvers.

"Your ISP or DNS provider will know that a request made to a specific Tor site was made by your IP," the post read.

DNS requests, by design, are unencrypted, meaning that any request to access .onion sites in Brave can be tracked, thereby defeating the very purpose of the privacy feature.

This issue stems from the browser's CNAME ad-blocking feature that blocks third-party tracking scripts that use CNAME DNS records to impersonate the first-party script when it is not and avoid detection by content blockers. In doing so, a website can cloak third-party scripts using sub-domains of the main domain, which are then redirected automatically to a tracking domain.

Brave, for its part, already had prior knowledge of the issue, for it was reported on the bug bounty platform HackerOne on January 13, following which the security flaw was resolved in a Nightly release 15 days ago.

It appears that the patch was originally scheduled to roll out in Brave Browser 1.21.x, but in the wake of public disclosure, the company said it's pushing it to the stable version of the browser released yesterday.

Brave browser users can head to Menu on the top right > About Brave to download and install the latest update.


TOPICS: Computers/Internet
KEYWORDS: brave; security
FYI for Brave browser users
1 posted on 02/25/2021 5:41:01 AM PST by rarestia
[ Post Reply | Private Reply | View Replies]

To: rarestia

Mine shows Version 1.20.110 as current version.


2 posted on 02/25/2021 5:45:46 AM PST by dynachrome ("I will not be reconstructed, and I do not give a damn.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Brave logo
Brave
An error occurred while checking for updates: Update check failed to start (error code 4: 0xA0430817 — system level).
Learn more
......................................


3 posted on 02/25/2021 5:46:56 AM PST by Red Badger (SLEAZIN' is the REASON for the TREASON .................................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Why would the CIA release a browser without that feature.


4 posted on 02/25/2021 5:48:15 AM PST by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Brave logo
Brave
Brave is up to date
Version 1.20.110 Chromium: 88.0.4324.192 (Official Build) (64-bit)
Get help with Brave


5 posted on 02/25/2021 5:48:34 AM PST by Red Badger (SLEAZIN' is the REASON for the TREASON .................................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

They should change the name to Hubris. :)


6 posted on 02/25/2021 5:51:02 AM PST by cuban leaf (We killed our economy and damaged our culture. In 2021 we will pine for the salad days of 2020.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Thanks for the heads-up; am patching my system now.


7 posted on 02/25/2021 5:56:01 AM PST by Montana_Sam (Truth lives.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

BFL


8 posted on 02/25/2021 6:00:48 AM PST by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FreedomPoster

There is no way anyone can trust anything anymore.


9 posted on 02/25/2021 6:07:35 AM PST by George from New England
[ Post Reply | Private Reply | To 8 | View Replies]

To: rarestia

Just serving the overlords of the deep state.


10 posted on 02/25/2021 6:10:01 AM PST by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: George from New England
There is no way anyone can trust anything anymore.

You can trust me. /snark

11 posted on 02/25/2021 6:19:24 AM PST by Perseverando (Antifa, BLM, RINO's, Islamonazis, Statists, Communists, DemoKKKrats: It's a Godlessness disorder!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: George from New England
There is no way anyone can trust anything anymore.

That would be a good tagline.

12 posted on 02/25/2021 6:27:03 AM PST by null and void (We, MSM, decide what news you can see, and what you can not see, don't you dare call us Not-Sees)
[ Post Reply | Private Reply | To 9 | View Replies]

To: rarestia

Even Brave admits that their implementation of The Onion Network is less secure than the Tor browser’s is.

But you’re also not getting the best out of Tor browser if you’re running it on Windows.


13 posted on 02/25/2021 11:25:08 AM PST by Paal Gulli
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paal Gulli

DNS over HTTPS + VPN + TOR, regardless of OS, is as private as you can get. If you want to use Linux, go for it, but it’s no more secure than Windows. Your OS is only as secure as your patch level, whether it’s Windows, Linux, or Apple.


14 posted on 02/25/2021 11:33:03 AM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: rarestia; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

Tech Ping


15 posted on 02/25/2021 11:34:39 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

For me. It might as well have been written in Greek.


16 posted on 02/25/2021 11:56:41 AM PST by Graybeard58 (The China virus doesn't scare me, Venezuelaism does.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Graybeard58

The takeaway should be that regardless of your platform/browser/application of choice, don’t blow off updates.


17 posted on 02/25/2021 11:58:02 AM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: rarestia

I never understood why the tor feature. If you want to use tor use the tor browser.


18 posted on 02/25/2021 2:15:53 PM PST by beef (Use a VPN, use Tor, and get a shortwave radio. Oh, and ACAB- All Commies Are Bastards)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

I’m on 1.21.44 going to 1.22.45


19 posted on 02/25/2021 2:19:22 PM PST by beef (Use a VPN, use Tor, and get a shortwave radio. Oh, and ACAB- All Commies Are Bastards)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson