DDG & TOR: non-js redirection

[Old Forum narfnarf] anonymous
Created: 6 years and 3 months ago

It seems that when I use http://3g2upl4pq6kufc4m.onion with JavaScript disabled, I get redirected to https://duckduckgo.com/html instead of http://3g2upl4pq6kufc4m.onion/html.

Loading http://3g2upl4pq6kufc4m.onion with JS enabled, then disabling it while still on the DDG start page and performing a search gives a broken result page with "Meanings"-Box and info-text with non-onion link:
This page requires JavaScript. Get the non-JS version <a href="https://duckduckgo.com/html/?q=test">here</a>

I suppose there should be used http://3g2upl4pq6kufc4m.onion/html in both cases?

It would also be nice to have the "Add to firefox" button on the DDG-TOR site install a DDG-TOR search plugin that uses the TOR service, not duckduckgo.com. I think I cannot post attachments here, but the code is rather short, so here is an example

  1. <SearchPlugin xmlns="http://www.mozilla.org/2006/browser/search/" xmlns:os="http://a9.com/-/spec/opensearch/1.1/">
    <os:ShortName>DuckDuckGo (TOR)</os:ShortName>
    <os:Description>Search DuckDuckGo (TOR Service)</os:Description>
    <os:Image width="16" height="16"></os:Image>
    <os:Url type="text/html" method="GET" template="http://3g2upl4pq6kufc4m.onion/?q={searchTerms}">
posted by [Old Forum narfnarf] • 6 years and 3 months ago Link
/html/ exists on the Tor Hidden Service at, http://3g2upl4pq6kufc4m.onion/html/

Due to recent events and news you shouldn't be using Javascript at all on Tor.

posted by msyano 4 years and 8 months ago Link
Can you clarify? Which recent events and news?

posted by [Old Forum guest] • 4 years and 8 months ago Link
Several popular .onion sites were compromised with malicious javascript, which was able to leak identifiable user info. http://www.twitlonger.com/show/n_1rlo0uu
posted by crazedpsyc 4 years and 8 months ago Link
Ok, I see what you are talking about.

Personally I am glad that the guy was caught, but I see the point that it shows vulnerabilities in browsers that can circumvent Tor. I wasn't aware that it had been done with JavaScript, but honestly I hadn't thought about it much.

Even without a malicious payload, JavaScript can probably be used to identify you by looking at your browser settings like the fonts and plugins you have installed. That's probably not enough to get your address, but it is easily enough to correlate different visits to a website, so you are not really anonymous. TorBrowser makes some efforts to correct this.

posted by [Old Forum guest] • 4 years and 8 months ago Link
posted by msyano 4 years and 8 months ago Link
