Roger Dingledine commited on 2009-05-16 23:47:15
Zeige 1 geänderte Dateien mit 9 Einfügungen und 8 Löschungen.
| ... | ... |
@@ -75,7 +75,7 @@ href="http://forums.sun.com/thread.jspa?threadID=5162138&messageID=9618376"> |
| 75 | 75 |
IP address</a>, and <a |
| 76 | 76 |
href="http://epic.org/privacy/cookies/flash.html">storing their own |
| 77 | 77 |
cookies</a>. It is possible to use a LiveCD or VMWare-based solution such as |
| 78 |
-<a href="https://www.torproject.org/torvm/">TorVM</a> or |
|
| 78 |
+<a href="<page torvm/index>">Tor VM</a> or |
|
| 79 | 79 |
<a href="http://anonymityanywhere.com/incognito/">Incognito</a> that creates a |
| 80 | 80 |
secure, transparent proxy to protect you from proxy bypass, however issues |
| 81 | 81 |
with local IP address discovery and Flash cookies potentially remain. |
| ... | ... |
@@ -87,14 +87,14 @@ try to unmask you by pretending to be them), and are unconcerned about your |
| 87 | 87 |
local censors noticing you visit them, you can enable plugins by going into |
| 88 | 88 |
the Torbutton Preferences->Security Settings->Dynamic Content tab and |
| 89 | 89 |
unchecking "Disable plugins during Tor usage" box. If you do do this without |
| 90 |
-TorVM, Incognitio or appropriate firewall rules, we strongly suggest you at |
|
| 90 |
+Tor VM, Incognito or appropriate firewall rules, we strongly suggest you at |
|
| 91 | 91 |
least use <a |
| 92 | 92 |
href="https://addons.mozilla.org/en-US/firefox/addon/433">FlashBlock</a> or <a |
| 93 | 93 |
href="https://addons.mozilla.org/en-US/firefox/addon/722">NoScript</a> along |
| 94 | 94 |
with <a href="https://addons.mozilla.org/en-US/firefox/addon/6623">Better |
| 95 | 95 |
Privacy</a> to block unwanted plugins and their cookies. Neither of these are |
| 96 | 96 |
foolproof protection against proxy bypass and |
| 97 |
-<a href="http://decloak.net">unmasking</a>, but you will at least be better off. |
|
| 97 |
+<a href="http://decloak.net/">unmasking</a>, but you will at least be better off. |
|
| 98 | 98 |
|
| 99 | 99 |
</p> |
| 100 | 100 |
|
| ... | ... |
@@ -111,9 +111,9 @@ not only just wasting your time, you are also actually endangering yourself. |
| 111 | 111 |
<b>Simply do not use Tor</b> and you will have the same (and in some cases, |
| 112 | 112 |
better) security. For more information on the types of attacks you are exposed |
| 113 | 113 |
to with a "homegrown" solution, please see <a |
| 114 |
-href="https://www.torproject.org/torbutton/design/#adversary">The Torbutton |
|
| 114 |
+href="design/index.html#adversary">The Torbutton |
|
| 115 | 115 |
Adversary Model</a>, in particular the <a |
| 116 |
-href="https://www.torproject.org/torbutton/design/#attacks">Adversary |
|
| 116 |
+href="design/index.html#attacks">Adversary |
|
| 117 | 117 |
Capabilities - Attacks</a> subsection. If there are any specific Torbutton |
| 118 | 118 |
behaviors that you do not like, please file a bug on <a |
| 119 | 119 |
href="https://bugs.torproject.org/flyspray/index.php?tasks=all&project=5">the |
| ... | ... |
@@ -280,8 +280,9 @@ deletion, but unfortunately, this behavior does not integrate well with Torbutto |
| 280 | 280 |
<a href="http://fscked.org/category/tags/insecurecookies">insecure |
| 281 | 281 |
cookies</a>.<br> |
| 282 | 282 |
|
| 283 |
- It can be difficult to configure such that the majority sites will work |
|
| 284 |
- properly though. In particular, you want to make sure you do not remove the Javascript whitelist for |
|
| 283 |
+ It can be difficult to configure such that the most sites will work |
|
| 284 |
+ properly though. In particular, you want to make sure you do not remove |
|
| 285 |
+ the Javascript whitelist for |
|
| 285 | 286 |
addons.mozilla.org, as extensions are downloaded via http and verified by |
| 286 | 287 |
javascript from the https page. |
| 287 | 288 |
|
| ... | ... |
@@ -306,7 +307,7 @@ forgery attacks. |
| 306 | 307 |
|
| 307 | 308 |
<p> |
| 308 | 309 |
There are a few known security issues with Torbutton (all of which are due to |
| 309 |
-<a href="https://www.torproject.org/torbutton/design/#FirefoxBugs">unfixed |
|
| 310 |
+<a href="design/index.html#FirefoxBugs">unfixed |
|
| 310 | 311 |
Firefox security bugs</a>). The most important for anonymity is that it is |
| 311 | 312 |
possible to unmask the javascript hooks that wrap the Date object to conceal |
| 312 | 313 |
your timezone in Firefox 2, and the timezone masking code does not work at all |
| 313 | 314 |