Tor Browser 7.5.5 is released

by boklm | June 9, 2018

Tor Browser 7.5.5 is now available from the Tor Browser Project page and also from our distribution directory.

This release features important security updates to Firefox.

This release updates Firefox to 52.8.1esr. In addition, we had to remove the amazon-meek pluggable transport.

The full changelog since Tor Browser 7.5.4 is:

  • All platforms
    • Update Firefox to 52.8.1esr
    • Bug 26098: Remove amazon-meek

Comments

Please note that the comment area below has been archived.

June 09, 2018

Permalink

CVE-2018-6126: Heap buffer overflow rasterizing paths in SVG with Skia
Another one hole in google's backdoor? Surprise, surprise...

June 09, 2018

Permalink

> we had to remove the amazon-meek pluggable transport.

Tragic.

Amazon's biggest customer is CIA, as some of us tried to warn over the past two years, so TP should have foreseen the demise of domain-fronting. You were so warned.

Please, TP, don't make the same mistake again by trusting the companies (such as Google) which are salivating over the prospect of becoming a permanent member of the US Surveillance-Industrial complex.

TP must find sources of funding other than USG or their public-private partners (BBG) and "benign" sponsorships such as "Google Summer of Code" from companies like Google.

If TP cannot look to "benign" USG agencies (like RFA) or "benign" multinational corporate partners of USG (like Google)--- because Yasha Levine is correct when he argues that there is no such thing as a "benign" partner of a government which seeks global hegemony--- who does that leave? Ordinary people.

This is why it is so worrisome that:

o the new TP ED has said nothing about whether she intends to continue Shari's attempts to move TP funding to a user-funded model similar to EFF,

o the long overdue TP financials have *still* not been posted, with no explanation of the hangup or any firm deadlines being offered.

And what about the PKI cert issue for this very blog? What's up with that?

June 09, 2018

Permalink

How's about NOT auto-updating my software, making me think I've been the victim of an automated attack?!
Prompting prominently, is acceptable.
Then I can download the update, verify it, and install it CLEANLY.
This is security best-practice. You're breaking that like Microsoft does - with the assumption that FORCING everyone to do it means more people are going to be updated and the 'herd' is overall less vulnerable.
Other people's laziness for such an easy-to-achieve operation is NOT my problem to suffer abuse over.
Whilst BLIND acceptance of updates (from which IP? I had no way to verify - HOW do I verify? It is safer to assume hostile environment, and I am suffering a potential VPNFilter infection, so no way do I trust things blindly at the moment.
But hey, what do I know, I only administrate my own equipment - you _must_ know better... sure...(!)

The automatic updates should be safe even with a hostile network:
https://decvnxytmk.oedi.net/projects/torbrowser/design/#update-safety

Automatic updates are enabled by default because this is what most users want, especially those that do not know how to change preferences. For advanced users that want more control over how updates are installed it is still possible to disable automatic updates by setting app.updates.auto to false:
http://kb.mozillazine.org/App.update.auto

Yes, Knowing, like Microsoft does. They do go after you and FORCE their updates which, for my computer, leaves it a little worse off almost every time. I now try to prolong the agony of their mostly unnecessary "updates". They usually sneak them in anyway and tell very little what they did. Tor is much more transparent and trustworthy. Thank you Tor, this time worked like a charm.

The op is correct. Automated updates from an unverifiable source is getting into Doze territory (aka proprietary non GNU-Linux hell). If people are incapable of updating a browser, an argument may be made that they are not intelligent enough to use TOR and should consider using Doze and Internet Explorer in perpetuity. You deserve what you teach yourself to deserve.

June 09, 2018

Permalink

danke für Ihre arbeit. ich stamme aus deutschland und habe den 2.weltkrieg durchlebt. werden Sie auch vom siegeswillen getragen!

June 09, 2018

Permalink

Hi

Just downloaded the latest version 7.5.5 and TOR browser just said goodbye.!!! :)
It does not start. Have tried many different ways it just would not start. Simple as that.
Even started the Vidalia to see if that will be able to connect to TOR servers, it did but the TOR 7.5.5 would not.

Please help

June 15, 2018

In reply to boklm

Permalink

I get this problem too in Win 7. Previous version tor browser still works ok. Please help.

June 25, 2018

In reply to boklm

Permalink

I have the same problem. Tor does not start. Nothing happens. It worked before. No error message. I am using Endless-OS (Linux). There was also an OS update. Also tried newer beta version without success.

June 09, 2018

Permalink

I know it's not related but is a new design for this blog coming?

I don't know what happened between this version and the old one (with green background) but this one is really disappointing.

- page title is "Tor Blog |" and should be without the "|" (yes I'm finicky)
- plain white background everywhere (except footer)
- big pixelated pictures for each articles
- excerpt feels like the legend of the above picture, also the interline space is odd (too big)
- "add a comment" box is nearer the below article than the one it's supposed to be with
- font sizes in general...

The blog feels like a default amateurish wordpress theme with the brand color of Tor for the texts.

I remember reading good articles on this blog in the past but this new design makes it painful to read or scroll anything.

Please rollback to the old design where you could see each element in a concise way.

Sorry for the rant, this is because I really care about Tor and hate seeing things going obviously wrong.

This Tor Browser version was an emergency release to fix an important issue in Firefox. As we did not have a lot of time to prepare this update and to avoid any risk we did not include other changes.

June 09, 2018

Permalink

Just remember that Tor is updated only after the NSA and FBI have conducted their investigations. Remember when Dingledine let CMU run its attack? Tor is consumer grade security.

This Tor Browser version was an emergency release to fix an important issue in Firefox. As we did not have a lot of time to prepare this update and to avoid any risk we did not include other changes.

June 09, 2018

Permalink

Hello, I have an issue. Whenever I try to watch any video, I get the following error message: "no video with supported format and mime type found". I've tried everything I've found online but haven't found a solution yet. Could anyone please help?

You mean this blog? We're privacy advocates and human rights advocates, not (for the most part) hackers.

But take a look at the PKI certificate for vbdvexcmqi.oedi.net. Weird, ain't it? Not a certificate controlled by Tor Project, and it is shared with numerous other domains including a company called forensicon.com. Makes you think, huh? Especially since TP is refusing to answer questions about it.

The PKI cert for decvnxytmk.oedi.net looks fine, BTW.

June 10, 2018

Permalink

palemoon has this function:

Tools>Preference>Content
Load images: Automatically,Never,Originating server only

Hop TOR has the function too. Thanks

June 11, 2018

In reply to boklm

Permalink

If you find that "Tor is too slow", the most effective ways of fixing that in Tor Browser are to use about:config to change that setting to value "2", and also to change javascript:enabled to FALSE. EFF's panopticlick appears to suggest that most Tor Browser users are making these changes.

arma never did explain why Rachel isn't working for TB instead of DARPA, regarding increasing entropy of posts like this one to make stylometry more difficult. That's too bad for us..

June 12, 2018

In reply to gk

Permalink

OK, well gk knows much more than I, so everyone should probably follow his advice, not mine.

I'd just ask that TP make sure someone (gk or nm mebbe) is looking into how the demise of net neutrality might affect ordinary Tor users. I think best judgment on issues involving how Tor interacts with the wider internet (e.g. CDNs, anti-DDOS screeners, new EU laws, new US laws, continued internecine warfare among media sites and with the US White House, etc.) is likely to change in coming months.

June 10, 2018

Permalink

hi.
i am one of the admirers of tor browser.
please indicate how to deal with a very disturbing reCHAPTCHA.
I want my tor browser can automatically execute reCHAPTCHA.
Please inform us how to solve it

Herrysequis@gmail.com

best regards,

Herry :)

June 12, 2018

In reply to gk

Permalink

The website encountered an unexpected error. Please try again later.Drupal\Component\Plugin\Exception\PluginNotFoundException: The "entity_form_display" entity type does not exist. in Drupal\Core\Entity\EntityTypeManager->getDefinition() (line 133 of core/lib/Drupal/Core/Entity/EntityTypeManager.php).

June 10, 2018

Permalink

am getting this message when trying to change to new identity

Torbutton: Unexpected error on new identity: [Exception... "Component returned failure code: 0x80520010 (NS_ERROR_FILE_NO_DEVICE_SPACE) [nsIPrefService.savePrefFile]" nsresult: "0x80520010 (NS_ERROR_FILE_NO_DEVICE_SPACE)" location: "JS frame :: chrome://torbutton/content/torbutton.js :: torbutton_do_new_identity :: line 1215" data: no]

and then the whole page goes what and have to restart tor which seems to take forever to launch...

June 10, 2018

Permalink

Torbutton: Unexpected error on new identity: [Exception... "Component returned failure code: 0x80520010 (NS_ERROR_FILE_NO_DEVICE_SPACE) [nsIPrefService.savePrefFile]" nsresult: "0x80520010 (NS_ERROR_FILE_NO_DEVICE_SPACE)" location: "JS frame :: chrome://torbutton/content/torbutton.js :: torbutton_do_new_identity :: line 1215" data: no]

June 11, 2018

Permalink

Mac
Experiencing constant slow uploading failures, increased time from 15 minutes to hours and eventual upload stuck.
Attempting to install 7.5.4 dmg wont open. The following disk images could't be opened. TorBrowser-7.5.4-osx6 Operation timed out.
Attempted to open 7.5.5 dmg won't open. The following disk images could't be opened. TorBrowser-7.5.5-osx6 Operation timed out.
Second attempt complete failure opening dmg for both versions. Must re download to get your one attempt. which fails with above message.

June 12, 2018

Permalink

Mac.
Mac dmg's 7.5.5 & 7.5.4 won't open. I let them update. Wanted to roll back.
7.5.5 running very slow, unusual, hanging compared to 7.5.4.

June 12, 2018

Permalink

Higher and higer GFW, less and less Plugintransports. We need more kinds of Bridge. FTE has not been updated for 3 years. What's next we will lose? Oh,god.

June 13, 2018

Permalink

Mac dmg's now opening.
Mac 7.5.5 hanging, stall out, lack of performance, uploading failure & unbearable tasks take longer & fail.

June 13, 2018

Permalink

On a Mac OS I see 4 bridges, obfs4, obfs3, meek amazon(works in China) and meek-azure(works in china) how does the removal of the Amazon transport bug26098 affect these bridges? Is meek amazon(works in China) related?

June 14, 2018

Permalink

Tor seems to remember all of the URL history from previous sessions, when I try to manually enter a new URL. That surprises me since Tor does NOT remember browser history. Is there a way to configure this behavior?

June 26, 2018

In reply to gk

Permalink

I did NOT say the Tor Browser history was preserved. The history page (ctrl+h) is always empty. What is being preserved is the *URL type-ahead* history. If I go to enter the website in the URL entry area at the top, Tor is matching the leading substring of anything I type. Are you saying those matches are confined to just the entries that I have permanently bookmarked? So that is a bookmark matching feature?

June 14, 2018

Permalink

There's something wrong with FF 52.8.1.
I'm using non e10 add-ons and after updating https everywhere
Multiprocess Windows 0/1 (Disabled by add-ons) changes to 1/1 (Enabled by default).
New Identity makes the TBB window moving step by step across the screen.
Platform Windows, maybe somebody can confirm.

June 15, 2018

Permalink

Mac 7.5.5
Constant problems Uploading, even loading a page, takes hours to perform a task.
Hanging, stall out, lack of performance, uploading failure & unbearable tasks take longer & fail.
I have to roll back a version to get it to work, but it still takes hours as it also attempting to upload to 7.5.5 at the same time. I've never seen anything extremely wrong with Tor till this version.
When will this be verified?

June 17, 2018

Permalink

Mac
Problem loading page. The connection has timed out. Uploads have gone from a couple minutes to over an hour or
never finishing.

June 20, 2018

Permalink

Very important comment.
I wish to thank you very, very much for this modification to my browser. It makes me feel really good.

June 21, 2018

Permalink

I am living in a dump like India and very much fed up with Google and Microsoft. as they always give hand third party to surveil its client..Thank you TOR to let us roaming freely in this beautiful virtual world..