New Release: Tor Browser 8.5a7
Tor Browser 8.5a7 is now available from the Tor Browser Project page and also from our distribution directory.
This release features important security updates to Firefox.
This new Tor Browser version ships the first alpha in Tor's 0.4.0 series, 0.4.0.1-alpha.
This release also features a lot of improvements regarding our branding. We ship our new Tor Browser logo for the first time in a release build on desktop platforms and are eager to learn about bugs and general feedback. Thanks for Antonela and Richard working on this!
Due to a last minute bug making our build non-reproducible, we had to revert the patch rebranding the Windows installer. We plan to have it fixed in the next alpha release.
Additionally, we fixed a number of crashes noticed in previous releases (WebGL crashed on some Windows machines, the print dialog on some Linux systems, and downloading files on some Android devices).
Note: Due to a bug in Tor 0.4.0.1-alpha, the Windows bundles on a new clean install will get stuck during the first start. Restarting the browser should solve the issue.
The full changelog since Tor Browser 8.5a6 is:
- All Platforms
- Update Firefox to 60.5.0esr
- Update Torbutton to 2.1.4
- Update HTTPS Everywhere to 2019.1.7
- Update NoScript to 10.2.1
- Bug 29082: Backport patches for bug 1469916
- Bug 28711: Backport patches for bug 1474659
- Bug 27828: "Check for Tor Browser update" doesn't seem to do anything
- Bug 29028: Auto-decline most canvas warning prompts again
- Bug 27597: Fix our debug builds
- Windows
- Update Tor to 0.4.0.1-alpha
- Bug 25702: Activity 1.1 Update Tor Browser icon to follow design guidelines
- Bug 28111: Use Tor Browser icon in identity box
- Bug 22654: Firefox icon is shown for Tor Browser on Windows 10 start menu
- Bug 27503: Compile with accessibility support
- Bug 28874: Bump mingw-w64 commit to fix WebGL crash
- Bug 12885: Windows Jump Lists fail for Tor Browser
- Bug 28618: Set MOZILLA_OFFICIAL for Windows build
- OS X
- Linux
- Android
- Build System
Comments
Please note that the comment area below has been archived.
I don't like the new icon :(
I don't like the new icon :(
+1
+1
I agree, I don't like it…
I agree, I don't like it either.
+1
+1
I don't like the new icon :(…
We can level the critique even further: I don't know of anyone who actually likes that new logo more than the previous one.
Tor WARN: Refusing to apply…
Tor WARN: Refusing to apply consensus diff because the base consensus doesn't match the digest as found in the consensus diff header.
Tor WARN: Expected: C543926A52B064BBDA1B7D69F8D729BAEAC5BA3CAE4A264BB9B448608FB96A6F; found: 1DCDD2B0E745BDDA51C4EEE0F3A1179D8099BF290600040B7545C43A3C762383
Tor WARN: Could not apply consensus diff received from server 'canpaste?:22'
Several occurrences from…
Several occurrences from different servers.
Could be https://trac…
Could be https://trac.torproject.org/projects/tor/ticket/28733 or related tickets, hard to say. If you can, please help diagnosing this and report your findings to the ticket, thanks!
Is it dangerous? What are…
Is it dangerous? What are the consequences of it? The messages seem to disappear over time, and tor continues to work without any visible changes.
On Windows this is probably…
On Windows this is probably https://trac.torproject.org/projects/tor/ticket/28614 because it wasn't seen before.
Thank you TP as always. …
Thank you TP as always. Remember everyone: there's more of 'us' than there is of 'them'. Use your TOR browser for everything so it never looks out of place if your ISP and/or others are watching and recording. The more normalised everyone's TOR use is, the better for all of us. More relays help, even if only for a short while. Get yourself used to setting it up so it becomes easier every time. xo
What does this browser…
What does this browser support?
HTMLVideoElement
H.264
WebM VP8
Media Source Extensions
MSE & H.264
x MSE & WebM VP9
media.benchmark.vp9.fps 139
media.benchmark.vp9.versioncheck 4
This update disabled VP9 on my i7 notebook!
I don't think we disabled…
I don't think we disabled VP9 in this release. Are you saying with 8.5a6 it is working fine but with 8.5a7 you suddenly don't have VP9 available anymore?
Exactly.
Exactly.
Hm, now it's working again…
Hm, now it's working again. That means something during update turns off VP9 until the test is rerun.
Which test are you (re…
Which test are you (re-)running?
Not me. It is automatic…
Not me. It is automatic bench:
media.benchmark.vp9.fps 139
media.benchmark.vp9.versioncheck 4
These prefs in config mean that it was run.
Going on five months or more…
Going on five months or more, when I click to search by DuckDuckGoOnion on first starting Tor Browser or a New Identity, I usually receive "400 Bad Request nginx". When I click a second time, it always goes through ok from that point forward until I reopen Tor Browser or make a New Identity. When the error shows up, it's always on the first try of the session. DuckDuckGo knows about it but hasn't said anything. Why is it only on the first attempt? Does it indicate eavesdropping? You might not want to display my comment, then.
We don't know yet why this…
We don't know yet why this is happening but have https://trac.torproject.org/projects/tor/ticket/29119 for further investigation. Please help!
Yes, there is absolutely…
Yes, there is absolutely nothing in logs. So, gk, give him/her a debug build ;)
I get that and I still get…
I get that and I still get it every time.All DW requests are nginx and 400.I've tried many times.WTF is Cloudflare?I used to be able to work around it but not anymore?
HTTPSE is spamming the…
HTTPSE is spamming the console when you hover over its icon:
Warning: no handler for message Object { tabId: 2, __meta: Object, _messageName: "broadcastSettings" } in context moz-extension://uuid/ui/options.html Messages.js:34:5
Error: No handler registered for message "broadcastSettings" in context moz-extension://uuid/ui/options.html Messages.js
Warning: no handler for message Object { policy: Object, xssUserChoices: undefined, unrestrictedTab: undefined, local: undefined, sync: undefined, reloadAffected: undefined, tabId: 2, __meta: Object, _messageName: "updateSettings" } in context moz-extension://uuid/ui/options.html Messages.js:34:5
Error: No handler registered for message "updateSettings" in context moz-extension://uuid/ui/options.html Messages.js
Promise rejected after context unloaded: sender.tab is undefined
Messages.js:68
Promise rejected after context unloaded: Message manager disconnected
Messages.js:68
Sounds like good things to…
Sounds like good things to check with the HTTPS-Everywhere developers. See: https://github.com/EFForg/https-everywhere for filing issues. Please link to it/them here in case you've filed one/some. Thanks!
Firefox is not so compatible…
Firefox is not so compatible with Remote Desktop as it states. Therefore, with the latest Windows 10 host and
WebGL 1 Driver Renderer Google Inc. -- ANGLE (Microsoft Basic Render Driver Direct3D11 vs_5_0 ps_5_0)
it has an issue that may affect fingerprinting:
06:04:33.674 Error: WebGL warning: Disallowing antialiased backbuffers due to blacklisting. 1 webgl.js:159:17
Hah, not only fingerprinting…
Hah, not only fingerprinting... https://demo.marpi.pl/biomes/ doesnt' work at all:
Error: WebGL warning: Disallowing antialiased backbuffers due to blacklisting. echarts-gl.min.js:1:173816
Error: WebGL warning: texImage2D: Invalid unpack format/type: 0x1908/0x1406 echarts-gl.min.js:1:44545
Error: WebGL warning: texImage2D: Invalid unpack format/type: 0x1902/0x1405 echarts-gl.min.js:1:44545
Error: WebGL warning: clear: Framebuffer not complete. (status: 0x8cd6) COLOR_ATTACHMENT0's image is not defined echarts-gl.min.js:1:395878
Error: WebGL warning: clear: Framebuffer must be complete. echarts-gl.min.js:1:395878
Error: WebGL warning: texImage2D: Alpha-premult and y-flip are deprecated for non-DOM-Element uploads. echarts-gl.min.js:1:44545
Error: WebGL warning: texImage2D: Invalid unpack format/type: 0x1908/0x1406 echarts-gl.min.js:1:44545
Error: WebGL warning: texImage2D: Invalid unpack format/type: 0x1902/0x1405 echarts-gl.min.js:1:44545
Error: WebGL warning: clear: Framebuffer not complete. (status: 0x8cd6) COLOR_ATTACHMENT0's image is not defined echarts-gl.min.js:1:111563
Error: WebGL warning: clear: Framebuffer must be complete. echarts-gl.min.js:1:111563
Error: WARNING: 0:1: 'GL_OES_standard_derivatives' : extension is not supported
WARNING: 0:2: 'GL_EXT_shader_texture_lod' : extension is not supported
ERROR: 0:31: 'GL_OES_standard_derivatives' : extension is not supported
1: #extension GL_OES_standard_derivatives : enable
2: #extension GL_EXT_shader_texture_lod : enable
3: precision highp float;
4: precision highp int;
5: precision highp sampler2D;
6: #define DIRECTIONAL_LIGHT_COUNT 1
7: #define AMBIENT_LIGHT_COUNT 1
8: #define AMBIENT_SH_LIGHT_COUNT 1
9: #define AMBIENT_CUBEMAP_LIGHT_COUNT 1
10: #define DIFFUSEMAP_ENABLED
11: #define ALPHA_TEST_THRESHOLD 0.5
12: #define SRGB_DECODE
13: varying vec2 v_Texcoord;
14: uniform sampler2D diffuseMap ;
15:
16: uniform vec3 color ;
17:
18: uniform vec3 emission ;
19:
20: uniform float alpha ;
21:
22:
23: uniform float lineWidth ;
24:
25: uniform vec3 lineColor ;
26:
27: varying vec3 v_Barycentric;
28:
29: float edgeFactor(float width)
30: {
31: vec3 d = fwidth(v_Barycentric);
32: v echarts-gl.min.js:1:179544
Error: WebGL warning: clear: Framebuffer not complete. (status: 0x8cd6) COLOR_ATTACHMENT0's image is not defined echarts-gl.min.js:1:375984
Error: WebGL warning: clear: Framebuffer must be complete. echarts-gl.min.js:1:375984
Error: WebGL warning: clear: Framebuffer not complete. (status: 0x8cd6) COLOR_ATTACHMENT0's image is not defined echarts-gl.min.js:1:395878
Error: WebGL warning: clear: Framebuffer must be complete. echarts-gl.min.js:1:395878
Error: WebGL warning: clear: Framebuffer not complete. (status: 0x8cd6) COLOR_ATTACHMENT0's image is not defined echarts-gl.min.js:1:111563
Error: WebGL warning: clear: Framebuffer must be complete. echarts-gl.min.js:1:111563
TypeError: Argument 1 of WebGLRenderingContext.getAttribLocation is not an object. echarts-gl.min.js:1:57060
Yes, WebGL is not running by…
Yes, WebGL is not running by default anymore, we put it behind a placeholder: https://trac.torproject.org/projects/tor/ticket/21805. But it seems some websites, like the one you visited block it outright, though. I've filed https://trac.torproject.org/projects/tor/ticket/29246 for further investigation.
Hah, that log is from…
Hah, that log is from enabled WebGL.
What are your steps to…
What are your steps to enable it and to produce that result?
Click the NoScript icon and…
Click the NoScript icon and select Custom for that site, and enable everything in it.
And where is my answer to…
And where is my answer to your question? That you can enable it in NoScript settings.
Thanks. I looked closer and…
Thanks. I looked closer and updated #29246 with my findings. In short, that error is expected right now as we have WebGL extensions disabled at the moment due to unsolved fingerprinting concerns. We have https://trac.torproject.org/projects/tor/ticket/15825, though, to fix that.
bn-BD is TOFU on Windows 10,…
bn-BD is TOFU on Windows 10, but is readable on Windows 7!
Thanks! I filed https://trac…
Thanks! I filed https://trac.torproject.org/projects/tor/ticket/29257.
Also bn, hi, kn, mr, pa, si…
Also bn, hi, kn, mr, pa, si-LK, ta.
How did you test that given…
How did you test that given that we don't ship bn-BD bundles yet?
:) Sekrit ;) (https://gitweb…
:) Sekrit ;) (https://gitweb.torproject.org/user/gk/torbutton.git/tree/src/chrome/loc…)
[01-31 08:28:51] Torbutton…
[01-31 08:28:51] Torbutton INFO: Component Load 0: New ExternalAppBlocker.
http channel Listener OnDataAvailable contract violation
pdf is broken? Attempting to…
pdf is broken?
Attempting to post a message to window with url "resource://pdf.js/web/viewer.html" and origin "resource://pdf.js^privateBrowsingId=1&firstPartyDomain=color.org" from a system principal scope with mismatched origin "[System Principal]".
Therefore, FPI is broken too…
Therefore, FPI is broken too:
[01-31 08:38:10] Torbutton INFO: New domain isolation for --unknown--: 01230d6736babaeb1a0c0131cad452e1
[01-31 08:38:10] Torbutton INFO: tor SOCKS: http://www.color.org/version4pdf.pdf via
--unknown--:01230d6736babaeb1a0c0131cad452e1
What are your steps to…
What are your steps to reproduce for getting that result?
Oh, that was with pdfjs…
Oh, that was with pdfjs.disableRange;true
07:12:06.361 TypeError:…
07:12:06.361 TypeError: event.originalTarget.getAttribute is not a function 1 tabbrowser.xml:1977:13
onxblmouseout chrome://browser/content/tabbrowser.xml:1977:13
Bug 29158: Install updated…
Bug 29158: Install updated apt packages (CVE-2019-3462)
Why is that listed if it's not fixed?
Because the patch got…
Because the patch got committed and made it into the release.
Bug 29081: Harden…
Security is not one of your strong points :(
That 'Liberia' exit node…
That 'Liberia' exit node becomes annoying with its 'Secure Connection Failed' jokes for e.g. this blog.
Often, directly after my Tor…
Often, directly after my Tor browser has done an auto-upgrade, every time I start it I get a 'please wait while Tor Browser installs the updates' message. The only way I can stop it happening is to download Tor manually and install it manually, then it's fine.
Might this be my computer? Or does it happen with other users?
That's normal as Tor Browser…
That's normal as Tor Browser is not applying the update in the background anymore and has it then ready if you restart. Now, it will apply the update after you restart, hence the dialog to inform you what is going on.
Bug 27503: Compile with…
https://trac.torproject.org/projects/tor/ticket/27503#comment:2
Yes, that is https://trac…
Yes, that is https://trac.torproject.org/projects/tor/ticket/26505. I am not sure yet we should make it hard for folks who need accessibility tools to make it hard(er) to use Tor Browser given that we operate under the assumption that your local machine needs to be trusted anyway for Tor Browser to work properly.
15:29:19.237 TypeError:…
15:29:19.237 TypeError: hostName is null 1 security.js:55:9
_getSecurityInfo chrome://browser/content/pageinfo/security.js:55:9
securityOnLoad chrome://browser/content/pageinfo/security.js:179:14
onmessage chrome://browser/content/pageinfo/pageInfo.js:372:5
That's https://trac…
That's https://trac.torproject.org/projects/tor/ticket/29327 now, thanks!
Reloading https://hg.mozilla…
Reloading https://hg.mozilla.org/releases/mozilla-esr60/rev/fe547fe73bba
[01-31 15:55:12] Torbutton INFO: tor SOCKS: https://hg.mozilla.org/static/3b362b7a9144/style-gitweb.css via
mozilla.org:d0148e6f3897997e603b597862d8ec9a
[01-31 15:55:12] Torbutton INFO: tor SOCKS: https://hg.mozilla.org/static/3b362b7a9144/mercurial.js via
mozilla.org:d0148e6f3897997e603b597862d8ec9a
[01-31 15:55:12] Torbutton INFO: tor catchall circuit has been dirty for over 10 minutes. Rotating.
[01-31 15:55:12] Torbutton INFO: New domain isolation for --unknown--: 0740d7fdd958dd54f49a14cf90c77785
[01-31 15:55:12] Torbutton INFO: tor SOCKS: https://hg.mozilla.org/static/3b362b7a9144/mercurial.js via
--unknown--:0740d7fdd958dd54f49a14cf90c77785[01-31 15:55:12] Torbutton INFO: tor SOCKS: https://hg.mozilla.org/static/3b362b7a9144/moz-logo-bw-rgb.svg via
mozilla.org:d0148e6f3897997e603b597862d8ec9a
[01-31 15:55:12] Torbutton INFO: tor SOCKS: https://hg.mozilla.org/static/3b362b7a9144/hgicon.png via
mozilla.org:d0148e6f3897997e603b597862d8ec9a
So, what's wrong with that cached js? Other cached items work properly. No OA saved for cached js?
I wonder whether that's the…
I wonder whether that's the same as https://trac.torproject.org/projects/tor/ticket/28719. Are there actually two GET requests issued for those JS resources?
I don't think so. Why two? I…
I don't think so. Why two? I see one in Network Inspector.
Because the log indicates…
Because the log indicates that the js file is requested once over the mozilla circuit and once over the catch-all circuit. Thus, if you only see indeed one request it seems to me this is actually the same bug.
Bug 28874: Bump mingw-w64…
is a 'Build System' change
Well, the WebGL crash fix is…
Well, the WebGL crash fix is not a build system change which is why the entry is where it is.
If it's not important to…
If it's not important to note the mingw bump, then no problem.
> Bug 26148: Update binutils…
> Bug 26148: Update binutils to 2.31.1
What is the reason to bump binutils now? I couldn't find any.
Bug 28618 is one. Another…
Bug 28618 is one. Another one is that it greatly simplifies our patch handling for it as some patches were upstreamed meanwhile. A third reason is that it was way behind the current stable release.
Unbelievable the number of…
Unbelievable the number of people that complain "opengl don't work" "pdf is broken"... If you want all those feature but just use google chrome idiots !
Thanks Tb team for you work, just finish to emerge it
Would really like to see…
Would really like to see uMatrix replace noScript. Smart HTTPS replace HTTPS Everywhere. A decent cookie manager. No big deal since we can reconfigure extensions ourselves.
Also, detailed about:config modifications should be part of an html-based page (part of the install). This way we can see the modifications. Included are recommended modifications that haven't been made for reasons of stability. Things like telemetry, clipboard, Service Workers, Push Notifications, Studies, Pocket, etc... Even Wifi Location Tracking (Google APIs) can all be added to your about:config changes/recommendations.
https://gitweb.torproject…
https://gitweb.torproject.org/tor-browser.git/tree/browser/app/profile/… is a good starting point to collect that info and should cover the majority of pref changes. But, yes, having one place handy where one can see those (and others) would be neat. Please help!
Im using orbot to control…
Im using orbot to control other apps that use tor. The new torbrowser for android breaks it. what is the solution?
How does Tor Browser for…
How does Tor Browser for Android break your Orbot you use to control other apps with? What is happening? (Depending on that I might be able to come up with a solution. :) )
torbrowser does not start…
torbrowser does not start because it has its own orbot I assume. so now there are 2 orbots on the same device and this is why I think torbrowser stops working.
to reproduce install orbot first (latest version) then torbrowser then try to start torbrowser it will not work.
as I mentioned in the first comment I need the separate orbot to use vpn mode for other apps.
what to do now?
What happens if you try to…
What happens if you try to start Tor Browser? What happens if you disable VPN mode in Orbot? Does Tor Browser then work for you?
Tor NOTICE: No circuits are…
Tor NOTICE: No circuits are opened. Relaxed timeout for circuit 118 (a Measuring circuit timeout 3-hop circuit in state doing handshakes with channel state open) to 60000ms. However, it appears the circuit has timed out anyway.
Tor NOTICE: Our directory…
Tor NOTICE: Our directory information is no longer up-to-date enough to build circuits: We're missing descriptors for 1/2 of our primary entry guards (total microdescriptors: 6563/6619).
Tor NOTICE: I learned some more directory information, but not enough to build a circuit: We're missing descriptors for 1/2 of our primary entry guards (total microdescriptors: 6563/6619).
For many days now a cannot…
For many days now a cannot update my tor install in ubuntu trusty i386, I also had to remove source from list because of update errors. I followed the instructions on tor site. Is there a problem for Ubuntu 14.04.5 i386 repository/ppa ?
Is that a Tor Browse…
Is that a Tor Browse question? I think you are referring to Tor? We stopped providing .deb files for Trusty IIRC as it is soon an unsupported Ubuntu and there were errors during test runs I think.
Tor android is as safe as…
Tor android is as safe as the pc?
And about the update android, it can not download images yet and the vpn is not activated.
Which Tor Browser version…
Which Tor Browser version are you on and what Android version? We had issues with downloading things on Android 7+ phones (the browser would crash), but that should be fixed now in 8.5a7. Do you have an example image/website where a download is not working for you?
Yes, we don't support VPN mode with Tor Browser, this is expected.
Whether the browser for Android is as safe as the one for the PC is hard to tell. We hope so but security among desktop platforms is even varying, so it is hard to compare. At any rate, if you need to have Tor Browser on your Android device Tor Browser as we have it right now should be your first choice.
About the images, this photo…
About the images, this photo of Twitter is not downloaded and in general from anywhere.
https://pbs.twimg.com/media/DyvmxooWsAItw0N.jpg
What happens in this case…
What happens in this case for you?
If you rename the browser…
If you rename the browser folder, you'll get a broken browser with
Could not read chrome manifest 'jar:file:///%CHANGED_PATH%/Browser/TorBrowser/Data/Browser/profile.default/extensions/tor-launcher@torproject.org.xpi!/chrome.manifest'.
Could not read chrome manifest 'jar:file:///%CHANGED_PATH%/Browser/TorBrowser/Data/Browser/profile.default/extensions/torbutton@torproject.org.xpi!/chrome.manifest'.
Could not read chrome manifest 'jar:file:///%CHANGED_PATH%/Browser/browser/extensions/%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D.xpi!/chrome.manifest'.
Yes, that's https://trac…
Yes, that's https://trac.torproject.org/projects/tor/ticket/27604.
But this one is on Windows.
But this one is on Windows.
I updated the ticket…
I updated the ticket description and added a note, thanks!
I love it. Great Work and…
I love it. Great Work and Great Service..
no updates again.https://www…
no updates again.
https://www.eff.org/files/https-everywhere-2019.1.31-eff.xpi
Yup. I already notified the…
Yup. I already notified the HTTPS-Everywhere folks last week. I hope this will be resolved soon.
Maybe startpage can be added…
Maybe startpage can be added as well as another search engine?
Melhorem mais a segurança! …
Melhorem mais a segurança! Abraços!