Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Tom Ritter

@tomrittervg@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

277 Followers
143 Following
12 Posts
Joined September 10, 2024
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 1mo ago

Alibaba got caught doing some invasive fingerprinting that actually interrupted a user's workflow. (Normally they're more stealthy than that.) https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html

I did a quick write-up about Firefox's efforts (and success) neutering this fingerprinting vector https://ritter.vg/blog-webaudio_alibaba.html

blog.laserphile.com

laserphile: AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting

34
0
31
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 4mo ago

Firefox started the week with SIX entries at pwn2own!! We shipped a dot release this week that made half of them withdraw. I got asked "Isn't that kind of cheating?" The answer is no - it is strictly better for contestants. Here's why.

If a contestant goes on stage and demos an exploit that we could have killed but didn't, then they go to the disclosure room. ZDI asks us if we know about the vulnerability. Duplicates don't count. So now the contestant walks away with nothing AND loses their chance.

If we kill the bug ahead of time, sometimes contestants have a backup bug. Sometimes they're just really extra and decide to find a bug and write an exploit the night before. (I forget if it was Dino or Charlie that did this...) Either way they have a shot at something. It would be underhanded to hold things back that we could have patched.

(By the way, of the three remaining entries, two withdrew today...)

23
0
9
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 5mo ago

New version of Firefox released.

It's got uh... (checks notes) 354 vuln fixes. So pretty impressed by the platform team for pulling that off in a 4-week cycle.

Actually, a 4 week cycle would include the 41 vulns we fixed in the dot release, so that would be 395 vulns.... Exciting times.

https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-25/

Security Vulnerabilities fixed in Firefox 150
Mozilla

Security Vulnerabilities fixed in Firefox 150

27
13
25
2
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 4mo ago

There was a blogpost that made the rounds with the comment "As an aside, if you're wondering, Mozilla Firefox screwed up their WebGL fingerprinting protection" and implying the Blink has more protections - that is decidedly not the case, and I have graphs.

https://ritter.vg/blog-webgl_renderer.html

ritter.vg
15
1
13
1
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 7mo ago

I've been seeing a lot of comments online about how browser telemetry is just a way to spy on users and we never actually use it, and it provides no value.

We can debate whether you think someone (Firefox or otherwise) overcollects telemetry, or doesn't collect it in a privacy-preserving enough way. And you should be able to turn it all off, for any reason.

But it's been instrumental for me, personally, to ship multiple security improvements to Firefox - and I'm just one of hundreds of developers. I wrote up some more here: https://ritter.vg/blog-telemetry.html

ritter.vg
35
22
37
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 5mo ago

OpenSSL's "0 means fail and 1 means success and oh yeah -1 also means fail" APIs have been causing bugs for decades.

https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/

CVE-2026-0073 Android adbd TLS client-authentication bypass
Barghest

CVE-2026-0073 Android adbd TLS client-authentication bypass

BARGHEST analysis of CVE-2026-0073, an Android adbd ADB-over-TCP authentication bypass enabling no-interaction RCE through cross-algorithm TLS certificate comparison.

7
0
2
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 4mo ago

Tor Project is hiring an Android Engineer: https://www.torproject.org/about/jobs/

The Tor Project | Privacy & Freedom Online
torproject.org

The Tor Project | Privacy & Freedom Online

Defend yourself against tracking and surveillance. Circumvent censorship.

4
1
11
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 17mo ago

As a reminder to my academic friends. If you are doing research that involves modifying a compiler - perhaps to add a security mitigation or to test an optimization or some other interesting behavior - and you want to run a real world benchmark or test suite: we can help you run it on Firefox.

We can get you set up with our CI so it's easy and efficient to iterate on your patches and run it through the whole gamut.

If you want a compelling story in your paper, showing results on what is probably the second most complicated piece of software in use ought to do it.

https://wiki.mozilla.org/Building_Firefox/SURF

wiki.mozilla.org

Client Challenge

35
1
30
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 8mo ago

Outrage and attention are limited resources - no matter how much you think you can generate them infinitely as the world spirals around us, everyone gets worn down. So I don't think hyping and handwringing over Facebook's actions seven or more years ago is terribly productive.

But if you want examples of recent things to be outraged over, how about the localhost Tracking to bypass VPNs and track browsing, or the September 2025 Senate testimony that Meta's legal team doctored internal research about kids as young as 10 bring exposed to groomers. Or Northeastern showing that fact-checking's replacement is useless.

3
0
2
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 4mo ago

When I was a younger man, I had my presentations done at least a week in advance, rehearsed. I looked upon those doing them last minute with scorn. (Doubly so for those proud of themselves.) Well here I sit, wearing my shame, completed far too late, practiced by the thinnest of margins. Perhaps they deserved my sympathy back then, for this was certainly not my intention, yet it is how I find myself.

ANYWAY if you're in NYC for the Reddit thing tonight, see you there. I brought stickers.

1
0
0
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 7mo ago

@khm I'll accede that bit; I removed it.

hj.9fs.net
2
0
0
0
Open post
Tom Ritter @tomrittervg@infosec.exchange
· 8mo ago
Replying to
@natashenka There always seems to be so much pushback on removing functionality. While turning it into a 1-click would help some (especially if the sender isn't in your contacts!), I'd be more curious to see if it could be very tightly sandboxed. (And if not... why not? Tight sandboxing of media libraries with limited kernel attack surface seems like a platform primitive that is broadly useful.) Or cross compiled to wasm - performance of an edge case scenario shouldn't be a concern.
1
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:09:31 UTC