https://tails.boum.org/news/version_5.1/index.en.html
This release fixes the security vulnerability[1][2] in the JavaScript engine of Firefox and Tor Browser announced on May 24.
This release was delayed from May 31 to June 5 because of a delay in the release of Tor Browser 11.0.14.
This is a very important release - please do not use version 5.0 or previous versions.
[1] https://tails.boum.org/security/prototype_pollution/index.en.html
[2] https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/
This discussion has been archived.
No new comments can be posted.
Tails Linux 5.1 is Out! Fixes the Security Vulnerability in the JavaScript Engine
|
Log In/Create an Account
| Top
| 12 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
(1)
(Score: 4, Funny) by Frosty Piss on Monday June 06 2022, @08:35AM (8 children)
Wait! There are security vulnerabilities with Java Script? Unbelievable.
(Score: 2) by maxwell demon on Monday June 06 2022, @11:53AM (6 children)
There are people trying to stay anonymous who actually enable JavaScript? Given that the majority of browser fingerprinting depends on JavaScript, I would have thought that disabling that would be standard for anyone trying to stay anonymous.
The Tao of math: The numbers you can count are not the real numbers.
(Score: 3, Insightful) by canopic jug on Monday June 06 2022, @12:50PM (5 children)
It has gotten to the point that most web pages have gratuitous javascript and will not even render without it. Instead of looking up the right semantic HTML element or digging through the now obscenely voluminous CSS specification, they'll "just" pull in a whole javascript framework just for one effect. It's a way of thinking.
A case in point is the details / summary [geeksforgeeks.org] pair of HTML elements. Nearly 99% of the time I have encountered equivalent functionality, it abuses massive amounts of javascript instead of a pair of "tags". So hats off to the SN team for keeping that functionality available without ruining the site with javascript.
Money is not free speech. Elections should not be auctions.
(Score: 0) by Anonymous Coward on Monday June 06 2022, @01:30PM (3 children)
I guess they didn't want to cripple the experience for sites that *did* require JavaScript.
Various degrees of protection can be accomplished by extensions, no?
NoScript, uBlock Origin, Privacy Badger etc.
(Score: 3, Insightful) by Freeman on Monday June 06 2022, @04:34PM (2 children)
I fear the day that uBlock Origin isn't supported by Raymond Hall.
Obligatory XKCD: https://xkcd.com/2347/ [xkcd.com]
The fact that there is one good ad-blocker and that the likes of google have actively hindered the use of ad-blockers is chilling. Thankfully something like Pi-Hole still works, too.
Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
(Score: 1, Touché) by Anonymous Coward on Monday June 06 2022, @10:59PM (1 child)
I don't fear that in the least.
Now, if it stopped being supported by Raymond Hill, that would be another story.
(Score: 2) by Freeman on Thursday June 09 2022, @02:26PM
Brain went poof there for a moment, sorry. You are indeed correct as uBlock Origin is supported by Raymond Hill.
Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
(Score: 0) by Anonymous Coward on Monday June 06 2022, @04:45PM
But without JS, how can sites ensure that they only server up content to those they can track?
The number of pages I have gotten with no non-JS content is just sad.
(Score: 2) by Freeman on Monday June 06 2022, @04:30PM
More like: "Inconceivable!"
https://www.goodreads.com/work/quotes/992628-the-princess-bride [goodreads.com]
Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
(Score: -1, Spam) by smithburn on Monday June 06 2022, @10:52AM
Mj Mover is one of the companies that offering moving services at cheap prices with the help of Cheap Movers [mjmoves.com]
https://mjmoves.com/ [mjmoves.com]
(Score: 0) by Anonymous Coward on Monday June 06 2022, @11:58AM
Valueing privacy and running random javascript from arbitrary websites is mututally incompatible, even if you do it via tor.
(Score: 0) by Anonymous Coward on Monday June 06 2022, @04:15PM
Small comfort to the surviving family of the guy who was using Tails Linux 5.0