Author Topic: Not every tor address in Brave private window with Tor is secure and private...  (Read 960 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
L.S.

For instance landing here with Brave browser in private window with tor:
IP found while testing using this service for automatic check inside Tor:
https://perfectoid.space/test.php (never getting any further than a yellow status, also after reloading ...
Where they blacklisted that proxy service was here: https://cleantalk.org/blacklists/89.236.112.100
Alxo consider info here: https://www.shodan.io/host/89.236.112.100
Consider this info: https://effi.org/en-yksityisyys/
also this address opens up to -https://walshlawneb.com/  a non-private connected attack-address won't open,
because TLS certificate does not match the host name.
https://www.shodan.io/host/208.91.197.27  (IP from Britisch Virgin Islands),
while abuse was being reported here: https://www.abuseipdb.com/check/208.91.197.27

And know that Google keeps an eye on ye, always, as -
Quote
This website is insecure.
83% of the trackers on this site could be protecting you from NSA snooping. Tell effi.org to fix it.

 All trackers
At least 6 third parties know you are on this webpage.

 -maxcdn.bootstrapcdn.com
 -Google
 -Google
 -effi.org
 -Google
-tor.effi.org -tor.effi.org
Legend

 Tracker could be tracking safely if this site was secure.

 Tracker does not support secure transmission. While I blocked this, and because of that receive this error:
File not found: -http://maxcdn.bootstrapcdn.com/bootstrap/3.2.0/js/bootstrap.min.js
low vulnerability score for Bootstrap, script - 3.2.0


Just wanted to make you guys aware of this, there is no security panacea on the Interwebz.

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

« Last Edit: June 03, 2020, 05:18:25 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!