Project

General

Profile

Current general security status and browsing the web through the Tor network

Added by Ellen Ripley 9 months ago

Hi,

I installed Replicant long ago and I was very happy about it. But time has passed and my device is not being updated, when I think of it I start to believe that maybe this phone is not as secure as I thought. Is there any estimate for an updated/upgrade?

One of my main concerns is surfing the web through Tor from the phone. Orbot works ok, and it gets updated through F-Droid. Orfox also gets updates but, as far as I know, it never worked on Replicant, did it? Please let me know.

Orweb works quite bad, it has many problems, but at least it is the only allegedly secure tool to browse the web through the Tor network, or at least that is what I learned long ago. But, is it secure to use an app whose last update was on 2015?

I guess I should stop using Orweb.

Is there any plan to make Orfox work on Replicant?

Thank you very much!


Replies (4)

RE: Current general security status and browsing the web through the Tor network - Added by Wolfgang Wiedmeyer 9 months ago

This mail from the mailing list answers some of your questions:
http://lists.osuosl.org/pipermail/replicant/Week-of-Mon-20170213/001180.html

Orfox should work using the software renderer llvmpipe with Replicant 6.0, but it will be very slow. There is still some work needed to make llvmpipe fast enough.

You could also consider using the browser Lightning. It has some settings to increase security/privacy. Probably the best thing you can do in this situation is to disable Javascript in the settings. This should prevent most of the possible attacks.

RE: Current general security status and browsing the web through the Tor network - Added by Kurtis Hanna 8 months ago

Ellen Ripley wrote:

Hi,

I installed Replicant long ago and I was very happy about it. But time has passed and my device is not being updated, when I think of it I start to believe that maybe this phone is not as secure as I thought. Is there any estimate for an updated/upgrade?

You should upgrade to the current Replicant 6.0 right now. Replicant 4.2 is too far out of date to patch everything that needs to be patched.

One of my main concerns is surfing the web through Tor from the phone. Orbot works ok, and it gets updated through F-Droid. Orfox also gets updates but, as far as I know, it never worked on Replicant, did it? Please let me know.

Make sure to enable the Guardian Project repository in F-Droid. It is not enabled by default, but perhaps it should be. This will provide you with much more recent versions of Orbot. You will likely have to uninstall the Orbot from the official F-Droid repo in order to install Orbot from the Guardian Project repo.

Orweb works quite bad, it has many problems, but at least it is the only allegedly secure tool to browse the web through the Tor network, or at least that is what I learned long ago. But, is it secure to use an app whose last update was on 2015?

I guess I should stop using Orweb.

Yes, you should stop using Orweb. Use Lighting Browser, which has native support for Orbot, or use Orfox via the llvmpipe option.

Is there any plan to make Orfox work on Replicant?

This redmine user confirmed that Orfox is currently working in Replicant 6.0 https://redmine.replicant.us/issues/1780#note-2

Thank you very much!

RE: Current general security status and browsing the web through the Tor network - Added by Ellen Ripley 7 months ago

How do I install Replicant 6.0? I do not see it at Replicant.us.

Thank you for the Lighting Browswer suggestion.

Is there any estimate on when version 6.0 will be officially released?

Thank you

RE: Current general security status and browsing the web through the Tor network - Added by Jeremy Rand 7 months ago

Hi Ellen,

Ellen Ripley wrote:

How do I install Replicant 6.0? I do not see it at Replicant.us.

See these links:

https://redmine.replicant.us/boards/21/topics/12057

https://redmine.replicant.us/boards/21/topics/14009

Thank you for the Lighting Browswer suggestion.

Since Lightning Browser uses WebView, which hasn't been updated in Replicant since 2015, it has security problems. Orfox with llvmpipe should be significantly safer, although llvmpipe will make your system somewhat laggier.

    (1-4/4)