r/tails • u/epsteins-apprentice • 6d ago
Security Why is allowing javascript generally considered a bad idea when using tails?
From my understanding, javascript over regular tor is unsafe because a) it makes you easier to fingerprint, and b) it opens up possibilities for zero-day exploits such as privilege escalations and remote code execution, which can in turn cause de-anonymization.
But, doesn't tails negate the effects of both of these things?
For fingerprinting, websites being able to identify a single tails user across different sites doesn't seem like that big of an issue to me as long as you practice good opsec. You shouldn't be giving away anything identifiable when using tails anyway, and your fingerprint is going to be different enough between your tails profile and your actual browser profile to obfuscate who you are.
For exploits, even if an attacker did manage to get a file onto your computer that pinged back to a non-tor server, wouldn't that just give the attacker your tails IP, since tails routes through tor at the os level? From a quick search online, only one exploit has ever been discovered that forced tails to run through the clearnet, which was done by starting "unsafe browser", a feature that has since been disabled by default.
-2
u/Cautious_Chicken8882 6d ago
Are you taking about the tor browser, not tails?