In a post on Twitter, a '''company specializing in purchasing zero-day exploits from researchers and selling them to government agencies''' revealed that several versions of the Tor Browser fail to prevent JavaScript from running even with NoScript on the most secure setting.>The security company, Zerodium, announced the vulnerability after a new version of the Tor Browser had been released. Tor Browser 8.x is unaffected by the vulnerability, according to their announcement.A company that earns profit on selling exploits for tor browser is telling you that tbb 7.X in UNSAFE and you need to migrate to SAFE tbb 8. does that sound legit? what is their motivation? how do you think?if TBB 7 is so insecure, why would they speak about it publicly instead of selling zero-days for it?the true reason is, because they have a lot of zero-days for TBB8, whereas TBB7 is mature and they won't be able to find much more holes.THEY ARE A PRIVATE COMPANY that is "specializing in purchasing zero-day exploits from researchers and selling them to government agencies". Your security is not in their interests, their interests is making profit by selling zero-days. If they shill for updating TBB to version 8, that means they will profit from it. How? By selling zero-days for TBB8. They have a lot of them.>Advisory: Tor Browser 7.x has a serious vuln/bugdoor leading to full bypass of Tor / NoScript ‘Safest’ security level (supposed to block all JS).The exploit is not in browser code but in NoScript. NoScript creators quickly released a fix. You can get it here: https://noscript.net/getit you need the 5.1.9 version for TBB7 and FF ESR <60.However, those fuckers from Zerodium, they tell you bullshit that you need to update your entire browser. Which is total bullshit. All you need is update NoScript.Zerodium shills for TBB8 because they have huge amount of exploits for it and they will get rich from it.'''Another problem with TBB8 is that it stops spoofing useragent. It lowers your privacy.'''https://forums.whonix.org/t/tor-browser-8-and-removal-of-user-agent-spoofing/5930https://trac.torproject.org/projects/tor/ticket/27495'''Tor Project makes changes that lower anonymity of Tor users. Tor Project is compromised by CIA and MOSSAD.'''Also, TBB8 and FF60 drops support for many important operating systems.==If you have TorBrowser 8 or Firefox 60+ you should quickly downgrade. This is SERIOUS situation.==However, this is not so easy, because Tor Project quickly removed all TorBrowser7.X from their site (https://dist.torproject.org/torbrowser/).You need to download Tor Browser 7.5.6 from 3rd party websites:https://archive.org/download/torbrowser-install-7.5.6_en-US_201811/torbrowser-install-7.5.6_en-US.exehttps://torify.me/en/download-tor-browser/download-tor-browser-for-windows.htmlafter you download you can verify fileSHA1 eb39a62bea0e23816d5376600ad60a1f5ec603b5SHA-256 475b2207314ddbf28ee79651b5d1154d59699e7b76a3b5081dce3caf97ab941eSHA384 8f0471f191cf6f4965b5975a2679acf60cd6d1e4b9aac71212ff9ba5532160edc843303ccaab190a53950218ad868d46SHA-512 6d8af481332ab552cf99a2f03373ed33262fbd8a74b6b082d3a05023c82a978ba0ff757a1d5c25414d419cf45dbd7b54678ea23c77cefff56a916cd48059d0c2CRC32 cb25f5f0MD5 886e550598a7328205c430936f4226f5Size 53 868 664After you install it, update NoScript, https://noscript.net/getit follow the instructions there and install NoScript 5.1.9.>Notice: you may need to open about:config and set your xpinstall.signatures.required preference to false in order to install NoScript 5.x, since Mozilla doesn't support signatures for legacy add-ons anymore. If you're using a non ESR Firefox, you may also need this hack. '''Your life is at risk. Follow my instructions to be safe. Spread this message to as many people as possible.'''tl;dr==Tor Browser 8.x and FF 60+ are totally COMPROMISED. Downgrade to Tor Browser 7 and FF ESR 52 as quickly as possible. Tor Project is compromised by CIA and MOSSAD.==">