
The Secrets of The Tor Browser
Source: YouTube · John Hammond · published Mar 12, 2024 · 19:10
This video investigates the forensic artifacts left by the Tor Browser to determine if user browsing history is retained locally. It concludes that while specific .onion history is not cached, artifacts indicating installation and usage timestamps remain 18:13-18:37.
Key Takeaways:
• The Tor Browser, built on Firefox, accesses dark web marketplaces selling malware and stolen data, though researchers use tools like Flare to monitor these threats 0:00-0:18, 1:35-2:12.
• Unlike standard Firefox which logs history to places.sqlite, the Tor Browser generally does not record user activity in this file to preserve anonymity 8:14-9:41, 12:23-12:31.
• A state file exists within the Tor data directory that provides a timestamp of the browser's last execution 14:24-15:31.
• Windows Registry keys, such as those for the Tor Project, can reveal that the browser is installed on a system 16:36-17:25.
Ultimately, the Tor Browser effectively hides specific user history from local storage, but digital footprints proving its presence and last activity time can still be uncovered 18:13-18:37.
Sources:
- 0:00-0:18 Overview of Tor Browser and dark web access
- 1:35-2:12 Using Flare for dark web research
- 8:14-9:41 Firefox history storage in places.sqlite
- 12:23-12:31 Tor Browser lacks user history storage
- 14:24-15:31(https://www.youtube.com/wat
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
The tour browser is one of the most common ways that you or anyone else could access the dark web. It's a web browser that allows you to visit these onion addresses or websites hosted across tour hidden services. It routes your traffic through all these nodes and you have to know the exact URL or location as to where you want to go and how to get there. And it is the dark web after all. There's a lot of weird stuff available out and about for sale whether it's malware. Hey, information, database dumps, passwords, credentials that are leaked, put out into the public, and drugs, illicit, illegal stuff that shouldn't be out and about. I'm looking at one of those dark web marketplaces now, and hey, you can see all the sketchy stuff that they might offer. Now, let me say a lot of this may very …