Brave Browser is fixing a privacy issue that leaks the Tor onion URL addresses you visit to your locally configured DNS server, exposing the dark web websites you visit.
Brave is Chromium-based browser that has been modified with privacy in mind, including a built-in ad blocker, tight data controls, and a built-in Tor browser mode to browse the web anonymously.
Tor Browser aims to make all users look the same, making it difficult for you to be fingerprinted based on your browser and device information. MULTI-LAYERED ENCRYPTION Your traffic is relayed and encrypted three times as it passes over the Tor network. Brave has a built-in feature to enable Tor’s integration with the browser to obscure a user’s web activities and offer optimum privacy and security. Tor, conversely, is also used to access.Onion sites, most of which are hosted on the Dark Web. Mar 06, 2021 TOR uses virtual channels, also known as nodes, to bounce your path of Internet use in a randomized order. So, rather than using a direct connection, once you do something on the web, the path goes through those nodes in no particular order, thus protecting your privacy from others. Now, it sounds great, doesn’t it?
Websites located on Tor use onion URL addresses that users can only access through the Tor network. For example, DuckDuckGo's Tor address is https://3g2upl4pq6kufc4m.onion/ and the New York Time's address is https://www.nytimes3xbfgragh.onion/.
To access Tor onion URLs, Brave added a 'Private Window with Tor' mode that acts as a proxy to the Tor network. When you attempt to connect to an onion URL, your request is proxied through volunteer-run Tor nodes who make the request for you and send back the returned HTML.
Due to this proxy implementation, Brave's Tor mode does not directly provide the same level of privacy as using the Tor Browser.
Brave's leaks Tor DNS requests
When using Brave's Tor mode, it should forward all requests to the Tor proxies and not send any information to any non-Tor Internet devices to increase privacy.
However, a bug in Brave's 'Private window with Tor' mode is causing the onion URL for any Tor address you visit to also be sent as a standard DNS query to your machine's configured DNS server.

This bug was first reported in a Reddit post and later confirmed by James Kettle, the Director of Research at PortSwigger.
BleepingComputer has also verified the claims by using Wireshark to view DNS traffic while using Brave's Tor mode.
As you can see in the video below, when visiting the DuckDuckGo and NY Times' onion URLs in Brave's Tor browser mode, the browser also performed DNS queries to our locally configured DNS server, Google's public servers at IP address 8.8.8.8.
Brave is aware of this bug as it was reported on their GitHub project page eighteen days ago, and developers have already created a fix.
Free sound editing software for mac. This issue is caused by Brave's CNAME decloaking ad-blocking feature that blocks third-party tracking scripts that use CNAME DNS records to impersonate a first-party script.
To prevent Tor URLs from being sent to configured DNS servers, Brave has disabled the CNAME adblocking feature when in the Tor browsing mode.
'Per discussion on slack with @bridiver and @iefremov, we came to a conclusion that disabling CNAME adblock for Tor would be best option now. Can we download google chrome on mac. Considering in order to make DoH route through Tor, we need to remove LOAD_BYPASS_PROXY for dns transaction but it might introduce dns and proxy code looping when we need to resolve proxy name,' the Brave developers explained in the reported issue.

Private Browser Site
This fix was originally expected to roll out in the Brave Browser Beta 1.21.x but Brave Browser developer Yan Zhu tweeted that a hotfix will be uplifted to the next Stable version.
this was scheduled to land in 1.21.x (currently in beta) but given that it's now public we will uplift to a stable hotfix
— yan (@bcrypt) February 19, 2021Related Articles:
[German]Brave browser have had a bug in the privacy mode, so that the leaked all Tor-Onion URLs in Privat Windows with Tor mode to the DNS provider. However, the developers seem to have corrected this bug in the meantime.
Brave is a Chromium-based browser that has been modified with privacy in mind. This includes a built-in ad blocker, strict data controls and a built-in Tor browser mode for anonymous web browsing. Websites on the Tor network use special onion URL addresses of the type https://3g2upl4pq6kufc4m.onion/ (DuckDuckGo), which users can only access through the Tor network. To access Tor onion URLs, Brave has provided a “Private Window with Tor” mode that acts as a proxy for the Tor network. Brave writes about this:

When you are in a private window with Tor, Brave does not connect directly to a website as usual. Instead, you connect to a chain of three different computers on the volunteer-run Tor network, one after the other, and only then to the web page you are visiting. Between those three Tor computers, only one really knows where the connection is coming from, and only one really knows where it’s going. And those two don’t even talk to each other because there’s another computer in the middle!
So when trying to connect to an Onion URL, the request is routed through volunteer Tor nodes. These perform the request and send back the returned HTML. From the perspective of the visited web pages, the connection comes from the last Tor computer, which acts as an exit node. Web sites do not learn the real IP address, but they can see that the connection is obfuscated by Tor (Tor nodes are not secret). In addition, the connection over many Tor relays is slow. Brave promises:
Your ISP, your employer, or the owner of the WiFi network you’re connected to won’t see what sites you’re visiting either, because Brave doesn’t connect directly to the site. Instead, someone watching your network connection will only see that you are connecting to the Tor network. Some network owners try to block connections to the Tor network because they want to decide which sites you can visit. With Tor, you can bypass this blocking.
Now someone has discovered that the Brave browser is giving away private Tor-Onion addresses through DNS queries. The link to this post was then shared on reddit.com, as Bleeping Computer notes here. James Kettle, Director of Research at UK provider PortSwigger, confirmed this in this tweet.
Security researcher Will Dormann also confirmed this bug in another tweet and posted the recording of the DNS sent.

Brave Browser Torrents
Brave Browser With Tor
James Kettle says, that the Brave developers were probably already aware of the problem, but had not yet fixed it with an update. Bleeping Computer linked to this Github page describing the bug in their article. Disabling CNAME Adblock for Tor would prevent the browser from sending DoH or standard DNS requests that are not routed through Tor. A hotfix was already planned for 1.21.x and in beta testing. Was then converted to stable. Here’s the tweet where someone confirms it:
Brave Browser Download
Bleeping Computer has put together some more details in this article. The problem is probably fixed for now. Also Catalin Cimpanu has compiled some details at ZDNet. Ccleaner.
Advertising
