Brave Browser with Tor

Hello folks,

we recently found that - despite we block “Tor P2P Anonymizer” in ZIA ATP settings and enforced SSL Interception in ZCC (3.1.0.103 with ZTunnel 2) - a user using “Brave Browser Private Window with Tor” (which is an integrated feature of this Browser, see https://brave.com/) can access ALL possible sites (inlcuding adult, weapons, etc etc whatever).

Any ideas? Did we miss something?

Thanks and BR
Manuel

Update:

Issue was confirmed by Zscaler-Support as a known bug and will be fixed in one of the next releases.

It seems blocking Tor in general is not possible at the moment with ZCC only. For example also the “Tor Browser” of https://www.torproject.org easily circumvents any ZCC/Zscaler policies by using one of the available Tor bridges as ZCC obviously just does not see/fetch/pickup the traffic.

BR
Manuel

1 Like

Final update:

Zscaler support verified my observations/assumptions that the switch for blocking Tor

image

is without function for ZCC v3 with profile configured for packetfilter, tunnel mode and tunnel 2.0.

BR
Manuel

1 Like