We found a stable Firefox identifier linking all your private Tor identities
1–10 of 306 posts
Re: We found a stable Firefox identifier linking all your private Tor identities
#2Re: We found a stable Firefox identifier linking all your private Tor identities
#3I was expecting an ad for their product somewhere towards the end, but it wasn't there!
I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting?
Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors burning their zero days through responsible disclosure!
Re: We found a stable Firefox identifier linking all your private Tor identities
#4Re: We found a stable Firefox identifier linking all your private Tor identities
#5Re: We found a stable Firefox identifier linking all your private Tor identities
#6Does Tor Browser still allow JavaScript by default? Because if you block execution of JavaScript, you won't be affected from what I understand.
Tor Browser also doesn't spoof navigator.platform at all for some reason, so sites can still see when you use Linux, even if the User-Agent is spoofing Windows.
Re: We found a stable Firefox identifier linking all your private Tor identities
#7It seems Qubes OS and Qubes-Whonix are not affected.
Re: We found a stable Firefox identifier linking all your private Tor identities
#8Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…
Re: We found a stable Firefox identifier linking all your private Tor identities
#9I would imagine most users of Tor are using Tor Browser. I am reading there was a responsible disclosure to Mozilla but is it me or did that section leave out when the Tor Project planned to respond or release a fixed Tor Browser? Do they like keep very close or is there a large lag?