We found a stable Firefox identifier linking all your private Tor identities
11–20 of 306 posts
Re: We found a stable Firefox identifier linking all your private Tor identities
#12From the sounds of this it sounds like it doesn't persist past browser restart? I think that would significantly reduce the usefulness to attackers.
Re: We found a stable Firefox identifier linking all your private Tor identities
#13It seems Qubes OS and Qubes-Whonix are not affected.
Re: We found a stable Firefox identifier linking all your private Tor identities
#14It seems Qubes OS and Qubes-Whonix are not affected.
How so? If you kept a disposable VM open and just created new identities in tor browser, how does Qubes mitigate the threat here?
Re: We found a stable Firefox identifier linking all your private Tor identities
#15Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…
Re: We found a stable Firefox identifier linking all your private Tor identities
#16Re: We found a stable Firefox identifier linking all your private Tor identities
#17Re: We found a stable Firefox identifier linking all your private Tor identities
#18Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…
We don't use vulnerabilities in our products.
Re: We found a stable Firefox identifier linking all your private Tor identities
#19Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…
We don't use vulnerabilities in our products.
No software wants to be fingerprinted. If it did, it would offer an API with a stable identifier. All fingerprinting is exploiting unintended behavior of the target software or hardware.
Re: We found a stable Firefox identifier linking all your private Tor identities
#20Earlier quoted context omitted.
We don't use vulnerabilities in our products.
I don't understand what you mean. What separates this from other fingerprinting techniques your company monetizes? No software wants to be fingerprinted. If it did, it would offer an API with a stable identifier. All fingerprinting is exploiting unintended behavior of the target software or hardware.