Does Tor Browser still allow JavaScript by default? Because if you block execution of JavaScript, you won't be affected from what I understand.
Disabling JavaScript actually greatly increases your fingerprint as not many users turn it off, so that instantly puts you in a much smaller bucket that you need to be unique in. Yes, not having JS means it limits your options for gathering other details, but it also requires much less effort to be unique now without JS. Tor Browser also doesn't spoof navigator.platform at all for some reason, so sites can still see…
We found a stable Firefox identifier linking all your private Tor identities
21–30 of 306 posts
Re: We found a stable Firefox identifier linking all your private Tor identities
#22Well that sucks. I guess in the long run we need a new engine and different approach. Someone should call the OpenBSD guys to come up with working ideas here.
Did you even read the article at all? Ah my children did bad in school, time to replace them with new children and a different spouse. This is what you're suggesting essentially. A browser is not just something you simply make out of thin air. There's decades of nuance to browser engines, and I'm only thinking of the HTML nuances, not the CSS or JS nuances.
Re: We found a stable Firefox identifier linking all your private Tor identities
#23Does Tor Browser still allow JavaScript by default? Because if you block execution of JavaScript, you won't be affected from what I understand.
Disabling JavaScript actually greatly increases your fingerprint as not many users turn it off, so that instantly puts you in a much smaller bucket that you need to be unique in. Yes, not having JS means it limits your options for gathering other details, but it also requires much less effort to be unique now without JS. Tor Browser also doesn't spoof navigator.platform at all for some reason, so sites can still see…
I've heard a handful of people say this but are there examples of what I would imagine would have to be server-side fingerprinting and the granularity? Since most fingerprinting I'm aware of is client-side, running via JS. While I expect server-side checks to be limited to things like which resources haven't be loaded by a particular user and anything else normally available via server logs either way, which could limit the pool but I wonder how effective in terms of tracking uniqueness across sites.
Re: We found a stable Firefox identifier linking all your private Tor identities
#24It seems Qubes OS and Qubes-Whonix are not affected.
Re: We found a stable Firefox identifier linking all your private Tor identities
#25The IndexedDB UUID is "shared across all origins", so why not use the contents of the database to identify browers, rather than the ordering?
Re: We found a stable Firefox identifier linking all your private Tor identities
#26Re: We found a stable Firefox identifier linking all your private Tor identities
#27> For security and product stakeholders, the key point is simple: even an API that appears harmless can become a cross-site tracking vector if it leaks stable process-level state.
This reads almost LLM-ish. The article on the whole does not appear so, but parts of it do.
Re: We found a stable Firefox identifier linking all your private Tor identities
#28It seems Qubes OS and Qubes-Whonix are not affected.
In the last ten years has qubes moved on to support more hardware? Every 4 years I would try to use it only to find it didn't support any of my hardware.
Re: We found a stable Firefox identifier linking all your private Tor identities
#29Well that sucks. I guess in the long run we need a new engine and different approach. Someone should call the OpenBSD guys to come up with working ideas here.
> Mozilla has quickly released the fix in Firefox 150 and ESR 140.10.0, and the patch is tracked in Mozilla Bug 2024220. Did you even read the article at all? Ah my children did bad in school, time to replace them with new children and a different spouse. This is what you're suggesting essentially. A browser is not just something you simply make out of thin air. There's decades of nuance to browser engines, and I'm o…
Re: We found a stable Firefox identifier linking all your private Tor identities
#30It seems Qubes OS and Qubes-Whonix are not affected.
In the last ten years has qubes moved on to support more hardware? Every 4 years I would try to use it only to find it didn't support any of my hardware.