Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

121–130 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#121

Earlier quoted context omitted.

I'm not upset, I just don't think we should criticize someone for doing something good. Maybe they're a terrible org, maybe they deserve criticism most of the time, but not in this instance. It's not like you can't point out that they did a good deed, but that they're still in the shitty business of fingerprinting users. Also, if people only get the stick no matter what they do, then eventually some will embrace the…

The inverse is also true, letting them whitewash their image by pretending they care about your privacy and seek to protect you will be good for their public relations, but only if we let them. I refuse to be this gullible and run to their defense for no apparent reason.

They can pretend all they want. I know what their business is, my opinion on the practices haven't changed.

And yet, they did a good thing. I will criticize everything else, but not what they did right. It doesn't mean I'll go out of my way to praise them either... if it wasn't your comment, I wouldn't have said anything at all.

Re: We found a stable Firefox identifier linking all your private Tor identities

#122

Earlier quoted context omitted.

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

I fantasize having a browser that I can use only for viewing content. No applications. No mail. No need for cookies. I can use a "regular" browser for more enhanced stuff. But for simple content consumption, we can just have a "dumb" browser that can't do much. > A user agent that says the browser's version? Reasonable enough. No user agent. I'm guessing it will need it for JavaScript or HTML features, and dynamicall…

Just use Tor browser? You can turn the tor part off if you need the speed.

What you want exists, have at it

Re: We found a stable Firefox identifier linking all your private Tor identities

#123
post #5

Does Tor Browser still allow JavaScript by default? Because if you block execution of JavaScript, you won't be affected from what I understand.

Because TBB has javascript on by default, turning it off increases your signature. It would be better if TBB defaulted to js off, with a front panel button to turn it on. JS also dramatically improves security. TBB is stuck in a 90s mindset about privacy, as if Firefox exploits were not dime a dozen. Especially with AI making FF exploits more available, we can expect many tor sites to be actively attacking their visi…

> turning it off increases your signature.

Tor endpoints are pretty easy to identify, there are plenty of handy databases for that, using it to begin with increases your uniqueness. If noscript was set to strictly disallow javascript by default, that decreases the degree to which it increases your signature relative to the baseline of using tor.

Then we have to account for the simple fact that many, many fingerprinting techniques rely on javascript, so taking them out of the picture reduces the unique identity that can be gleaned.

Are we absolutely, positively sure that the tradeoff is worth it? Without a strict repeatable measurement, I think I'm highly skeptical about whether or not a default of "allow" is a net boon to hiding your identity. I remember the rationale about the switch mostly being directed towards "most of the web is broken otherwise and that's bad."

Re: We found a stable Firefox identifier linking all your private Tor identities

#124
post #118

Earlier quoted context omitted.

I'm not upset, I just don't think we should criticize someone for doing something good. Maybe they're a terrible org, maybe they deserve criticism most of the time, but not in this instance. It's not like you can't point out that they did a good deed, but that they're still in the shitty business of fingerprinting users. Also, if people only get the stick no matter what they do, then eventually some will embrace the…

This isn't a someone. It's a corporation, a legal fiction explicitly designed to dissolve responsibility.

And like a broken clock that is right twice a day, sometimes a corporation also does the right thing, even if for the wrong reasons.

Nothing wrong with pointing out hypocrisy and bullshit, but criticizing something they did right? That's not how I operate. You are, of course, free to do things differently.

Re: We found a stable Firefox identifier linking all your private Tor identities

#126

Earlier quoted context omitted.

Most users seem to not care about ad tech/tracking as much as technical users. Even further, most seem to want to enable more tracking to [protect the children or whatever the reason is] pretty regularly (at least in opinion polls about various legislation). ToR users are not at all like that + could be harmed in a very different way... so I think it's fair to frame them differently even if I'd personally say people…

> Most users seem to not care about ad tech/tracking I don't think this is true. Most people don't understand that they're being tracked. The ones that do generally don't understand to what extent. You tend to get one of two responses: surprise or apathy. When people say "what are you going to do?" They don't mean "I don't care" they mean "I feel powerless to do anything about it, so I'll convince myself to not care…

> If you don't buy my belief then reframe the question to make things more apparent. Instead asking people how they feel about Google or Meta tracking them, ask how they feel about the government or some random person.

This is exactly what I was saying - if you look at the polls, people actually tend to support things like the UK's Online Safety Act. Explaining it more does not usually result in a change of that. The difference with a PI is you're asking about them individually instead of everyone - of course they trust themselves, they just want everyone surveilled for that same feeling of confidence.

Re: We found a stable Firefox identifier linking all your private Tor identities

#127

Earlier quoted context omitted.

Painting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.

Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?

> Instead of trying convince-by-assertion

TBF the idea that any and all fingerprinting falls under the umbrella of exploiting a vulnerability was also presented as an assertion. At least personally I think it's a rather absurd notion.

Certainly you can exploit what I would consider a vulnerability to obtain information useful for fingerprinting. But you can also assemble readily available information and I don't think that doing so is an exploit though in most cases it probably qualifies as an unfortunate oversight on the part of the software developer.

Re: We found a stable Firefox identifier linking all your private Tor identities

#128
post #125

Earlier quoted context omitted.

All fingerprinting is a vulnerability, unless the client opts-in.

The opt in checkbox is labeled "Enable Javascript"

https://fingerprint.com/blog/disabling-javascript-wont-stop-...

https://github.com/jonasstrehle/supercookie

Re: We found a stable Firefox identifier linking all your private Tor identities

#129
post #80

Earlier quoted context omitted.

Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?

There's a pretty big difference between: 1) wanting functionality that isn't provided and working around that and 2) restoring such functionality in the face of countermeasures The absence of functionality isn't a clear signal of intent, while countermeasures against said functionality is. And then there is the distinction between the intent of the software publisher and the intent of the user. There is a big ethical…

Even if the intent is clear I don't think the act of reading an available field qualifies as exploiting a vulnerability. IMO you need to actually work around a technical measure intended to stop you for it to qualify as an exploit.

Re: We found a stable Firefox identifier linking all your private Tor identities

#130
post #10

From the sounds of this it sounds like it doesn't persist past browser restart? I think that would significantly reduce the usefulness to attackers.

This excerpt from the article describes the risk well. > In Firefox Private Browsing mode, the identifier can also persist after all private windows are closed, as long as the Firefox process remains running. In Tor Browser, the stable identifier persists even through the "New Identity" feature, which is designed to be a full reset that clears cookies and browser history and uses new Tor circuits.

I wonder why "New Identity" wasn't implemented as a fork-and-exec with a newly created profile?
Post reply on HN