Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

191–200 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#191
post #37

Earlier quoted context omitted.

Many users leave their browsers open for months.

Open enough tabs and you'd be lucky to keep firefox running for more than a couple weeks.

I have had hundreds of tabs open for many months in the past. The bottleneck is usually the OS crashing rather than firefox.

Re: We found a stable Firefox identifier linking all your private Tor identities

#192
post #15

Earlier quoted context omitted.

We don't use vulnerabilities in our products.

The real reason is that fingerprint.com's selling point is tracking over longer periods (months, their website claims), and this doesn't help them with that.

it allows you to track a browser forever because it is stable fingerprint point. This helps with long term tracking a great deal.

Re: We found a stable Firefox identifier linking all your private Tor identities

#193

Being fingerprinted across Tor is different from being deanonymized—it basically just "psuedonomizes" you. You now have an identifier. It is a significant threat, but it is not hard to "psuedonomize" someone based on stylometry and some of the people with the highest threat model—operating an illegal site, will be pseudonymous anyway. Don't get your opsec advice from HN. Check whonix, qubes, grapheneos, kicksecure fo…

This fingerprint persists over private and non-private Firefox sessions until you restart Firefox. State actors might be able to connect your Google-login in FF window 1 with your tor session in FF private window 2.

Usually you have TOR browser for TOR and a standard Firefox for the standard browsing so they already are two sessions.

Re: We found a stable Firefox identifier linking all your private Tor identities

#194

Earlier quoted context omitted.

Most users seem to not care about ad tech/tracking as much as technical users. Even further, most seem to want to enable more tracking to [protect the children or whatever the reason is] pretty regularly (at least in opinion polls about various legislation). ToR users are not at all like that + could be harmed in a very different way... so I think it's fair to frame them differently even if I'd personally say people…

> Most users seem to not care about ad tech/tracking I don't think this is true. Most people don't understand that they're being tracked. The ones that do generally don't understand to what extent. You tend to get one of two responses: surprise or apathy. When people say "what are you going to do?" They don't mean "I don't care" they mean "I feel powerless to do anything about it, so I'll convince myself to not care…

> If you don't buy my belief then reframe the question to make things more apparent. Instead asking people how they feel about Google or Meta tracking them, ask how they feel about the government or some random person. "Would you be okay if I hired a PI to follow you around all day? They'll record who you talk to, when, how long, where you go, what you do, what you say, when you sleep, and everything down to what you ate for breakfast."

Yes and no, because people still will think that when it's done at scale it's different from some stalker following YOU explicitly, and not just following everybody. Also, the mental model is "they just want to sell me something, but I can just ignore and don't buy if I'm not really interested". And especially going down this second rabbit-hole opens a whole world about consumerism that not many people are comfortable with. At the same time there are people that are totally against consumerism that should be more informed and care more about tracking and privacy; with those people it's probably easier to have that conversation.

Re: We found a stable Firefox identifier linking all your private Tor identities

#196

Earlier quoted context omitted.

> Instead of trying convince-by-assertion TBF the idea that any and all fingerprinting falls under the umbrella of exploiting a vulnerability was also presented as an assertion. At least personally I think it's a rather absurd notion. Certainly you can exploit what I would consider a vulnerability to obtain information useful for fingerprinting. But you can also assemble readily available information and I don't thin…

For the readers convenience I restated the argument also in my post, but if you look you can see it was also stated much earlier in the thread.

You haven’t made an actual argument. You’ve made a repeated assertion that you feel so religiously about that you simultaneously can’t justify it and get very abrasive when someone asks you to back it up.

Re: We found a stable Firefox identifier linking all your private Tor identities

#198

Earlier quoted context omitted.

The real reason is that fingerprint.com's selling point is tracking over longer periods (months, their website claims), and this doesn't help them with that.

it allows you to track a browser forever because it is stable fingerprint point. This helps with long term tracking a great deal.

If I understand correctly, it was only stable until you restarted Firefox / your computer.

Re: We found a stable Firefox identifier linking all your private Tor identities

#199

I learned enough about security years ago that there's basically zero chance you're secure and almost 100% chance someone is watch everything you do online. Whether they care is entirely separate.

Ah, yes, the "fuck it" approach to infosec.

Re: We found a stable Firefox identifier linking all your private Tor identities

#200
post #3

Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…

>> why would this company report this vulnerability to Mozilla if their product is fingeprinting?

Maybe because is not as serious as them and their title, made it to be? Did you read it fully?

The identifier described is not process lifetime stable, not machine stable, or profile stable, or installation stable. The article itself says it resets on a full browser restart...

So this is not a magic forever ID and not some hardware tied supercookie. Now what should we do with that title, and the authors of it?

Post reply on HN