Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

241–250 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#241
post #110

Earlier quoted context omitted.

Unfortunately you've now made an incredibly niche browser, and the lack of those metrics is a good fingerprint by itself. How browsers render SVGs can be used for fingerprinting (even the underlying OS affects this, and I assume you'll want to see those), combine with ISP from IP address, and unless theres hundreds users in every city you're now pretty easily trackable.

> Unfortunately you've now made an incredibly niche browser, and the lack of those metrics is a good fingerprint by itself. If 100 people are using that browser, how will they know which one is me? > How browsers render SVGs can be used for fingerprinting (even the underlying OS affects this, and I assume you'll want to see those) Can you provide details on this? And how will they know which OS I'm using (through SVG…

You're the only one out of 100 that visits HN, or who's use matches a particular timezone, or who has the use pattern that [anti-]correlates with your work pattern, or ...

Re: We found a stable Firefox identifier linking all your private Tor identities

#242

Earlier quoted context omitted.

> Most users seem to not care about ad tech/tracking I don't think this is true. Most people don't understand that they're being tracked. The ones that do generally don't understand to what extent. You tend to get one of two responses: surprise or apathy. When people say "what are you going to do?" They don't mean "I don't care" they mean "I feel powerless to do anything about it, so I'll convince myself to not care…

> If you don't buy my belief then reframe the question to make things more apparent. Instead asking people how they feel about Google or Meta tracking them, ask how they feel about the government or some random person. "Would you be okay if I hired a PI to follow you around all day? They'll record who you talk to, when, how long, where you go, what you do, what you say, when you sleep, and everything down to what you…

Some good counterpoints. But you're suggesting more people would be okay with 'PI following them' hypothetical than GP suggests—simply with the knowledge that others are subject to the same degree of surveillance?

I'm not so sure that counterpoint in particular holds. I think to say the "number of people that are going to be okay with that will [still] plummet" is an understatement. I'd go so far as to say no one, at least no rational person, would be okay with a "record [of] who you talk to, when, how long, where you go, what you do, what you say, when you sleep", etc., just because of the scale.

Re: We found a stable Firefox identifier linking all your private Tor identities

#243

Earlier quoted context omitted.

Most users seem to not care about ad tech/tracking as much as technical users. Even further, most seem to want to enable more tracking to [protect the children or whatever the reason is] pretty regularly (at least in opinion polls about various legislation). ToR users are not at all like that + could be harmed in a very different way... so I think it's fair to frame them differently even if I'd personally say people…

> Most users seem to not care about ad tech/tracking as much as technical users. Part of the problem is the misconception that the data being collected is only being used to determine which ads to show them. Companies love to frame it that way because ultimately people don't actually care that much about which ads they get shown. The more people get educated on the real world/offline uses of the data they're handing…

This is definitely a point that should be emphasized more in this discussion. Even still, where it ultimately falls flat (currently) is the lack of hard proof to show people that it's truly happening.

Also, the degree to which some are more comfortable with the personal privacy/'feeling of personal safety' tradeoff notwithstanding, the examples that do get media traction are predictably extremes that the average person doesn't feel applies to them.

Re: We found a stable Firefox identifier linking all your private Tor identities

#244

Earlier quoted context omitted.

For the readers convenience I restated the argument also in my post, but if you look you can see it was also stated much earlier in the thread.

You haven’t made an actual argument. You’ve made a repeated assertion that you feel so religiously about that you simultaneously can’t justify it and get very abrasive when someone asks you to back it up.

Oh wow, do you really only write negative comments on others discussion? I defer to you much greater experience on being abrasive

Re: We found a stable Firefox identifier linking all your private Tor identities

#245

Earlier quoted context omitted.

> On Qubes, you do not create a new identity in the same VM. This would go against the Qubes approach to security/privacy. Using separate VMs for independent tasks is the whole point of using Qubes. This is technically incorrect information and could get people in trouble if followed literally. On Qubes OS, if a user creates a new identity inside a Whonix workstation disposable VM via the browser's new identity funct…

You are right, and I am saying exactly the same thing. You seem to misunderstand that Qubes saves you whenever you use it as designed by its security approach. To benefit from Qubes security, you have to use virtualization to compartmentalize your tasks. Only virtualization is a guarantee of security. Everything running in the same domain is assumed to be not isolated, and a compromise would affect everything in it.…

This is some kind of technological No True Scotsman you keep doing.

Also, please stop grossly misreading the comments of others. You consistently do it to numerous people here.

Re: We found a stable Firefox identifier linking all your private Tor identities

#246

Earlier quoted context omitted.

Qubes OS is a great solution for this threat model. By my (admittedly cursory) understanding of this attack, one would have to chain the attack to escalate to dom0 to get around it. Having said that, fsflover exhibits a poor grasp of how this stuff works and all should be aware that even in Qubes OS, one would need to spawn new disposable VMs for each identity; relying on the Tor Browser's new identity creation withi…

> one would need to spawn new disposable VMs for each identity This is by design how everyone should always be using Qubes OS for any task, according to its documentation and approach to security. > relying on the Tor Browser's new identity creation within the same disposable VM would be little different from running Tor Browser on a traditional OS Yes, if you use a single VM on Qubes OS for everything, then all secu…

Again, this is some kind of technological No True Scotsman you keep doing.

Yet again, please stop grossly misreading the comments of others. You consistently do it to numerous people here.

Re: We found a stable Firefox identifier linking all your private Tor identities

#249

Earlier quoted context omitted.

As I understood not ANY website can see it. But the same website can see it regardless if you reset your identity in Tor Browser. So it persists between anonymous sessions. So you could connect User A that logged out and reset the identity to User B who believed was using a fresh anonymous session and logged in afterwards.

No, it does allow identification across different websites (the article says "both cross-origin and same-origin tracking"). Both websites just need to create some databases with the same names. Since the databases are origin-scoped, these aren't the same databases, so you can't just write some data into one and read it on another website. But it turns out that if two websites use the same names for all these database…

OK, that's even worse. Thanks.

Re: We found a stable Firefox identifier linking all your private Tor identities

#250

Earlier quoted context omitted.

Most stock android phones don't either. You usually get to control precise location, notifications, some background activity, SMS, Calls, Mic, Camera, SD Card, etc. But most ROMs don't allow controls for WiFi, Cell data, Phone ID, Phone number, User ID, local storage, etc...

all these permission you have to accept?

For those things you can't control it doesn't ask. You can see those under "other permissions" (or similar). But once you look there it's too late if you care about this data and forgot to turn on airplane mode.
Post reply on HN