Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

251–260 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#251

Earlier quoted context omitted.

> If you don't buy my belief then reframe the question to make things more apparent. Instead asking people how they feel about Google or Meta tracking them, ask how they feel about the government or some random person. "Would you be okay if I hired a PI to follow you around all day? They'll record who you talk to, when, how long, where you go, what you do, what you say, when you sleep, and everything down to what you…

Some good counterpoints. But you're suggesting more people would be okay with 'PI following them' hypothetical than GP suggests—simply with the knowledge that others are subject to the same degree of surveillance? I'm not so sure that counterpoint in particular holds. I think to say the "number of people that are going to be okay with that will [still] plummet" is an understatement. I'd go so far as to say no one , a…

Let me focus it from a slightly different side: my believe - from observing the world around me - is that physical privacy violation is perceived differently from a software one because of the side-effects: you gaze out of your window and see the same car with some guy in it parked there, you see the same car following you when you are going to the mall etc. There is some similar side-effect with online tracking, which is the typical "ad in my Instagram feed for something I searched for last week in Google", and there are people that are "scared" by this. But since it's just about buying things, well hey I might actually tap on that Instagram ad!

I see some success by telling people "what if was our government doing the same thing to us, even by extorting private companies? what if that same government, or the next one, just hates you for whatever reason?"

Re: We found a stable Firefox identifier linking all your private Tor identities

#252

Earlier quoted context omitted.

Creating a new identity in the browser in a disposable VM does not start a new disposable VM.

I never said that. I only assumed that a user followed the docs when using Qubes-Whonix.

A dangerous assumption for someone who styles himself as the introducer of Qubes OS to new audiences.

The saying about assumptions is as true as ever, unfortunately for both of us.

Re: We found a stable Firefox identifier linking all your private Tor identities

#253
post #2

I would imagine most users of Tor are using Tor Browser. I am reading there was a responsible disclosure to Mozilla but is it me or did that section leave out when the Tor Project planned to respond or release a fixed Tor Browser? Do they like keep very close or is there a large lag?

Not sure about "most". I use tor without a tor browser, because I don't care about being identified. I only used it to go around geoblocking and visit onion sites.

Re: We found a stable Firefox identifier linking all your private Tor identities

#254
post #2

I would imagine most users of Tor are using Tor Browser. I am reading there was a responsible disclosure to Mozilla but is it me or did that section leave out when the Tor Project planned to respond or release a fixed Tor Browser? Do they like keep very close or is there a large lag?

Not sure about "most". I use tor without a tor browser, because I don't care about being identified. I only used it to go around geoblocking and visit onion sites.

Are you really not sure? I'm pretty darn sure a lot of "normal" people don't know how to configure their systems to use a SOCKS proxy to use Tor.

Re: We found a stable Firefox identifier linking all your private Tor identities

#255
post #165

Earlier quoted context omitted.

This is a bad idea though, because any newly discovered means to get even a single data point results in being able to ID every tor user. I'd be better to have every tor browser always generate a random fingerprint so that even if the unexpected happens people will never get anything but random results.

> to have every tor browser always generate a random fingerprint Browsers do not "generate" fingerprints. They expose data that can be used to fingerprint users. You cannot "randomize" this; even if you were to return random values for, say, user screen size, with various visual side effects, it would just be another signal to fingerprint: "Oh, your browser is returning random values? Must be a Tor browser user".

> it would just be another signal to fingerprint: "Oh, your browser is returning random values? Must be a Tor browser user".

That's perfectly fine! As long as they can't tell which tor user you are they can't track your browsing activity or associate it to any one tor user. That's the goal. Currently tor browser sticks out like a sore thumb by trying to appear identical no matter who uses it, which is fragile because any one data point unaccounted for unmasks everyone.

Re: We found a stable Firefox identifier linking all your private Tor identities

#256
post #9
post #2

I would imagine most users of Tor are using Tor Browser. I am reading there was a responsible disclosure to Mozilla but is it me or did that section leave out when the Tor Project planned to respond or release a fixed Tor Browser? Do they like keep very close or is there a large lag?

Tor Browser is always quick to rebase on the latest Firefox ESR. They released an update the next day: https://blog.torproject.org/new-release-tor-browser-15010/

This is great to hear. I wish the original article was more clear on that instead of a vague "they'll get to it" which has bad connotations.

Re: We found a stable Firefox identifier linking all your private Tor identities

#257

Earlier quoted context omitted.

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

Most of the things you've listed here don't actually seem all that reasonable to me. User agents as a concept are rather poorly thought out across the board and not all that useful but persist because that's just how technical cruft is. Fonts should be provided by the website; if not provided the choice should take the form of a spec sent by the website including line height, sarifs or not, monospace or not, etc. The…

> Fonts should be provided by the website

No way!

I don’t ever use any font provided by the website. I don’t even let websites choose which fonts get used. Instead I choose a set of fonts (monospaced and proportional) that are readable and everything uses those.

If you want to see what that looks like, go into the Firefox settings, find the Fonts section, click Advanced, and then uncheck “Allow pages to choose their own fonts, instead of your selections above”. Be sure to adjust the “Minimum font size” while you’re here so that nobody uses text sizes that you cannot read.

Re: We found a stable Firefox identifier linking all your private Tor identities

#258

Earlier quoted context omitted.

most people would expect something different from tor, surely.

The purpose of a system is what it does.

This phrase is practically https://en.wikipedia.org/wiki/Thought-terminating_clich%C3%A... now

Re: We found a stable Firefox identifier linking all your private Tor identities

#259

Earlier quoted context omitted.

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

Most of the things you've listed here don't actually seem all that reasonable to me. User agents as a concept are rather poorly thought out across the board and not all that useful but persist because that's just how technical cruft is. Fonts should be provided by the website; if not provided the choice should take the form of a spec sent by the website including line height, sarifs or not, monospace or not, etc. The…

> fonts should be provided by the website

Yeah, because I love it when every website I go to downloads 10 megs of fonts to my computer before it starts rendering the page. Fonts should be suggested by the website, and a bog-standard "every computer has this" font should be listed as the fallback.

> Timezone and other obviously private metadata should never be shared without the user explicitly granting permission on a case by case basis

100% agree.

> Size of the physical screen should never be exposed under any circumstances

I mostly agree, but with the understanding that this would cause issues with "modern" web pages having very difficult to format layouts. Responsive design requires a response, after all.

> Video formats should be provided by the website as a list of offerings and the browser should respond with a choice

You're still getting the same feedback with this, that the browser chose to use X format, so you're not increasing privacy with this, only difficulty.

> Querying the current time should be gated behind an explicit permission

100% agree. If there is no active local processing of information that the server relies on, in the format of a game or some other interactivity, then there is no reason why the server needs to know your local time.

Re: We found a stable Firefox identifier linking all your private Tor identities

#260
post #227

Earlier quoted context omitted.

Ridiculous comment. People should not have to choose between functionality and privacy.

You can't go out in public naked and just ask everyone to look away. If you want someone you don't trust to run unvetted general purpose code on your machine you have to accept that you are trading away some privacy. You can sandbox them (wear cloths) but that doesn't give you strict privacy.

It's not a binary situation. Lots of fingerprinting is based on e.g. audio or canvas rendering quirks. Browsers should be obfuscating that shit.
Post reply on HN