Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

261–270 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#261
post #15
post #3

Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…

We don't use vulnerabilities in our products.

> We don't use vulnerabilities in our products.

With all due respect, and acknowledging that your work is technically excellent…

Isn't everything that you do an exploitation of vulnerabilities? https://news.ycombinator.com/from?site=fingerprint.com

Fingerprinting is all about extracting information about a site's visitors which those users didn't explicitly intend to reveal.

Re: We found a stable Firefox identifier linking all your private Tor identities

#262

I learned enough about security years ago that there's basically zero chance you're secure and almost 100% chance someone is watch everything you do online. Whether they care is entirely separate.

Be careful when telling other campers that you think it's pointless to try to outrun a grizzly bear.

They may outwardly appear to agree with your statement, but it may be for very different reasons than you think.

Edit: clarification

Re: We found a stable Firefox identifier linking all your private Tor identities

#263

Earlier quoted context omitted.

>We are aware that EFF has a project that used to be named after a pedophile on this subject You bring this up like it's a well known incident, but my googling can find no evidence of it? The only reason not say the name of the project would be if it's common knowledge, but it's not? ChatGPT research reckons you're making it up, and I'd be curious if you have evidence to the contrary?

It used to be called Panoptoclik (sp?), a reference to Foucault's theory of the panopticon. Focault's extracurriculars are well documented and not everything is an "incident" -- it's a thread on fingerprinting. People who study that are aware what is now called "cover your tracks", and people who do post grads tend to be well rounded enough to have read a bit of philosophy, or at least, they did in my day. So what ha…

[deleted]

Re: We found a stable Firefox identifier linking all your private Tor identities

#264

Earlier quoted context omitted.

>We are aware that EFF has a project that used to be named after a pedophile on this subject You bring this up like it's a well known incident, but my googling can find no evidence of it? The only reason not say the name of the project would be if it's common knowledge, but it's not? ChatGPT research reckons you're making it up, and I'd be curious if you have evidence to the contrary?

It used to be called Panoptoclik (sp?), a reference to Foucault's theory of the panopticon. Focault's extracurriculars are well documented and not everything is an "incident" -- it's a thread on fingerprinting. People who study that are aware what is now called "cover your tracks", and people who do post grads tend to be well rounded enough to have read a bit of philosophy, or at least, they did in my day. So what ha…

Are the allegations described here what you're referring to? From cursory reading it sounds like satanic panic bullshit with some good old "gay men are pedophiles" thrown in, and basically just character assasination using debunked or non-existent sources.

https://lundi.am/The-Black-Masses-of-Michel-Foucault-the-Bul...

Plus as others noted, even if true your original statement would still be a lie since a Panopticon is a concept not a person.

Re: We found a stable Firefox identifier linking all your private Tor identities

#265

Earlier quoted context omitted.

You are right, and I am saying exactly the same thing. You seem to misunderstand that Qubes saves you whenever you use it as designed by its security approach. To benefit from Qubes security, you have to use virtualization to compartmentalize your tasks. Only virtualization is a guarantee of security. Everything running in the same domain is assumed to be not isolated, and a compromise would affect everything in it.…

This is some kind of technological No True Scotsman you keep doing. Also, please stop grossly misreading the comments of others. You consistently do it to numerous people here.

This has nothing to do with "No True Scotman", because my definitions and assumptions are not flexible. They are defined by the Qubes developers and documented. You misunderstanding me does not equal me being wrong.

When I say "this tool protects you" and you reply "it doesn't protect you if you misuse it; you give dangerous advice", you are the one misleading everyone. (Same with the kill switches on Librem 5.) Other people asked me for details instead of making a personal attack, https://news.ycombinator.com/item?id=47868133

Perhaps you are right that I could add more details for newcomers, but I was not wrong or harmful, unless you think every advice must have a full documentation for tools attached to it.

Re: We found a stable Firefox identifier linking all your private Tor identities

#266

Earlier quoted context omitted.

> one would need to spawn new disposable VMs for each identity This is by design how everyone should always be using Qubes OS for any task, according to its documentation and approach to security. > relying on the Tor Browser's new identity creation within the same disposable VM would be little different from running Tor Browser on a traditional OS Yes, if you use a single VM on Qubes OS for everything, then all secu…

Again, this is some kind of technological No True Scotsman you keep doing. Yet again, please stop grossly misreading the comments of others. You consistently do it to numerous people here.

https://news.ycombinator.com/item?id=47878794

Re: We found a stable Firefox identifier linking all your private Tor identities

#267

Earlier quoted context omitted.

I never said that. I only assumed that a user followed the docs when using Qubes-Whonix.

A dangerous assumption for someone who styles himself as the introducer of Qubes OS to new audiences. The saying about assumptions is as true as ever, unfortunately for both of us.

People who use tools incorrectly bear responsibility for corresponding dangers themselves. They can always ask for an additional advice or more details. I don't understand why you are attacking me for that. See also my answer elsewhwere (and please stop repeating the same thing in every comment thread): https://news.ycombinator.com/item?id=47878794.

Re: We found a stable Firefox identifier linking all your private Tor identities

#268

Earlier quoted context omitted.

Some good counterpoints. But you're suggesting more people would be okay with 'PI following them' hypothetical than GP suggests—simply with the knowledge that others are subject to the same degree of surveillance? I'm not so sure that counterpoint in particular holds. I think to say the "number of people that are going to be okay with that will [still] plummet" is an understatement. I'd go so far as to say no one , a…

Let me focus it from a slightly different side: my believe - from observing the world around me - is that physical privacy violation is perceived differently from a software one because of the side-effects: you gaze out of your window and see the same car with some guy in it parked there, you see the same car following you when you are going to the mall etc. There is some similar side-effect with online tracking, whi…

I take your point about the 'abstract' nature of online privacy. But another angle might be suggesting to those that are ambivalent on the issue that the pervasive (and for all intents and purposes, permanent) recordkeeping nature of 'software surveillance' should be much scarier than some guy sitting outside. I mean, at the very least, even with some guy sitting outside, you'd still have privacy inside.

But again, I hear you. Most people unfortunately have come to view the issue as being just about targeted advertising (which some go so far as to espose as a good thing).

Re: We found a stable Firefox identifier linking all your private Tor identities

#269

Earlier quoted context omitted.

Most of the things you've listed here don't actually seem all that reasonable to me. User agents as a concept are rather poorly thought out across the board and not all that useful but persist because that's just how technical cruft is. Fonts should be provided by the website; if not provided the choice should take the form of a spec sent by the website including line height, sarifs or not, monospace or not, etc. The…

> fonts should be provided by the website Yeah, because I love it when every website I go to downloads 10 megs of fonts to my computer before it starts rendering the page. Fonts should be suggested by the website, and a bog-standard "every computer has this" font should be listed as the fallback. > Timezone and other obviously private metadata should never be shared without the user explicitly granting permission on…

> fonts

That's why I said that a spec mechanism should also be provided. The issue is that sites can perform measurements regarding the layout that change based on the font used. So the browser should only ever provide a few fallbacks, nothing more, and anything else needs to come from the site itself.

> screen size

I think maybe you're confusing the physical screen with the current size of the browser window?

> video formats

The issue at present is that a site can programatically test a long list of formats against your setup to see what happens. What I'm describing increases privacy because the site can no longer directly query for the entire list of supported formats and the user can optionally control the process. Obviously it's still possible to botch the implementation on the browser's end but the point is to make it possible to do the right thing.

Re: We found a stable Firefox identifier linking all your private Tor identities

#270
post #210

Earlier quoted context omitted.

Implement it then.

Ah yes, the age old reply when people exhausted all arguments.

The person I have responded wrote the "should have" construction without giving any proofs why is it so. Maybe in the world of pink ponies everyone should have a free bread on the breakfast, but some things might be unintuitive in the our one.
Post reply on HN