From the sounds of this it sounds like it doesn't persist past browser restart? I think that would significantly reduce the usefulness to attackers.
Many users leave their browsers open for months.
We found a stable Firefox identifier linking all your private Tor identities
71–80 of 306 posts
Re: We found a stable Firefox identifier linking all your private Tor identities
#72I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?
>Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff? Like Android phones perhaps? Unfortunate Apple gives very little granular control.
But most ROMs don't allow controls for WiFi, Cell data, Phone ID, Phone number, User ID, local storage, etc...
Re: We found a stable Firefox identifier linking all your private Tor identities
#73I'm confused. The IndexedDB UUID is "shared across all origins", so why not use the contents of the database to identify browers, rather than the ordering?
There's an instructive example on the page. Suppose a page creates the databases `a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p`, then queries their order. They might get, for example `g,c,p,a,l,f,n,d,j,b,o,h,e,m,i,k`, based on the global mapping of database names to UUIDs. The key vulnerability here is that, for the lifetime of that Firefox process, any website that makes that set of databases is going to see the exact same outpu…
So it persists between anonymous sessions. So you could connect User A that logged out and reset the identity to User B who believed was using a fresh anonymous session and logged in afterwards.
Re: We found a stable Firefox identifier linking all your private Tor identities
#74Earlier quoted context omitted.
Uhh okay, so they do exploit vulnerabilities, they just try to target victims who can be served ads? What a weird distinction.
Painting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.
On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?
Re: We found a stable Firefox identifier linking all your private Tor identities
#75I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?
The most popular browser is made by an ad company. They also provide the majority of funding for their biggest competitor. Why would you expect anything different?
Re: We found a stable Firefox identifier linking all your private Tor identities
#76Re: We found a stable Firefox identifier linking all your private Tor identities
#77Earlier quoted context omitted.
Would you prefer that they kept this for themselves instead of disclosing it? I get criticizing their business and what they do wrong, but doesn't seem right to criticizing them for doing the right thing.
It means they are suspect. I think its right to be wary of motives if they are involved in the very thing they aim to bring awareness too. Questions arise in my mind as to why they would do something like this in the first place. Its been my experience that the general public doesn't seem to follow patterns and instead focus on which switch is toggled at any given moment for a company's ethical practices. This is the…
I understand where you're coming from, by the way, but sometimes the worst person you know does the right thing and it's not fair to criticize them for doing it (you could say nothing, don't have to change your opinion about them, etc). We also don't want someone to go "if I'm bad no matter what I do, then might as well make some money with this" and sell the exploit.
Re: We found a stable Firefox identifier linking all your private Tor identities
#78Re: We found a stable Firefox identifier linking all your private Tor identities
#79Earlier quoted context omitted.
So it's the criminal that convinced themselves they are the good guys, I didn't expect that one. You are a malware company get a grip.
Would you prefer that they kept this for themselves instead of disclosing it? I get criticizing their business and what they do wrong, but doesn't seem right to criticizing them for doing the right thing.
Re: We found a stable Firefox identifier linking all your private Tor identities
#80Earlier quoted context omitted.
Painting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.
Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?
1) wanting functionality that isn't provided and working around that
and
2) restoring such functionality in the face of countermeasures
The absence of functionality isn't a clear signal of intent, while countermeasures against said functionality is.
And then there is the distinction between the intent of the software publisher and the intent of the user. There is a big ethical difference between "Mozilla doesn't want advertisers tracking their users" and "those users don't want to be tracked". If these guys want to draw the line at "if there is a signal from the user that they want privacy, we won't track them", I think that's reasonable.