Tor Anonymity: Things Not to Do
whonix.org
whonix.org
I do not use Tor myself but few years ago I've analyzed an anonymized data site and was amazed how easy it was, with a high degree of probability, to track someone just based on screen resolution + viewport size (i.e. size of your browser window). Almost every viewport size was unique (when correlated with screen resolution).
> Here's one they missed: do not resize your window!
Under the "Don't change settings if you don't know their consequences." section: For example removing a menu bar or using Full Screen
in Tor Browser is recommended against. The latter
is known to modify the screen size, which is bad
for the web fingerprint.
Also, the current version of the Tor Browser warns you when you resize the window.I don't know what their roadmap is, but I'm assuming, this will be eventually coming to the stable release for all platforms supported.
I believe it only warns you if you maximize the window, not if you resize it.
Similar to what the nosleep utility does with jiggling the mouse by an unnoticable +/- a few pixels.
Could make sense to do so on a session-by-session basis, though.
The specific values depend on the individual configuration of your browser - icon size, toolbars, themes ...
mine is: 1920 x 992
if I add the bookmark bar the sizeing turns: 1920 x 968
It's not identifying but individual.
Just curious I guess, it's a shame that there are people out there who've likely done everything right except changing the size of their window, and maybe they got v& or even hurt because of this.
@media (min-width: 400px) {
.thing {
background-image: url(size-400.png);
}
}
@media (min-width: 401px) {
.thing {
background-image: url(size-401.png);
}
}
You could combine this with pixel density for even more specificity. @media(max-size: 200px) { #container { background: url(tiny_mobile.png); } }
@media(max-size: 400px) { #container { background: url(small_mobile.png); } }
@media(max-size: 800px) { #container { background: url(medium_tablet.png); } }
@media(max-size: 2000px) { #container { background: url(large_desktop.png); } }
@media(min-size: 2000px) { #container { background: url(retina.png); } }
Not always loading the same image is a good idea on mobile.People being smart is the horse, and programmers colluding with "advertisers and spies" in a massive fashion is the zebra.
There is a W3C TAG document that touches on this at
http://www.w3.org/2001/tag/doc/unsanctioned-tracking/
One problem is that there are so many ways of tracking user-agents in the web platform today that it can be hard to convince anyone that addressing one of them will improve the situation. :-(
One reason that it is still relevant even though you are already using Tor is that there are many ways to slip up and expose yourself. And when you do, you've paired this additional one in a hundred identifier to yourself. Might as well just use lynx.
Your personas are isolated and segregated. They share no information, hobbies, interests and at a tech level they don't share connections, machines, browsers, apps.
Your anonymous personas use Tor in an isolating proxy configuration, where traffic is explicitly allowed and proxied rather than routing all by default (NAT) with explicit blocks (like a firewalls block all then allow vs allow all then block)
If you look at Opsec failures (read thegrugq[1]) you'll find that a very large number are the result of a lack of compartmentalisation and were found by establishing link(s) between known and unknown personas
There's another interesting feature. Carefully restricted privacy-focused personas for different people tend to be very similar.
Of course, this is not perfect, and still allows for breaking some of the recommendations in the article, but it's a good start. Not to mention it's easy to switch compartments: restart the computer (still not perfect, but there's really no such thing as perfection here).
Still have to update it, but shouldn't be as bad as burning a CD every time.
I think TAILS should only be used in "one time/week only" situations, such as when you want to expose some information. It's not meant to be used on a regular basis. Qubes/Whonix, especially if you use it in a "disposable" (delete the VM) fashion should be generally more secure.
[1] https://tails.boum.org/doc/first_steps/upgrade/index.en.html...
Newly patched software = who was it patched by exactly?
I (probably) exaggerate, but the problem is that your anonymity pool is now very small.
Does anybody know if you might actually be safer from, say, a theoretical surveillance program by "blending in" as a typical Internet user vs. using Tor, where just one mistake might trigger a red flag?
I guess this technique wouldn't applicable if you do have something to hide, though... Hmm!
Everyone has something to hide, and everyone need the security that the right to privacy provides. If I am the victim of a crime, I do not wish that the lawyer of the criminal has every single detail of my life to dig through and find something to paint doubt in a judge/jury mind. I also do not wish that the criminal has total information about the judge and jury, which they could then use to figure out how to manipulate them to a different decision then the truth. As such, I do not only wish privacy for me, but privacy for every person who could end up as jury, judge, lawyer, victim or accused. Our justice system depend on privacy to protect the human beings involved from being manipulated.
How do you blend in? By not visiting any "subversive" websites and by not mentioning any "subversive" keywords. At that point you are a typical internet user. But how do you know what is considered subversive? Animal rights/environmental activists with no actual proof that they've done anything or planned anything are under house arrest right now in France just because the government wanted to free up resources to track Islamic extremist terrorists.
> using Tor. where just one mistake might trigger a red flag?
Btw as a point of interest your username just triggered a red flag and got put on a slightly elevated watch level by the US surveillance program. Why? You mentioned the word "Tor" (Snowden files for details).
> wouldn't applicable if you do have something to hide, though... Hmm!
Do you have genitals? Do you like keeping tabs on who gets to see them? Congratulations you have something to hide.
Would you like your boss to see what porn you watch? Congratulations you have something to hide.
Source? All I could find were warrants issued for actual protests during a state of emergency.
As far as the reports stated the State of Emergency is ongoing.
For instance someone looking to hide from a local tap, say while at work, can safely use tor to login to account they would normally access directly. The enemy isn't the website you are accessing, or some nation state with limitless tapping resources. You just want Tor to hide what you are doing from the boss. (But make sure you aren't sending your login details in the clear.)
In many environments these are also less likely to be blocked or detected by network operators, as they're a common component of business network traffic, while Tor (identified by communications with publicly listed Tor nodes) is not.
Tor was designed for anonymity, not circumvention. Circumvention is a side-effect of Tor and some circumvention features have been added (namely bridges), but there are significantly more elegant solutions for when only circumvention is necessary.
Most recently, the rendezvous system and hidden services have been particularly powerful in reducing censorship on the end of content publishers, but this feature was added two years in, it is an area in which Tor performs significantly more poorly than, e.g., i2p, and very few people are actually talking about this when they discuss using Tor for censorship evasion.
I love the Tor project, but people should understand that it is an anonymity system, not an anti-censorship system. When you are facing censorship on your end (the reader's end) and do not require anonymity, just use a SOCKS proxy or a VPN. They're radically faster, often easier to use, and there are a million different options for evading blocking and detection - using DNS queries as a covert channel is a popular one, but the sky's the limit.
If you need to evade censorship on the publisher's end, then this generally comes down to an anonymity problem (the publisher must remain anonymous for their protection) and so onion-routing becomes a reasonable approach. This is relatively uncommon, though, and I believe people should more strongly invest in other projects that originally built around this goal, rather than having it added later. Some of these are more robust against attempts at direct censorship (rather than just punishing the creator) as well, as Tor is relatively centralized.
If "they" have physical access to a machine, you shouldn't trust it.
* Don't type anything into an untrusted web page—you can be deanonymized by your typing patterns. Whenever you need to type anything, type it into a text editor and then copy and paste. http://arstechnica.co.uk/security/2015/07/how-the-way-you-ty...
* Don't move your mouse over the web page—you can be deanonymized by your mouse movements. So disconnect your mouse and interact via the keyboard only (always bearing in mind the problem of deanonymization via typing, of course). http://dl.acm.org/citation.cfm?id=2046725
> Heroes only exist in comic books keep that in mind! There are only young heroes and dead heroes.
- Prevent Tor over Tor scenarios.
Sincere question:
Is that really what they meant to say? Do NOT prevent Tor over Tor scenarios?
Since back in my demoscene days (which is a mostly European, non-native English speaking crowd) that one always stood out to me, almost exclusively French that made this mistake (pretty consistently, as well).
For a long time time before NSA was exposed, it had been working closely with a lot of security related technologies, researchers, developers, companies, and was a key part of the software security industry including standards. For instance SeLinux is a NSA project pushed hard by a number of open source companies including trying to integrate it into the Linux kernel but stymied by Linux Torvalds. A lot of these technologies and companies often get a free pass.
For anyone with serious anonymity or privacy needs it would be pragmatic to think carefully before relying on technology that is linked to the US government or US companies which basically rules out a lot of computing. Using technology to fight an adversary with unlimited resources and access to talent, and has been an integral part of the security industry is foolhardy and seems difficult to win. We need to find alternatives.
For those with a 'serious' as in life dependent need for privacy, for instance whistle blowers or persons of interest it can be argued the Internet today cannot deliver the level of anonymity they require.
1) You open a new tab in your favorite browser. At this point, a new instance of a read-only, lightweight, virtual machine is resumed. The virtual machine doesn't know about tor, but its entire network traffic is torrified by the hypervisor.
2) The tab now displays a VNC connection to the virtual machine you just spun up.
Now, it's possible that some things will leak through the VM, but it should also be easier to control than an entire browser running in your OS. For example, enforcing that the VM image be read-only ensures that once a tab is closed, all sources of history are gone... no cookies, no history, no browser settings. You only need to whack one mole.
Yes, there might be exploits that jump out of the hypervisor, but these aren't as common as browser exploits and you would need both to jump out.
So don't use the same passwords while utilizing tor that you have used with other accounts.
Or use similar passwords naming schemes. So if you are in the habit of using '@' for 'a' then try to avoid that and use random schemes.
Someone should make a short gif to explain this: imagine someone with a Guy Fawkes mask browsing facebook on his computer. Then some guy behind him look at his screen him and tells him "hey Mark Dupont, what's up?"
If I am running a normal Windows installation(say, Windows 7 Home) on a commonly-sized screen (say, 1366x768) and have a normal sized taskbar, no odd widgets, toolbars, or other screen-space taking things, it seems I am only reducing the anonymity pool to those other users with the same features, which I suspect is more than 4.
For a non-persistent live-boot situation such as Tails, I would expect the risk to be even lower.
What am I missing, if anything? Was there some legal situation in which browser window size was used to de-anonymize someone that warrants the attention to browser window size? I understand it's another layer of protection, defense-in-depth and all, but it seems to be getting a disproportionate amount of attention.
If (for example) you've got a vertical taskbar on a 4k monitor the pool will be much lower. Add in one other slip up, such as visiting a low-traffic website you've visited outside of Tor, and you've got a huge vulnerability for deanonymization.
As far as legal, I don't think there has ever been such a case, no. However, it definitely opens someone up to parallel construction, and there are always certain agencies for which a legal case is not necessary their end goal (CIA, NSA, etc).