What else, besides using Tor, and turning off Javascript, does a user have to do that a website operator finally gets they don't want to be tracked?
I'd be interested in a viable example of this being used to identify users.
This is pretty hard, considering the Tor Browser does a good job at having a common fingerprint at it's highest security setting (Javascript disabled, which is what this tracker is for).
I think he is saying that users can't be tracked between page-loads using this method, or your risk sending multiple users the same token. (which is true, at least with this implementation)
The time they spend on the website, latency, etc can all be used to add to a fingerprint, but there isn't something magic that makes this accurate, especially without JavaScript.
Edit: please don't mind me ghostposting kthx