What can you learn from an IP address? (2019)
blog.apnic.net
blog.apnic.net
Clearly the IP address maps to a website, though not always one-to-one. In which case Reverse DNS gets you most of the way there. Presumably, this is better in the case of multiple sites served on the same IP through shared hosting or a CDN. Disambiguating with subqueries makes sense to get that last-mile accuracy.
While TFA claims 95% of sites are identifiable with their method, it also states 68% already would have been from IP alone in the first place. Presumably unique IP + unique resource boosts that higher. So the fingerprinting is perhaps not so dramatic, while requiring a lot more work.
What would be interesting to measure is how many sites _require_ fingerprinting to be uniquely identified. As well, the average number of sites per shared IP - to see how precise IP is even in the shared case.
In particular, don't interpret that 68% figure of bijection to mean the reverse lookup will be meaningful. I'd wager a large number of them are public cloud instances, and a PTR string ending in "compute.amazonaws.com" isn't likely to be a famous bookshop. Hey, consider yourself lucky it wasn't a NXDOMAIN.
Note that DNS is not actually normative for HTTP. The standard does not specify how names are resolved to endpoints; it defines no service name or equivalent/alternative record. For years the standards committee has (quite shamefully and negligently in my view) relied on tacitly squatting the address (A/AAAA) record. This architectural wart forces workarounds for consequential misbehaviours both in HTTP (such as aliasing at the domain apex), and in other protocols besides since everyone else has to tiptoe around the entitled gorilla. I suspect the workarounds thus employed further contribute to the fingerprinting options available.
There was a proof of concept tor like network posted here that did away with the real time aspect and wasted quite a lot of bandwidth to conceal your true target connection but that seemed like a good solution.
Unfortunately I can't remember it's name.
There us no definite answer to that. Even TOR nodes are heavily under surveillance.
Whether that's a reasonable thing to believe in is a good question. I trust that more than most sketchy VPN providers, but that's a low bar.
(An adversary could compromise Cloudflare's or any other CDN's network and snoop that way, but that takes more effort and is more risky than passive collection of internet traffic, which is otherwise all you need.)
If you as a residential broadband singlehomed user in, let's say, China, have all of your traffic going through an advanced DPI system run by an authoritarian state, they absolutely can correlate your activity on a number of metrics and statistical methods even if the crypto for end-to-end transport of your content is flawless.
Which there may still be other side channels, and other things, but the naive version of that attack sounds a little unlikely.