Tor Browser: a legacy of advancing private browsing innovation
blog.torproject.org
blog.torproject.org
To enable Fingerprinting Protection in Firefox, go to about:config and set privacy.resistFingerprinting to true.
Some Firefox forks enable Fingerprinting Protection by default, including LibreWolf[3] (desktop) and Mull[4] (Android). If you are on Android, the release version of Firefox does not include access to about:config, and you'll need to either switch to Firefox Beta/Nightly or use a fork like Mull, Fennec F-Droid, or Iceraven to take advantage of this feature.
[1] https://wiki.mozilla.org/Security/Tor_Uplift
[2] https://support.mozilla.org/en-US/kb/firefox-protection-agai...
Interesting side effect though.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1369357
[2] https://addons.mozilla.org/en-US/firefox/addon/zoom-page-we
We could question if that’s really necessary as well but the ship has kind of sailed on that one.
People should be trained to allow script execution only when they trust the site, and there should be levels: Zero, Fully Isolated, Trusted.
OK now time to wait for someone to tell me this will be too much to ask from users. It wouldn't be an invalid point either, we can't even train people to have some common sense when in control of tons of steel going fast loaded with highly flammable liquids... So, there's that.
I don't know.
I don't think it would work when there's a state across views or server though, but maybe that's something you avoid when using Tor anyway?
One could use element.getBoundingClientRect and similar APIs to measure what size certain elements are rendered at and compare that with their default size for instance.
The resulting zoom level can then be used as a signal for fingerprinting.
I wrote more but I sound like old man shouts at cloud. I've got ad and JavaScript blockers, but so much of the web is created sitting upon a mesh of invasive bullshit that it breaks easily.
Shakes fist at cloud anyway.
IE, web component where you can set a format string and then the browser renders it substituting the info it has?
Then sites that need to know the date can ask for it.
There's a lot we could do by splitting stuff into permissions and some sort of standard templates.
I use a site that only does UTC, and time zone related complaints are the most common issue asked about on the forums
you can easily detect this
- please display this localdatetime as a string
- read it back and parse it
- are they (almost) exactly multiples of 60 minutes apart?
- if yes it's most probably your timezoneAnd displaying time/date locally would leak that information anyway if you wanted to do it in a way that works in various contexts it would need to in a website (e.g. canvas based apps)
even if you just let the user stylize the font of the date (which you clearly would need to), you tell your magic date input to only show the current hour, then use a font that has a certain width for each number, allowing you to then based on the width of that element figure out the hour, same for other things, obviously. It's easy to imagine some thing like that without thinking about all the details, but it's not really feasible once you think about how this would be implemented and how it could be circumvented. And that's in addition to not working in contexts where you schedule a blog post, zoom meeting, or whatever else might require the server to account for user time zone
It would be very interesting to develop a modern web based purely on declarative content (modern HTML/CSS). HTMX is an interesting take on this, although it's currently implemented as server-provided JS: i don't see a reason why such patterns couldn't be implemented by the browser itself.
For sure. I think some scripting could also potentially be implementable without massive fingerprinting / privacy implications. E.g. pure compute scripts, form validation, etc. that has no practical way to smuggle any data out of your browser. Anything that sends a request would have to be statically derived (or explicit user input as into form).
EDIT: Just for the sake of mentioning, simple/obvious computations for interactivity was the promise of GNU's libreJS project. I'm unaware of the current state of it, though.
Is not that the subset of the web that would work when javascript is disabled? Some already develop it in that direction - what is not declarative shall be unnecessary. Or are you suggesting something different?
I don't understand why we need to have dozens of CSS frameworks for "components" that have become common practice across the ecosystem. Pagination, "Hero" elements, intra-page tabs, breadcrumbs (and many others) should be HTML standard so that it's more accessible and users can come up with their own stylesheets. The breadcrumbs for example would enable your browser UI to show a "go up" button like your file browser does. Another interesting example would be element filtering: why can't a <form> with a local action property (like "#data") be used to filter a list of elements without JS?
As long as most UI of a page is dictated by dozens of piled-upon CSS hacks, user stylesheets will remain a wild dream. But given how little variety there is on the web these days, many things could be standardized part of the HTML spec so that CSS is only needed for customization (eg. colors, spacing) on simpler pages, while retaining the possibility for the server to suggest more complex CSS UIs as we currently do if you absolutely want to do that.
There is something like that, the Gemini protocol.
I understand the appeal of simplicity but if you ask me that's a huge step backwards compared to HTML5. No <form>, no <section>/<article... It's like markdown but with another syntax :-/
it wouldn't be much work
Also, is there some good venues to discuss the semantic/declarative web with you htmx folks and hopefully people from other like-minded projects? IRC? XMPP? Matrix?
We use discord for chat right now:
Do you maybe have a gateway/bridge to a libre network such as IRC/XMPP/Matrix? I find HTMX pretty interesting but i wouldn't touch discord with a 10-foot pole, if only because my limited computing resources won't allow for such a resource-hungry app to run in the background.
It seems like matterbridge supports discord backend but i don't have a discord account to try it with. If you're not willing to host matterbridge, i'm already hosting one and i would just need credentials to try and connect it to Discord. If you're willing to give that a try, feel free to mail me at my username @ thunix.net.
Seeing that a user has a site's zoom set to 90% seems to be close to worthless in terms of narrowing down what cohort they're in, let alone identifying them individually. What am I missing here?
How so? 90% is by far not the normal zoom level people browser with, so it is a perfectly valid data point to use for fingerprinting. Every single bit of data they can get makes your whole fingerprint more unique.
You can see the informational content of various fingerprints here: https://coveryourtracks.eff.org/
Another thing that has less than a bit of content is having cookies enabled. Nearly everyone has cookies enabled, for better or worse, so having them on doesn't add much to a fingerprint. Having them off adds far more. But both add something.
It's just another bit of information. Collect enough bits and eventually you'll have a likely-unique id. It doesn't matter what that information is as long as it somehow is about you (and not e.g. random). If you want to fingerprint, you just try to grab every bit of information you can, no matter how irrelevant it is taken on its own.
It doesn't need to say anything about a cohort to be useful, it just needs to enable identifying so that they can track you around and eventually combine other information they discover about you in a profile. And it doesn't even need to be 100% accurate; "that person coming from a Telia-owned IP visiting this site again at 2 AM GMT+2 using Firefox Nightly on Linux, with 1440p display and 120% zoom level and no fonts installed" could be two or three guys if I'm lucky but it's probably close enough to not matter for someone who just wants to sell me garbage.
If your zoom level were the only thing, then indeed it would be useless. Problem is, browsers leak lots of bits. It's better to try plug all leaks you can than it is to ask whether that particular leak alone is harmful enough.
Differential calculus. One negligibility times by a huge amount equals one discreet amount. One bit here, one bit there, you get a fingerprint of a thoundred bits.
For example, although tor --help still sends users to https://www.torproject.org/, as far as I know it's impossible to find the daemon documentation starting from there. The older website https://2019.www.torproject.org/ does have these docs, but it's surprisingly hard to turn up in a search. (You're much more likely to turn up old documentation on one of the man pages sites.)
It's interesting to compare https://www.torproject.org/ and https://2019.www.torproject.org/ more generally. To my eyes, the new site is uglier, less inviting and less useful, but I'm probably just getting old so my tastes don't align with fashion, if they ever did!
The thing I love about Tor Browser is such that when I end the session all tabs are gone. No more unlimited "interesting" tabs left opened for months. If I want to leave some information for later then I bookmark it in note app with a proper commentary why I would need it.
used this for like a decade. this works like firefox focus on android.
Looking at my logs, I couldn't identify where these people are coming from. I've added a bunch of checks to make sure it's not an automated script, but they seem legit. Until I started i started looking at their ip addresses.
Every single ip is from a tor exit node. I have no idea if these are fake users or real ones. I can't tell if I should be worried or excited.
Unless your blog is about online privacy, it does sound sus, though. If it’s all from a single actor, I wonder what the end-game is. Is it on the level where it’s starting to cost more to maintain?
`Other reasons`. Would love to know other use-cases for Tor Browser Bundle besides the ones mentioned in the info-graphic. One other reason not mentioned is recon and intelligence gathering, or OSINT. I do little investigations on various topics, safe in the knowledge I'm anonymous doing so. Need to lookup about erectile dysfunction? (ED). Then Tor's perfect for that.
I've used Tor for a very brief period once in my life, and that was to purchase adderall off of either Silk Road or AlphaBay (I can't remember), and I'm unsure of what the Tor ecosystem is like today, but not even that long ago, the vast majority of the Tor network was used for crime - ranging from child pornography, to hitmen available for hire, banned weapons, and obviously, for drugs.
I did not come across anything meaningful browsing the onion ecosystem, but left with a depressing insight of anonymity.
On a higher level pov, anonymity allows some of the most toxic and damaging ideas to brew and fester.
This is easily pointed out by the characteristics and behaviors between Twitter accounts that have an association with a real individual as opposed to ones that don't.
The difference in what they tweet is staggering.
Not to mention sites like 4chan and it's children.
Don't get me wrong, I'm rather against Big Brother or ISPs tracking and selling off our data, but absolute full anonymity is just an invitation for some of the worst things to happen.
Mind you, if you look to buy drugs on Instagram or Facebook you’ll find many outlets.
Your experience is limited to the markets because that’s what you were after presumably.
We created the BBC Tor site to help audiences access BBC News where they can’t and also to provide more secure access if they want.
You probably don’t know how bad the internet in China or Iran is. Imagine you can’t access any news site other than the government’s own outlets, and forget about social media.
We expected our Tor site to serve more users in Iran but interestingly we found more users coming to BBC Chinese, BBC Mundo and BBC Portuguese.
We think we are getting more users from Hong Kong and Brazil who are doing it for the sake of privacy rather than circumvention (our clear web sites are still accessible in Hong Kong).
At times when the news flares up, we get more users for BBC Russian, presumably because news consumers there want to have access to an independent source of news.
BBC site on Tor:
https://bbcnewsd73hkzno2ini43t4gblxvycyac5aw4gnv7t2rccijh774...
The alternative is no anonymous internet which is also not something I would want.
Also, based solely on gut feeling, the speed Tor from 10 years ago to today is night and day. Something tells me a ton of nodes are state actors and Tor is quasi broken. Not “buy an oz of weed FBI don’t move we’ll shoot” broken but if you are planning another 9/11 they probably can figure that shit out even if you are on Tor. I base that on zero facts.
Same applies to Tor, it just needs more users.
All "good" things have serious downsides. Free speech is good but if you defend it you'll no doubt at some point have to defend its use by a scumbag who using it in a scummy way - but the alternative is worse.
Same could be said for democracy, presumption of innocence, habeas corpus or any other of the cornerstones of a liberal society - they have big downsides but the alternative is worse. Sadly, right now, we're living the worse alternative to having strong privacy because people don't see it's value so we'll have to make do with Tor.
Your examples are not things that people are given anonymity and then do naturally - it's what people seek out anonymity to do. That is, you have cause and effect backwards.
Meanwhile, there is a difference between using Tor to access regular websites to avoid surveillance and using .onion sites.
> …
> On a higher level pov, anonymity allows some of the most toxic and damaging ideas to brew and fester.
You mention Twitter, but haven’t mentioned Facebook. That anonymity makes people to become or expose the worst version of themselves — or that anonymity allows some of the most toxic and damaging ideas to brew and fester — isn’t necessarily completely true. On Facebook, people use their real names, post personal photos (including participation in local events), their location, etc., and there’s still a huge amount of toxic ideas from these same non-anonymous people that brew there and are allowed to (because that makes the company more money).
I don’t disagree that anonymity allows people to be more honest in expressing themselves without filters. It’s one of the best things that happened with the Internet. But completely banning or not allowing anonymity isn’t the solution that some may immediately reach out for when faced with some social problems. Usually the people who dislike anonymity and want to eliminate it (I’m not saying it’s you) are those in power or want to be in power. And they don’t like it when people can organize outside their surveillance view.
> the vast majority of the Tor network was used for crime
How could you know the scope of the Tor network? Is that technically possible? Perhaps looking for ilicit goods, that's what was found?
Tor has sites for the Facebook, NY Times, BBC, ProPublica, Deutche Welle, Buzzfeed, and more.
I mean, while using Tor, sites can't track you or fingerprint you. But the fact you setup Tor in itself gives something to someone so that they can fingerprint you.
Pluggable transports are not perfect and can be profiled by a determined adversary, although it takes more resources and sophistication than identifying unbridged Tor traffic.
I mean one can't see what I am browsing on Tor browser, but the fact I am using Tor or have downloaded Tor, is it also hidden information?
Sorry, I know very little about it.
Remember, Zerodium revealed a 0day in all Tor Browser v7 and under once v8 had been released https://twitter.com/Zerodium/status/1039127214602641409
That's irrelevant, per the guidelines.
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
1. I responded to the strongest possible interpretation based on what was said.
2. How is that irrelevant?
If, for whatever reason, your goal is to conceal conflict or negatives in general, I suggest you pick on someone else.
This means (not exclusively) that you have to first answer yourself to that doubt you expressed vis-a-vis the post that originated it, and attempt finding an acceptable interpretation of the original post. Your reply shall reflect that.
(If your «strongest possible interpretation» clashes with the assumption of good faith, you will have to think again, and longer. Surely, your reply will reflect that.)
Contextually, for example: the poster did not recommend a non-identity concealing product over an identity concealing product /in general/ - the poster noted that the way the identity concealing product is developed/distributed, it is easier for exploitable bugs to be fixed comparatively later - the user must be aware of this.
Also:
> conceal conflict
No. "Manage conflict productively", to achieve some result. «For whatever reason»: efficiency, efficacy, productivity, civilization, enthalpy (fighting entropy), "keeping the place in good order".
Why can't you assume good faith on my part?
My point is making assumptions about intent leads to boring discussion. See the moderators (dang) post history and what he has to reply to, for examples.
There is a guideline on HN about replying to the best possible interpretation.
Doing so diffuses trolls and encourages people who didn’t explain well the first time to expand on their thinking.
It is also super pleasant to read posts of this style.
You seem to entail from the formulation of that guideline («...easier to criticize») that only strawman arguments are discriminated: too literal. For that matter, one could have mentioned «curious conversation», «shallow dismissals», «insinuations». You should take the guidelines as a whole - the intention - instead of just their formulated parts (which are not a lean complete formal logical corpus from which all consequences can be entailed through sheer syntactical deduction). Literally, a mandate is there against what «degrades discussion».
Privacy depends on security. Firefox is about 3-5 years behind security level of Chrome (Sandbox, Fuzzing efforts, hardening efforts, source code reviews, etc.).
When running in Safest mode, it's essentially just rendering HTML/CSS/images: anything that involves convoluted decoding (video, webfonts, scripts) is disabled. Treating your web browser as an environment for declarative pages is best practice for security: no matter how many layers of sandboxing you'll use, people will find holes.
So apart from a few bypasses like the parent comment explained, TBB is decades ahead any other browser's security level out there (except for your favorite CLI browser over Tor which has roughly the same properties).
Really doesn't matter anymore how extensive it is the browser fingerprinting protection feature or the access you do through Tor.
I believe we need a new type of Tor...
https://yggdrasil-network.github.io/
Granted, neither of those are designed as proxies to the clearnet... and maybe that's one of the bad things about Tor besides its its history with DARPA.
That's also why for the highest security needs VPN+Tor is a recommendation. Although to be fair i personally believe if an actor is powerful enough to perform traffic analysis across the Tor network, they're probably powerful enough to correlate your computer activity with the VPN<->tor link.
Networks that resist metadata analysis are called mixnets and there's some interesting research about them. The downsides are you add latency (because each hop needs to randomize sleep) so bidirectional sessions like TCP is unthinkable. So nothing as usable as Tor Browser for checking your webmail or reading a blog.
Beyond that, I've heard of xolotl related to gnunet, but I am not sure to what extent it is actually implemented and/or working, as usual with gnunet.