> IP addresses won't necessarily ID a TOR user unless all exit nodes are known and being checked for.
Forgive my naivety, I don't really know Tor that well or even use it, but aren't nearly all exit nodes known and aren't they routinely checked for? It does not seem like a difficult thing to check for. I mean when I googled to check it seems like it is easy and Tor even provides a tool and publishes the 2188 addresses[0,1,2]. So... I'm quite confused about your assumption because a quick googling is leading me to believe that this is a rather known thing and doesn't require anywhere near state level action. I mean people routinely scan the entire internet and those posts don't even make it to HN anymore because they are so easy.
> The shared fingerprint makes TOR users indistinguishable from other TOR users unless/until a single identifying factor isn't accounted for at which point all TOR users are identifiable on every connection, across time, different domains, etc. The sameness of TOR user's fingerprints + even just one consistent identifying feature means TOR users could be individually tracked.
This is a great point, and I get it. But I'm not sure how this is different from normal situation. Doesn't this mean a misconfiguration of the Tor browser? One or two metrics may not be enough entropy to have confidence in an identity, though certainty you're right that it is of concern. I'm just trying to intuit the entropy difference. I'd wager it matters which metric is broken. But the question is when we start undoing Tor fingerprint overrides, at what point does the entropy decease before it starts increasing again? (as you're suggesting) Is that enough information to confidently identify a person? I honestly have no idea. This is a question since you're stating this is a cause for concern.
> A unique canvas fingerprint can be used to track you, but as long as it's differently unique on every request it can't be used to track you because the resulting fingerprint will always be different.
Is that true? I heard that Canvas Fingerprint randomizers actually decrease anonymity for the average user (i.e. done without other measures such as what Tor and Mullvad are doing). Due to noise being information itself, and is thus itself a fingerprint. You just call the function multiple times and look for differences or call different functions and look for similarities (i.e. the return const value). Maybe not as clear of an identifier as a normal canvas fingerprint, but it does constitute good information as most browsers aren't randomizing. I mean one piece of information alone isn't enough, that is why they collect several. You aren't being identified by only your canvas fingerprint.
> isn't a bad thing, it's just extremely fragile. Still, it's better than nothing.
I'm just asking what your alternative is. Btw, Tor and Mullvad __are__ randomizing[3]. So what is your complaint and what is your suggestion?
[0] https://metrics.torproject.org/exonerator.html
[1] https://2019.www.torproject.org/projects/tordnsel.html
[2] https://ipdata.co/blog/tor-detection/
[3] https://mullvad.net/en/browser/hard-facts
> privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts set to true
> privacy.resistFingerprinting.randomDataOnCanvasExtract set to true