In defense of Tor routers
arstechnica.com
arstechnica.com
My experience with Tor was limited and was several years ago, but it felt like I'd returned to a 28k modem...except the entire Internet had begun to serve content on the implicit assumption that I at least had a few megabits of pipe. Do these routers actually offer a solid cornerstone of the kind of solution I've been waiting for?
But it seems to me that this kind of fingerprinting would be pretty easy to defeat if people new it was happening and wanted to defeat it. Something like panoticlick could give advic on fonts and plugins to add to lose yourself in the herd.
Panopticlick is nice but it's not that advanced.
(Much) more info: https://www.torproject.org/projects/torbrowser/design/
This contradicts what I have read on the Tor Project site:
"Site-specific or filter-based addons such as AdBlock Plus, Request Policy, Ghostery, Priv3, and Sharemenot are to be avoided."[1]
[1] https://www.torproject.org/projects/torbrowser/design/#philo...
With something like RequestPolicy the specific policy in place likely uniquely identifies the user.
Maintaining anonymity with a modern web browser is virtually impossible.
Maintaining pseudonymity substantially less so, but you're probably identified as "user running tails version x"
Or would CSS tricks allow a first-party site to conditionally load elements and reveal your RequestPolicy policy?
Sigh. :(