[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: email with Tor



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Marco Gruss wrote:
> Ben Clifford wrote:
>> Received: from hotmail.com ([65.54.229.28]) by mc12-f31.hotmail.com
>> with Microsoft SMTPSVC(6.0.3790.211); Mon, 17 Oct 2005 05:48:40 -0700
>>
>> It has time zone information in it: -0700. From this they can infer
>> what area of the world I am in.
> 
> This header is from an internal "transaction" at Hotmail (65.54.229.28
> belongs to them). I'm pretty sure their servers usually stay within the
> same time zone <g>
> 
> That you are in the same time zone is just a coincidence. 

I don't think so. I checked my mail folders for mails from Hotmail accounts
for the time zones they use in "Date:" and "Received:" headers. German
hotmail.com users always have +0100 or +0200 there (depending on whether it's
summer or winter), which is the correct local time zone. American users tend
to have something from -0400 to -0700. In spam sent from Hotmail other
timezones occur as well, e.g. -0300 or +0400.

Thus I suppose they're really using JavaScript to read your browser's timezone.

Or maybe they have servers around the world and forward you to the one that
seems to be nearest to your IP -- but then Ben should have seen different time
zones when he uses Hotmail via Tor, so that's probably not the case.

A workaround to this problem is probably to switch to another freemail
provider and, if you're paranoid, to turn off JavaScript.

Bye
	Christian

- --
|------------ Christian Siefkes ------------- christian@xxxxxxxxxxx -----|
|    Web: http://www.siefkes.net/     |     Jabber: hc@xxxxxxxxxxxxx     |
|  Graduate School in Distributed IS:   http://www.wiwi.hu-berlin.de/gkvi/
|------------ OpenPGP Key: http://www.siefkes.net/key.txt (ID: 0x346452D8)
Information is free.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD4DBQFDVjGr301HxjRkUtgRAnvbAJdMXaWwTWoZXQvZY7j12jMJbBJzAKCL2T1x
NINASGcQOSY8wQG85y/DYg==
=q3R3
-----END PGP SIGNATURE-----