[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #10833 [Firefox Patch Issues]: Screen resolution should not be identical to window size



#10833: Screen resolution should not be identical to window size
--------------------------------------+-----------------------
     Reporter:  ben                   |      Owner:  mikeperry
         Type:  defect                |     Status:  closed
     Priority:  normal                |  Milestone:
    Component:  Firefox Patch Issues  |    Version:
   Resolution:  duplicate             |   Keywords:
Actual Points:                        |  Parent ID:
       Points:                        |
--------------------------------------+-----------------------

Comment (by ben):

 > It is not possible to both defend against fingerprinting *and* prevent
 TBB from being detected as TBB.

 OK, so detection of Tor is not an issue. Understood.

 > We make our decisions about fingerprinting based on the concept of
 entropy reduction *inside* the TBB userbase.

 Right. But a screen resolution of 1057x909 would appear likely only once
 world-wide.

 > First, there are websites out there that will try to resize browser
 windows to the whole desktop resolution

 We'd need to prevent that. Even regular Firefox prevents window resize and
 popups (by default, and almost all websites accepted this limitation). So,
 I don't think that's an issue. If we would allow that, that would
 definitely allow tracking: Just resize the window to a unique size, and
 then later or on another site or session query it. Even if you change the
 size for new windows, it would allow to match different sessions within
 the same window.

 > Further, ... people with larger than 1920x1080 displays will necessarily
 stand out with your suggestion.

 No more than they currently do.

 My suggestion can reduce entropy dramatically (from 20+ bits=unique to 2
 bits: 2 resolutions within TBB only). Is there a case where it increases
 entropy compared to now in TBB?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10833#comment:13>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs