[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #26146 [Applications/Tor Browser]: Setting `general.useragent.override` does not spoof the platform part anymore in ESR 60 which is confusing



#26146: Setting `general.useragent.override` does not spoof the platform part
anymore in ESR 60 which is confusing
-------------------------------------------------+-------------------------
 Reporter:  gk                                   |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  Medium                               |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  ff60-esr, tbb-fingerprinting-os,     |  Actual Points:
  tbb-8.0-issues                                 |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by traumschule):

 We collected two more duplicates today (#27671, #27672). Can somebody bump
 the score, please?

 From ​https://arthuredelstein.github.io/tordemos/os-detection-font-
 css.html:
 > Your likely operating system is: Linux Mac Windows
 I'm fine with that.

 > Also I'm curious about how you use media streaming to detect the OS.
 Me not so much. My focus would be to educate users that all kind of media
 can harm their anonymity (#13543) and it's best to use the feature filter
 (aka "Safest"). There are better programs to watch videos than your
 browser. VLC accepts youtube links and if the terminal is your friend,
 youtube-dl and mpsyt make your day. libs to decode mp3 and other media are
 prone to all kinds of exploits to take over your browser. no way around
 it.

 Someone with time could look into
 https://github.com/pyllyukko/user.js/issues/316
 (i hope this won't fall an my feet later)

 I suggest (to myself) not to wait for a decision, but to produce something
 that works. I am confident it will earn positive feedback.

 - #20842 is the place to go for fonts.
 - libm seems unfixable, better keep js turned off (#13018 #15473).
 - i propose to disable power management completely (#23627). This will
 break things and this is the goal.
 - #23701 confuses me
 - #27128 seems untouched
 Did i forget anything?

 I vote for: One UA for all Desktop OS with an option to disclose info for
 selected (by the user) apps.
 (Knowing that voting doesn't help much).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/26146#comment:50>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs