[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-talk] Data collection by Tor Browser
- To: tor-talk@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [tor-talk] Data collection by Tor Browser
- From: Georg Koppen <gk@xxxxxxxxxxxxxx>
- Date: Wed, 15 May 2019 08:18:00 +0000
- Autocrypt: addr=gk@xxxxxxxxxxxxxx; prefer-encrypt=mutual; keydata= mQINBFH3/woBEADHs/Q4t69Vm+mNMW0vH0Ms6HtjpzBsto/yyDAoLitmAxfMIeCuWuyuBdHR krdq9Rk5WQLYtP9eROGkuABK/UaxpLw8zkwkmqbxQ2wxytVwgonOmAFPXvPjzVy+ToJvKWJj tRGFoWwO9OEZ8q6xhVnwLUJXRQF01/XhBhU2RPzzUTHrgiY2bi6Ko34nSM8qAuidykqd/elI wE+kn4+TZ+yBC7pzwUfRK0bOqc05qtq5ooH7rYGpvdOkt9DuoFEjhLrBaL3UiP5J6D9W1Ltv 7Y239RGZyGr0wO5ClhuJwipnw6yWDt493cw4fOy7J1Lbo8dZyU4pnFIgt1Cu506/CvdQ53pR UHhCSIS/IyOiEL9PI/PPByG9UhwNQYk9U22h4MalPwa+4rZ1XA6mf5+T4QQRmghAnegPwyQw qnQzHc2ZPAal+Ill15AncyfIeMfuCLyA/TVWwQTQMzdcVwu3nljBfGOjOSTHOafBqsVlvgEo R9GB9OaTbriP7lCDJmBsgFFZ5F0m6us2pP72TpM0GMYCae7PHk7POhvcE5VJg03E3tjyQUQA zt5ZcpzjZtbcWIoYjxEJMq1Wzj0PYfZYFYZGq2lQx7xJ54gb+RlXEaKiXhDQH+EkrKZHBDWi atMbfkMWiknmn8O7VkuT4LOHsF1I9oJt1VTZ0dx2MVvk2hhs3QARAQABtCBHZW9yZyBLb3Bw ZW4gPGdrQHRvcnByb2plY3Qub3JnPokCOgQTAQgAJAIbAwULCQgHAwUVCgkICwUWAwIBAAIe AQIXgAUCUuzzUQIZAQAKCRCUNzqpS3wyI694D/90P74XiDzioGbNEH37W9P5G6unLUKp/zLf 5Ifosf6ijS5EvhKXpSXAqWu4eSpUh+i72Kr53SvzAIggWjUM61e92xt0bg4+VFaguMh6d9l0 MpDMfRJB+qoRNaDDyGk1VH9ZLBJOpTY59HcIIyg2LIMt1PHk+3npr0MnDfh/5fgyPvFRv9ZK WkKdwD4ImlqGXaxsES2pPk8tn21k7J4N8jzRAYM8oV9cMeeCbMgERilU2sRxNORs55zV6GiD A68lmwY6+OHjaKd0k+Oibs63PrTl1+P4EYBZTlXK9gSSWKiUydVP+2lQoyGVmuH0VpepEcnv zu06g+YU4TiH3f7t1chknGlEm1s872nyZo7Nd+zVDcIa4iklBMpeEsPDB6zRT7KBH+oCw5vK G+Ngjv3AO8hD2RTFHw8oAD8WPBbrOB2C9qSha/XSl7rjxTpqRillP+543xhQncC3b2x+Vk4C wlJdrjOvweMnM4xCEeg03WUeRz6a4Uuh6A9x4WZia+5Y5PrKG4GKPeBbskFdw6N0/10Gk1nF wpS42esKsrvqeltRLPzwFj0FEO+mole3y2f+iR8rJd/rik7AW9PM2YkhiF8kmcyh07GSjcCo qg7AkOJ87Bv2knZ0KYlukY5wBKK/DY55GTLGQ7w6kR/BzMOlKnru1e0+zvyZ4KijODEuaUi1 2bkCDQRblYJ6ARAAz+9QcEoz5GB8GoPRsVLDeAB33O3cHTiH/UGZjuiswnoaPZnJ+jt/1b3P CsAdWdFwj3oYHz5B2SxBl/GSslPBJAIzlLss3uGEq+DLqV5kzvL55dc3HTC8evNSJF6OBkqk 5r24yuJDbLVhpyB+34QfYN2vESBBf8usQrNqp3lfm0ePiHkLFBX8Y8hIdYg5pz5WzXywaz1t oGlyfDtfZuOqd0m8er4W5VmARb5PvB6TIGjSOhOTJPQV67c6cSxKsx+dCvgsZzBGVhlQ33nO 7yQKsvl+DFJ254s876AoyGQ7iQRxk/0/8mWOpdcmIqLjdmZNVX7OGmsJf4RfC7a+mUgImg5r za+A0qE13b+XwpzTBOgIhsFeqVySXCV865ZNSPqzOCTI5fNCa9RaOhswYQcrGsQUy7hiw3qU lJyDsOCuQ8AUxB8qHBQ9Eh4jSk0Pfgdk0/KHa8bshkbexQBq5zjQXFb6zSaSPPeJsJ3t1o68 shVV3DjX7msMP5tTvHPbM841OHxl2UIN/Lixw7tYDhXKOdshd3k3KuDZSv57vY2US5g437hh kYcYtz+EvP10ufJR/DM1ed4gozqQLMZcYR4DgzeB6q2f02paNSfOhEYliUmEHKV50tbIo3l7 1FiLRAeu/IHAupKpwjnud3XgFpwl38IROQLgUB0uf5bksGu10TUAEQEAAYkCPAQYAQoAJhYh BDXNdMJKmxWhnhqBoZQ3OqlLfDIjBQJblYJ6AhsMBQkB49aAAAoJEJQ3OqlLfDIj5z4QALaX P1KME/Eru5D4giAuflIzI7zQh2Hx+fOWwTL3fld8Cpkr3qpc8YD8aesL/y1Brrhj0cUHZsjq 3W7CdrjGj+bvNlycaGuBicpaODVcZDdn7wgvGJYmzkcgE5wWFRUCVrPPc+Q6LQNEVNyXyTQf qFikL7Cpt5q/vGvAyNxGOOTkK+hJXXRdwT4PrBS9ve9h+B+zf5dcd8mfRgQlQNjK/SEzVJpr qL7IS0dhIO1bTFLvMHz92M9MEiUz43PLKCtplF3gE++U6gcXMpWIZR/nf0Dx81lBMvWA4B8y eXuXjZW7oXa3sDrZ8tBTQ+UApHV/LCf9JUM8YA7eFL1O2KHGQKPURKeVvVBpkqSGBZj8kCqO XiGvlZCkzQTSRX0zr/j2uhaz3YjuflS94yYWDZ36Lc/pa24BHf+I+4ZW+kimoyi9VWmVYgBV iCDRs24S+++g+9wcRZ6TKYOvCW3mid5YFcOpwba1VZsPH6VBLT576KKg08rDTBixMTK6AAhb OeWcURa7bU5Q98wcexHbEfTxA0Bw6nplAW8IAksuaFjiScqJfJc9fSsjIbCArFoLkNgegpMJ BCWns156d8659oUmWZi01k3cwrDPQmOhvEqSDpVuAMK/ecLFUt+eZAABN/YD9MtDnEAwRE9U 3dS22OFRyBCGmZwuAQQD17UAc7YnwBGDuQINBFuVgrgBEADS9Y8DkhZWadmRRSJFr9z7UsNP 0GC3M9449dhWDq/cYkHKycK1t9cqDMd+cy59QdQBoZAFnIvMQ+bwzEamQyn5jSTkFU4ZYW/l DZXVqeyFCWFOFA9WXNj2Av5RtNZoL7zPLkVztNKxHIheKOx8w5XgFv/MDj1wVHMzQ5zLnCQv 6RbKslfAFIrzy2u2wW91yZ20Oqxjgku5jw8D1/cztkGa+g9a47E9jZSmUE+Nxo4hd7Vn09Qw K8wi86sQKwyCgrL3MugUoLIuiJuctF7MlmqkSKnGDKjgZSX9p64+bFqBUK+T9WEvY0abs6FX dsmMjp9T/N89pMmqvvBxu+XaVU//esApjI49az1jPOkh08UjlmtTN06KZhx6appub2tJZiNw NQDfBKtC572w1bXiHg0knyCRmwXubXtSs3bRiSY8WDRGkQa6nxky368tJ767KQvMD3Ck9gqd xrcBldPgN1bcFmSeNvQX7RA1arQzYuM+gdIUzborEYS6oFWygFNjwUIDiQzVrjiKodgWQIR+ 5MrNcU5Zw8edpDDPsYCO5yhPjVEpMtWXL7aAGUFSs+yXqj06HHSrK83I/BXaImpo1HRlCrIc Ktrbn3goAW9e3+VivWgElvvRs13/NZic7N+JjqaNfLKfPRS4oRkwVHD1kqZQ72iyXO6vtMCn DVJQBAcmPwARAQABiQRyBBgBCgAmFiEENc10wkqbFaGeGoGhlDc6qUt8MiMFAluVgrgCGwIF CQHj1oACQAkQlDc6qUt8MiPBdCAEGQEKAB0WIQSqGlmSKghzjSNCvAVNkqfkq3PsVAUCW5WC uAAKCRBNkqfkq3PsVPmaEADJL4Qsjt45hDStlhWrECSWcNdPws1klQybZ7mvjip3ChEr/6vX pDUrWvonUT70uUksC/1IMdIf/n4U/YYZDLznA4/mFfzD0sEhhQ+UzSsUV0su8uhexpY0D5uG ZC4YgVy8+CTAo0PHQV1VzEu7bbUJIqGQbum4rNUp3A0fuZJgcN0/m8z56uCCU+AWbtOThLu6 15LbIJiBNuE2ruA7fvedxAEyMAL0aSiRQIqV8iuIqWb2d1Aa6I1R3Ze0JYUotJNHkViSlhJH 1xpWurPjGWZMb2YGFI/sYbOdYvmnzvjEPT8EPgCzK8FhPkwzmUXY4X9UTZuzZQl04ajjkTd2 wt/+oHHDp9+4RlMv4259Tc3LC3CTiK9A0kyGs6VwS8r4L3f9t3r/Dp0gPXZYi4PEOFph98l5 +VFpaCI+BNIskgaKcrgp+VhjjtL80Xryw4euYaBc7TkijdaKzdk8Y1pn1tHKtgUiWMnoJq/6 zpwEntNFK86+PUzbuolPsloMx/BeQueEjFgAnRTWbq3hD9tu3plg2CfN0dicVzrzkchDqQqI N/mbpba+VXX6RZzbfYhcRwevmYb9eHmNFyLsjJotUK49yuhPCu7hdriWBpRT1tVI26HEB8OJ ZPZqnR/drMwOZNgnnyL+F00XvbbXEBJzgPM8mBlFJEw5/JQCnsXoJXJx2Ki9D/4jYWlXSTva Ux/gjT8noe8b24NJZcbOcNOj5UeRi1+D30uCWvTALaltnLgr4wBhkjLQ0AkszFrIaCwXMsvS rvcwCfoeOuO+4fnrHPpLT+gLShbY3TFXyOLXrpEDTKVbJ5DMAUjGynQuzPrsvJg46BZxsXRN bjC5qcazAcUsVs6zE7erX5+r4K52YWTNz9BPCDZ20BnUroyVjNfAngVQbVLvpvubjexLVg9Y HRkH8WKDMjFZU3FRww+blRQEhl0vdqYU0TNKgCWYE3RrvaS/F6/LzGTJSVr4B7eLZDqibE1r M1qjvrhqoLyIGpG2M1A0GfwmRoRlVs7ltoV8ZhnGwUSiQmKpuqhAGON9i/IWFL5ncAl9wfAW CCFprkVBqqFxgnB34bP9FtCu5sKeGf2+NbvqhQGaaY9kBIyouK7Pn3f//PXUxOm5vTXFkBV4 mZh1CU0y23/3G6SSdxr6WAIRUdrPD4HhDAKxxG275TsyGnTHYQ6shybdAWHcC5FoAohjTBPJ +8MYotKp3qoQBHQ2Z5BZrO4i/dgR44U1QdBL3CEjFRc9Evvi/bFpbQSdGY2p4Wx6zUqVj9b3 MhfambCS1hIZ3MzFFPlVbfcKFLbTp1op5aUM0s+R7fEgS1UkpRKoSmd+lxq7V3H43fPVoBiI iMVqRRL3IFUR+1BN4zqS9YSh6g==
- Delivered-to: archiver@xxxxxxxx
- Delivery-date: Wed, 15 May 2019 05:49:25 -0400
- In-reply-to: <16aabdba39b.adefaa0434432.631552690051091832@zoho.com>
- List-archive: <http://lists.torproject.org/pipermail/tor-talk/>
- List-help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
- List-id: "all discussion about theory, design, and development of Onion Routing" <tor-talk.lists.torproject.org>
- List-post: <mailto:tor-talk@lists.torproject.org>
- List-subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
- List-unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
- Openpgp: preference=signencrypt
- References: <1693c8f4bfc.11989793128050.8103172444614974568@zoho.com> <5a23bb09-2922-913b-b992-273d6ab37c40@torproject.org> <16aabdba39b.adefaa0434432.631552690051091832@zoho.com>
- Reply-to: tor-talk@xxxxxxxxxxxxxxxxxxxx
- Sender: "tor-talk" <tor-talk-bounces@xxxxxxxxxxxxxxxxxxxx>
npdflr:
> Thanks Georg and Roger.
>
>
>
> I have taken some time to read the links given by Roger and try to understand various terms related to tracking/privacy on the internet.
>
>
> Basically, I understand that there would be a need to gather some technical data to keep the Tor network running and also improve the Tor network and if there is any sensitive data gathered at all then it would be for as short as time as possible depending on the requirements and also not made public.
>
> Further, I would like to ask:
> 1. Whether any extensions (such as HTTPS, NoScript) or other technologies/tools in-built (preinstalled) in Tor browser would be gathering data?
> (or in other words: Should I go through their terms or contact them separately?)
As far as I can tell, no, they should not gather data. If that's the
case then this is a bug we should fix.
> 2. Can Tor browser or Tor client be used in a commercial environment? (by an organization or individuals who are self-employed)
Yes. There is nothing that speaks against that from the Tor side at least.
Georg
> Thank you.
>
>
> ---- On Wed, 06 Mar 2019 00:32:00 -0800 Georg Koppen <mailto:gk@xxxxxxxxxxxxxx> wrote ----
>
>
> npdflr:
>> Hi,
>>
>>
>> Does Tor browser itself collect any data (Technical data, Web activity data, Personal data etc)?
>>
>>
>>
>> As Tor is a modified Firefox ESR, does Tor browser follow the Firefox Data Collection Practice? (https://wiki.mozilla.org/Firefox/Data_Collection)
>
> No, there is no such data collection by the browser itself. We try
> pretty hard to disable things like telemetry and other potential data
> collection mechanisms. If we have overlooked something here then this is
> a bug we should fix.
>
> Georg
>
>
>
>
>
>
>
>
> ---- On Fri, 01 Mar 2019 21:13:32 -0800 Roger Dingledine <mailto:arma@xxxxxxxxxxxxxx> wrote ----
>
>
>
> On Fri, Mar 01, 2019 at 08:00:17PM -0800, npdflr wrote:
>
>> Does Tor browser itself collect any data (Technical data, Web activity data, Personal data etc)?
>
>>
>
>> As Tor is a modified Firefox ESR, does Tor browser follow the Firefox Data Collection Practice? (https://wiki.mozilla.org/Firefox/Data_Collection)
>
>
>
> I believe the answer is no, Tor Browser shouldn't tell anybody else
>
> any of these things about you.
>
>
>
> You can read the Tor Browser design goals here:
>
> https://www.torproject.org/projects/torbrowser/design/
>
> and anything where it reveals your browsing activity would count as a
>
> bug -- and depending on the type of information leak, could qualify for
>
> a bug bounty: https://hackerone.com/torproject ;.
>
>
>
> Three caveats to my answer though:
>
>
>
> (1) This word 'collect' is confusing, because that word sure makes it
>
> sound like it includes internal program data structures. The browser
>
> needs to know something about your web activity while it's loading web
>
> pages for you, and that by itself isn't harmful. The key question is
>
> whether it shares that information with anybody else. For this sort of
>
> user info, we aim to stick to the principle of "no secret databases",
>
> that is, anything that we gather should be so sanitized, and so safe to
>
> collect, that we share it with everybody else too. That way we're never
>
> in the position where attackers might want to break into our systems to
>
> learn more about our users.
>
> https://www.freehaven.net/anonbib/#wecsr10measuring-tor
>
> For browser activity, the obvious simple approach to only publishing
>
> safe things is to publish nothing at all, which is what we try to do.
>
>
>
> (2) I might not be up on the latest Tor Browser moves, so it's possible
>
> there are some open tickets for disabling telemetry or the like which
>
> aren't yet fixed. Keeping up with the constant changes to Firefox is tough
>
> to do perfectly. I'll let the browser team jump in here if they want.
>
>
>
> (3) Other places on the Internet could still keep statistics, based
>
> on your connections to them. I'm thinking in particular of:
>
>
>
> (3a) the addons.mozilla.org server, which ought to see just anonymized
>
> connections over Tor, but that still lets them gather general statistics
>
> like how many Tor users there are, what extensions they have installed,
>
> etc. Similarly, the periodic update pings, and update fetches, happen
>
> over Tor but can still be counted in the aggregate:
>
> https://metrics.torproject.org/webstats-tb.html
>
> https://blog.torproject.org/making-tor-browser-updates-stable-and-reliable-fastly
>
>
>
> and
>
>
>
> (3b) the Tor relays, which see connections from the Tor client that is
>
> part of Tor Browser. Because of the decentralized Tor design, no single
>
> relay should be able to learn both who you are and also what you do on
>
> the Tor network. But they can still collect what they observe about who
>
> you are. Relays collect and publish aggregate statistics about the users
>
> they see (but not what they do, because they can't learn that). For much
>
> more info, see https://metrics.torproject.org/about.html
>
>
>
> and
>
>
>
> (3c) other researchers might perform experiments using their own
>
> internet connections to try to answer questions about Tor performance,
>
> usage, safety, etc. The ones who are doing it right will consider how
>
> to minimize risks while doing their experiments:
>
> https://research.torproject.org/safetyboard.html
>
>
>
> Hope this helps!
>
> --Roger
>
>
>
> --
>
> tor-talk mailing list - mailto:tor-talk@xxxxxxxxxxxxxxxxxxxx
>
> To unsubscribe or change other settings go to
>
> https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk
>
Attachment:
signature.asc
Description: OpenPGP digital signature
--
tor-talk mailing list - tor-talk@xxxxxxxxxxxxxxxxxxxx
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk