Re: [tor-talk] Making TBB undetectable!

On Sat, Sep 26, 2015 at 7:44 PM, Jeremy Rand <biolizard89@xxxxxxxxx> wrote:
>Maybe I'm not understanding you, but given that all TBB users are
>already distinguishable from other users since their IP address is a
>Tor exit, I'm not seeing how TorBrowser having a different fingerprint
>from other browsers is a problem.  The important thing is that
>TorBrowser users have the same fingerprint as each other, which the
>TorBrowser devs seem to be doing a good job on.

False! A unique Tor exit IP that visits site1.com then site2.com won't
compromise same person visited those sites or tow different person who
used same Tor exit IP at the same time did that, thus anonymity
remains true.

On Sun, Sep 27, 2015 at 7:40 AM, Dave Warren <davew@xxxxxxxxxxxx> wrote:
>No, you can't just patch in a hardcoded window and screen size unless it reflects the actual >viewport size.
>JavaScript is often used to position elements using relatively absolute positioning based on >the viewport that it understands is correct, this will fail if the viewport vs reported size isn't >accurate. More importantly, it won't even work, JavaScript can detect where wrapping >happens, and some creative 1 pixel tall transparent images could detect the actual horizontal >width by using varying widths.

Browser Add-ons can change actual view size to anything we plan.

On Mon, Sep 28, 2015 at 4:23 PM, AMuse <tor-amuse@xxxxxxxxxx> wrote:
>Having a unique, or unique enough browser fingerprint would allow
>website owners and content network providers to track a TOR user across
>nodes and/or sessions. With a large enough CDN (facebook, etc) you could
>reasonably de-anonymize a user.

That is correct. But a Tor user who temporarily use a natural
fingerprint to become undetectable for a while won't deanonymize
itself nor the rest of other Tor users who use a detectable version of
TBB because when a natural fingerprint is used once then there will be
no enough information available for data miners to link pseudonyms for
deanonymization, and for sure Tor users who need undetectability won't
use the undetectablizer Add-on all the time hence detectable TBB users
won't become unique.

Undetectability is a crucial requirement for privacy protection tools
and unfortunately seems that Tor developers don't wanna put their time
on this issue. I hope other folks take this problem serious and do
something quickly.
