6 ms·
> In my experience, HTTPS makes you more distinct and trackable than plain HTTP. You lost me here. https://www.wired.com/2017/01/half-web-now-encrypted-makes-
by CiPHPerCoder 9y ago
> In my experience, HTTPS makes you more distinct and trackable than plain HTTP.
You lost me here.
https://www.wired.com/2017/01/half-web-now-encrypted-makes-everyone-safer/ https://www.wired.com/2017/01/half-web-now-encrypted-makes-e...
- nom 9y agoTrue, almost every remotely important page uses HTTPS now so the TOR traffic doesn't really stand out as much as it did a couple of years ago, but it still might look suspicious once you look at the overall bandwidth.
- irl_ 9y agoAlso me, so I wondered what experience he could have had to lead him to this conclusion. I found this: > His research focus on anti-anonymity technologies combines fields as vast as ergonomics and child development to artificial intelligence and theoretical biophysics. (http://www.hackerfactor.com/about.php http://www.hackerfactor.com/about.php)
- djsumdog 9y agoI suspect it was because the author thought the key used to connect could uniquely identify that browser, or that keys are somehow reused across sites?
- apeace 9y agoThe author is correct. HTTPS adds more vectors which can be used to form a fingerprint, such as the TLS version or the preferred cipher suites of the browser. For example: https://www.ssllabs.com/projects/client-fingerprinting/ https://www.ssllabs.com/projects/client-fingerprinting/ Anecdotally, I can tell you I have heard of ad tracking companies actively using this (for years now).
- acdha 9y agoThat's what you use when you don't have the richer information offered by HTTP sniffing. TLS versions tell you someone is one of a billion users of iOS version X; with HTTP they can piece together session cookies across every site and service you use, or with active attacks use things like the Verizon injected tracking code uniquely identifying you across devices.
- apeace 9y agoThat's true. If you're talking about your ISP sniffing your traffic, HTTPS is a win. But since the author was talking about using Tor, I figured he was focusing on fingerprinting by the websites themselves, where HTTPS is easier for them to fingerprint than HTTP.
- CiPHPerCoder 9y agoI don't doubt that HTTPS fingerprinting can be useful, but you can see the contents of their communications with HTTP. That seems much more useful for getting intelligence about Tor users.
- acdha 9y ago> fingerprinting by the websites themselves, where HTTPS is easier for them to fingerprint than HTTP. Could you explain your reasoning on that? If they're using the Tor browser every user is going to be very similar on crypto suites, user-agent, etc. — it's a rebadged Firefox distributable so it's going to be using their HTTPS implementation and you won't even get the OS version variations unless someone at the Tor project massively screws up. The bigger problem is that if you are being targeted by the website, there are far more interesting attacks they can try – convince the user to turn on JavaScript and do all of that profiling for WebGL/canvas rendering, local fonts, network resource timing to look for cached content from other sites, etc.
- apeace 9y agoYes, great point. But I said _easier_, not _easy_. Using HTTPS, a user may have a more outdated version of the Tor browser with different cipher suites than everyone else. Using plain HTTP, that can't happen. > unless someone at the Tor project massively screws up And that is what the author of the article is claiming. My comments here aren't in agreement with the author of the article, and I'm not claiming "HTTPS is bad" or anything like that. It's simply a categorical fact that HTTPS has more vectors to be fingerprinted than HTTP. But of course, as you mentioned, features enabled by Javascript are the bigger problem, which is why users who wish to be anonymous should completely disable it!