3 ms·
They use hexchat as an example but do these processes run with the users configuration? Wouldn't this leak IRC usernames if you forget to change it. ... Or lea
by ericfrederich 1y ago
They use hexchat as an example but do these processes run with the users configuration? Wouldn't this leak IRC usernames if you forget to change it.
... Or leak cookies if you launch a browser?
- charcircuit 1y agoWhat do you mean by leak usernames? It would leaks that a username uses tor. It would still leak that all of the usernames connecting to the same IRC host would be the same person. IRC seems pretty dangerous if you want to remaining anonymous considering how many people are logging disconnection times allowing them to be correlated with other network disruption events.
- 01HNNWZ0MV43FF 1y agoIrssi iirc used to default your username to your system username, so noobs would leak their given name by accident. After seeing that I changed my username in Linux to always be the most common username
- SV_BubbleTime 1y agoWhat is the most common Linux username though? Obviously you don’t want to do your regular work as root. And guest has its own issues. Is there a “common name”?
- tbrownaw 1y agoNot sure about "most common", but I have some vms that use `user` as the username.
- Xevion 1y agoadmin
- romnon 1y agoubuntu
- Fnoord 1y agoroot
- user32489318 1y agoRobert'); DROP TABLE Students;-- Roberts
- PaulDavisThe1st 1y agoroot?
- ericfrederich 1y agoI was talking more about you using HexChat with your preferred username "FooBar", but then when on Tor you want to be "SpamEggs". If you launch HexChat through oniux and it reads your config file, you might hit the login button before changing your name from FooBar to SpamEggs.
- 47282847 1y agoTor is anonymizing you primarily from the network. There are many use cases where you do want to be authenticated/known to whoever you are talking to. You just want observers to not know. In your example of correlation of connection times, it may not be your goal to remain anonymous from the network and its participants, you may be interested in the location-hiding properties, and/or adversarial networks (like local government or corporate networks) and firewalls.
- alfiedotwtf 1y agoSeparation of concerns - although Tor goes to great lengths to prevent fingerprinting, Tor and Oniux’s main aim IMHO is to make the source IP untraceable. Same thing could have been said about using Tor to login to Gmail (if it were not HTTPS).