3 ms·
Figuring out someone is using Tor is trivial (e.g. list of exit node IPs https://www.dan.me.uk/torlist/?exit https://www.dan.me.uk/torlist/?exit). This mitigat
by qualeed 1y ago
Figuring out someone is using Tor is trivial (e.g. list of exit node IPs https://www.dan.me.uk/torlist/?exit https://www.dan.me.uk/torlist/?exit).
This mitigation helps protect the individual Tor user (e.g. with a unique 1726x907 px window) being fingerprinted across multiple sessions / sites.
- trod1234 1y agoThey removed OS spoofing just recently, and there isn't a mitigation for Raptor, some think meek might help with Raptor, but its very much up in the air.
- qualeed 1y agoThere is partial mitigation for RAPTOR: Counter-RAPTOR from 2017 (https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7958620 https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=795...) with mostly the same authors. I haven't kept up with the space much since then, so am unaware if there is more recent work. In any case, there are valid threat models where you want to mitigate website fingerprinting but aren't necessarily concerned with AS-level adversaries.
- trod1234 1y agoI've seen that, but I didn't see much of a mitigation, though I'll go back and recheck just to be sure, I was pressed for time last time I look at that. In fairness, most of big tech are AS-level adversaries at this point. Active attack through BGP-hijacking may be partially mitigated, but this isn't really needed for the most pernicious attacks which are interception/injection from a regional entity that's routing to the broader internet (outbound connections). The same entities can do early transparent encryption termination for outbound connections (to the general web) since they have their own private signing keys tied to root trust CAs (just not the one the valid cert was issued to), and that lets them collect a treasure trove of forensic artifacts to improve their citizen dossier for advertisers/highest-bidder, or inject content that is ephemeral in nature.
- wfn 1y ago> There is partial mitigation for RAPTOR: Counter-RAPTOR from 2017 (https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7958620 https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=795...) Oh I had missed that, thank you btw! Need more of those BGP monitoring systems... (and they performed an actual live BGP attack (not just simulation), neat)
- immibis 1y agoNote this means instead of always sending a Windows user-agent, they send either Windows, Mac, or Linux: one of three user-agents. They don't send more than that, e.g. they don't reveal your Windows version.
- ranger_danger 1y agoIt was always trivial to find the real OS behind a tor browser user because navigator.platform has never been spoofed by TBB, even when the user-agent was.
- Scoundreller 1y agoWhile not perfect, I thought tor rounded reported resolution to a small set of values
- abdullahkhalids 1y agoYou are correct. I was going off my memory. They say [1] > To prevent fingerprinting based on screen dimensions, Tor Browser starts with a content window rounded to a multiple of 200px x 100px. The strategy here is to put all users in a couple of buckets to make it harder to single them out. Moreover, even if you resize your window, the browser tries to protect you > by adding margins to a browser window so that the window is as close as possible to the desired size while users are still in a couple of screen size buckets that prevent singling them out with the help of screen dimensions. [1] https://tb-manual.torproject.org/anti-fingerprinting/#letterboxing https://tb-manual.torproject.org/anti-fingerprinting/#letter...