!OJFkLJksWastbfdRuf:matrix.org

Whonix

371 Members
| Part of the Cybersec matrix.org community (#cyber-space:matrix.org) | RULES: https://cybersec-rules.thomcat.rocks | Whonix-focused room | Off-topic chat is fine. Keep it brief and/or move it to #cybersec-offtopic:matrix.org55 Servers

Load older messages


SenderMessageTime
3 Aug 2024
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them] Each tier gets progressively harder to fingerprint. Even if you don't want to disable JS entirely, setting the security level to Safer reduces the amount of JavaScript APIs that are exposed to websites, thereby making fingerprinting more difficult 23:24:27
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]
In reply to @chile09:matrix.org
user/agent?
It's very much not recommended to change the user agent in Tor Browser. Doing so will only make you more fingerprintable, not less
23:25:00
@chile09:matrix.orgrolodondo34but most sites are using CDN hosted JS no?23:25:01
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]
In reply to @chile09:matrix.org
but most sites are using CDN hosted JS no?
If we're talking about fingerprinting, this is irrelevant
23:25:29
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]If we're talking about cross-cite tracking, that's potentially relevant. But that's a separfate discussion entirely23:25:52
@chile09:matrix.orgrolodondo34what is the most common user/agent?23:25:56
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]
In reply to @chile09:matrix.org
what is the most common user/agent?
The default
23:26:09
@chile09:matrix.orgrolodondo34what is the default23:27:06
@chile09:matrix.orgrolodondo34cross-site tracking using cookies?23:27:42
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Well, Tor Browser is based on Firefox, so its user agent defaults to the default for the Firefox version it's based on23:28:24
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Though it does fake the OS you're running on, since there's no need to give that info to websites23:28:43
@chile09:matrix.orgrolodondo34but this is a vulnerability? The OS?23:29:21
@chile09:matrix.orgrolodondo34how can it be?23:29:41
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Telling websites your OS creates a data point that can be used for fingerprinting you23:29:48
@chile09:matrix.orgrolodondo34but it's fake no?23:30:23
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Fingerprinting is about using a combination of innocuous data points to identify someone uniquely. Any time the browser gives a website information that's different for different users, that creates a data point for fingerprinting23:30:41
@chile09:matrix.orgrolodondo34right but the OS is faked23:30:58
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Tor Browser solves this by simply reporting the same OS for every user, regardless of what OS they're actually running23:31:20
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]It's not enough for the OS info to simply be fake, it needs to be the same as what's reported for everyone else23:31:46
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]Technically if you happen to be running the exact OS version it reports, it's not fake, it's accidentally your real OS version23:33:18
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]But an attacker has no way to distinguish that23:33:31
@chile09:matrix.orgrolodondo34f23:38:16
@chile09:matrix.orgrolodondo34Tor Browser solves this no?23:45:52
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]I just explained how Tor Browser solves the issue of OS fingerprinting23:46:13
@chile09:matrix.orgrolodondo34si claro23:46:27
@chile09:matrix.orgrolodondo34gracias23:46:32
@chile09:matrix.orgrolodondo34what about GNU Icecat plugins, LibreJS, JShelter?23:47:10
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]It's not a problem if Tor Browser accidentally reports your real OS version, because the attacker has no way to know whether it's fake or real23:47:11
@memorysafetybelike:envs.netBabba27's Evil Twin (DriftNotSkid) [they|them]
In reply to @chile09:matrix.org
what about GNU Icecat plugins, LibreJS, JShelter?
Tor Browser is more effective
23:47:24
@chile09:matrix.orgrolodondo34por que?23:47:40

Show newer messages


Back to Room ListRoom Version: 6