Tom Ritter tom at ritter.vg
Fri Nov 17 13:23:24 UTC 2017

On Nov 17, 2017 3:49 AM, "Georg Koppen" <gk at torproject.org> wrote:

I don't understand, though, why this is an issue for Tor Browser at all
right now as the combination of "comes from a Tor exit AND is using the
Tor Browser user agent" could pretty easily be used to decide whether to
show the canvas warning or not, without adding additional strings to our
User Agent which then would get sent with *every* request.

The script runs client side in JavaScript and is designed to require no
setup by users who deploy the WordPress themes. With those requirements
WordPress would have to call out to a third party API - either us or
themselves, both bad options.

