[tor-bugs] #12609 [TorBrowserButton]: HTML5 fullscreen API makes TB fingerprintable, disable it!

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 28 00:16:39 UTC 2014


#12609: HTML5 fullscreen API makes TB fingerprintable, disable it!
----------------------------------+--------------------------------
     Reporter:  cypherpunks       |      Owner:  mikeperry
         Type:  defect            |     Status:  needs_revision
     Priority:  major             |  Milestone:
    Component:  TorBrowserButton  |    Version:
   Resolution:                    |   Keywords:  tbb-fingerprinting
Actual Points:                    |  Parent ID:
       Points:                    |
----------------------------------+--------------------------------

Comment (by saint):

 It's possible to set a video to fullscreen automatically (with
 javascript). I'd say to either prompt user when they try to enable full-
 screen that doing so reduces their anonymity slightly, or go with
 mikeperry's proposed solution below.

 Per mikeperry's mention in #tor-dev, limiting full-screen mode to the size
 of the browser window still allows someone to make an educated guess at
 resolution.  Which is still a big improvement over the default.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12609#comment:20>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list