[tor-bugs] #7256 [Firefox Patch Issues]: Explore zoom-based alternatives to fixed window sizes

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jul 24 18:56:25 UTC 2014


#7256: Explore zoom-based alternatives to fixed window sizes
-------------------------------------+-------------------------------------
     Reporter:  mikeperry            |      Owner:  mikeperry
         Type:  project              |     Status:  new
     Priority:  normal               |  Milestone:
    Component:  Firefox Patch        |    Version:
  Issues                             |   Keywords:  tbb-fingerprinting tbb-
   Resolution:                       |  bounty
Actual Points:                       |  Parent ID:
       Points:                       |
-------------------------------------+-------------------------------------

Comment (by joebt):

 Furthering the issue on TBB default opening window size, I visited
 Panopticlick again today, using both Firefox 30 & TBB 3.6.2, in Windows
 Vista.
 Maybe someone can explain the results & comment on vanilla Fx having fewer
 bits of identifying info (bits ii) than TBB in default screen size.

 I visited Panopticlick from a new identity, in a new TBB session (all
 browsing data cleared).

 1) Even at TBB's opening, default screen size (not maximized) - when
 Windows' DPI is a '''non'''-default value, Panopticlick shows TBB has
 43.98 bits ii, when js is disabled.  Many sites don't operate well w/o js.
 (do social media sites?)  The EFF says approximately 33 bits are needed to
 identify a computer.

 I will visit the site again, when the system DPI is @ default 96 & with
 TBB in starting, non-maximized window size.  As long as JS is enabled, not
 sure if the total will drop '''<''' 33 bits ii.

 2) Again, if users have the system __DPI @ '''non'''-default__ value,
 multiple browser characteristic detection sites report "odd" screen size
 for TBB.
 TBB opening default screen size was detected @ 1000x8'''67''' w/ java
 script enabled. Earlier today, same scenario, different session &
 identity, but js disabled, it showed 1000x8'''37'''.  How's that possible?
 It seems problematic, in itself?  Nothing was different about TBB starting
 size in the 2 scenarios (that I controlled), or displayed toolbars, etc.
 I've seen the same behavior before.

 3) In my previous test (see comment 10 above), with the __system DPI @
 '''96 default'''__ value, Panopticlick STILL showed odd screen size for
 TBB.  If Panopticlick is correctly detecting it (what's actually being
 reported), how can this be the intended TBB behavior?

  * For detected screen size, how is TBB better than vanilla Fx?  Unless
 I'm doing something incorrectly, for screen size, detection sites '''don't
 seem to show TBB as less unique''' than Firefox.

  * So far, I've __never seen anything close to a multiple of 200x100__, or
 any other multiple of real world monitor sizes, __for TBB__ on
 Panopticlick, '''''in any scenario'''''  - whether the system is default
 96 DPI, or not.

 4) Either there's something unusual about my system, or TBB reporting
 multiples of 200x100 doesn't work on all systems.

 There was nothing "unusual" about my previous browser window / toolbars,
 during the Panopticlick visit described in comment 10.

 5) It seems that TBB window size & the GUI (including __allowed toolbars__
 & their sizes) need standardizing.

 6) In my vanilla Fx 30, in '''full screen''' with java script & cookies
 __disabled__, same non-default system DPI, it showed 24.08 bits ii.

 Same Fx 30 w/ js enabled, but no other changes, it showed 41.71 bits ii
 (still better than TBB @ its starting size??).  All other things being
 equal, if I were to use !JonDo Fox (extension) in Fx, the bits ii are
 likely lower than TBB __in its starting size__.  Certainly, screen size
 would be less unique.  Note:  In this Fx profile - for fingerprint
 testing, I'm not using special spoofing methods; just disabling js &
 cookies.

 Yes, there are other reasons to use TBB vs. something like JonDo, but
 that's not the topic of this bug.  Fingerprinting & reported screen size
 are the topics.  I'm not touting JonDo Fox over TBB.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7256#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list