[tor-bugs] #22919 [Applications/Tor Browser]: Form tracking and OS fingerprinting (only Windows, but without Javascript)

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Dec 2 18:44:21 UTC 2019


#22919: Form tracking and OS fingerprinting (only Windows, but without Javascript)
-------------------------------------------------+-------------------------
 Reporter:  basvd                                |          Owner:  acat
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Major                                |     Resolution:
 Keywords:  tbb-fingerprinting,                  |  Actual Points:  0.5
  TorBrowserTeam201912R                          |
Parent ID:                                       |         Points:  1
 Reviewer:  tom                                  |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by tom):

 This LGTM. I began to wonder if we could use AppendInt(uint64) to get the
 same bitness for  2 calls to RandomNum instead of 3; but I think this
 would change the ultimate output of the boundary, and we would idally keep
 it looking the same so it's not apparent if one is using the old-style RNG
 or the new-style.

 If you agree this is keeping the same format/appearance of the boundary
 (aka, you can double check my belief) - let's land it in Tor and/or submit
 it for uplift to get it upstreamed/further review.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22919#comment:15>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list