[tor-bugs] #31206 [Applications/Tor Browser]: http://ip-check.info detects browser window size with JS disabled

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jul 19 10:31:34 UTC 2019


#31206: http://ip-check.info detects browser window size with JS disabled
-------------------------+------------------------------------------
 Reporter:  cypherpunks  |          Owner:  tbb-team
     Type:  defect       |         Status:  new
 Priority:  Medium       |      Component:  Applications/Tor Browser
  Version:               |       Severity:  Critical
 Keywords:               |  Actual Points:
Parent ID:               |         Points:
 Reviewer:               |        Sponsor:
-------------------------+------------------------------------------
 STR:

 1. Disable JavaScript by setting `javascript.enabled` to `false` in
 `about:config`
 2. Restart Tor browser (or use new identity)
 3. http://ip-check.info and "Start test!"
 4. New identity
 5. Resize window
 6. Repeat step 3

 Result:

 (I don't know how exactly but) Browser window size is detectable.

 *(tested also in ungoogled-chromium with JS disabled - same result: window
 size detectable)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31206>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list