Firefox sends your uptime

Geoffrey Goodell goodell at eecs.harvard.edu
Sat Apr 5 12:09:58 UTC 2008


On Sat, Apr 05, 2008 at 02:01:29PM +0400, .FUF wrote:
> Firefox sends your uptime in "gmt_unix_time" field (seconds since boot).
> Other browsers (IE, Opera) send your current system time in UNIX format.

Even sending the current system time is somewhat troublesome, since
small inaccuracies may be likely to remain relatively constant over long
periods, allowing an attacker to observe, for example, which machine is
twenty seconds slow.  Not sure about to what extent running NTP
ameliorates this.

Geoff



More information about the tor-talk mailing list