TorButton user can still be diferentiate using their fonts list. the font list of torbutton user should be uniform. It's also one of Torbutton's design requirements "to make all Tor users look uniform amongst themselves".

I know i can just disable javascript to prevent site read the font list, but if i disable javascript i can't login to google account, The Worst Privacy Ranking of Internet Service Company (

Font Detectors:

I think even disabling JavaScript won't help. CSS can now instruct Firefox to load and use a font from a specified URL if a font with a specified name is not already installed on the user's system.

Sadly, there are a lot of CSS capabilities that are bad for fingerprinting with more growing every day... We could toggle browser.display.use_document_fonts for this particular fingerprinting issue. I will accept a patch to do this, but I don't think the option should be on by default.

I think the right way to do this is to figure out how to wrap the font engine so we can provide a reduced list, but since it is not an XPCOM component, this seems non-trivial from an XPI.

Alternatively, this may be something that we need to fix in the Tor Browser Bundles, by specially building firefox to only search font paths that we provide.

Dup of #2872.

