Opened 2 years ago

Closed 23 months ago

#23708 closed defect (invalid)

Menu Bar and Bookmark Toolbar privacy consequences

Reported by: NavigaTor@… Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

With the panoptickick test (https://panopticlick.eff.org/) and:

  • tor-browser: GNU/Linux 32bit, English, 7.0.6
  • Medium or low Security Settings
  • Menu Bar and Bookmark Toolbar enabled

I get the report that my browser configuration is unique (with medium) or nearly unique (with low).

Configuration bits summary
medium 9.9
medium + Bookmarks Bar 16.2
medium + Menu Bar 18.37
medium + Menu Bar + Bookmarks Bar 19.37 Unique

And with low:

Configuration bits summary
low 9.89
low + Bookmarks Bar 16.05 nearly unique
low + Menu Bar 17.79 nearly unique
low + Menu Bar + Bookmarks Bar 17.79 nearly unique

Child Tickets

Change History (4)

comment:1 Changed 2 years ago by cypherpunks

Component: - Select a componentApplications/Tor Browser
Owner: set to tbb-team

It's not recommended as resizing windows and disabled by default.

The main concern is

System Fonts 	
15.29 bits
	
38728.55 
unique

(with medium)

comment:2 Changed 2 years ago by cypherpunks

When you enable the bookmark bar did you choose New Identity? Since then your screen resolution will be adjusted conveniently.

Also to solve the problem with fonts just re-install the Tor Browser from scratch.

In any case, if this is exclusively about bookmar/menu bar and screen resolution then I'm sure it's a duplicate.

comment:3 Changed 2 years ago by cypherpunks

Status: newneeds_information

comment:4 Changed 23 months ago by NavigaTor@…

Resolution: invalid
Status: needs_informationclosed

I re-did the test with this test procedure:
1) Open the tor-browser, configure it for the test and close it completely
2) Open it again and go to https://panopticlick.eff.org, write down the test results, close the browser completely

Results:
"Currently, we estimate that your browser has a fingerprint that conveys 6.66 bits of identifying information." is obtained with:

  • High + no menu bar + no bookmark bar
  • High + menu bar + bookmark bar

"Currently, we estimate that your browser has a fingerprint that conveys 10.88 bits of identifying information." is obtained with:

  • Low + no menu bar + no bookmark bar
  • Medium + no menu bar + no bookmark bar
  • Low + menu bar + bookmark bar
  • Medium + menu bar + bookmark bar
Note: See TracTickets for help on using tickets.