Opened 6 weeks ago

Last modified 2 weeks ago

#27083 new defect

TBA: Window size rounding isn't used

Reported by: sysrqb Owned by: tbb-team
Priority: Very High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-mobile, tbb-fingerprinting-resolution, TorBrowserTeam201809
Cc: sysrqb, igt0, arthuredelstein Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

On desktop, the window size rounding was uplifted into Firefox with bug 1330882. This is not effective on Android.

Child Tickets

Change History (9)

comment:1 Changed 6 weeks ago by igt0

How will this bug will affect the sites UX? Specially when they are using CSS media queries.

comment:2 in reply to:  1 ; Changed 6 weeks ago by sysrqb

Replying to igt0:

How will this bug will affect the sites UX? Specially when they are using CSS media queries.

I'm not sure. Currently, when I visit https://whatismybrowser.com using TBA it shows something like:
Computer Screen: 412x609
Browser Window Size: 412x609 or 412x670 (depending on whether the toolbar is showing or not (Full-screen browsing)).

I suspect these screen sizes can fingerprint specific devices (but I haven't tested many other phones or tablets).

comment:3 in reply to:  2 Changed 6 weeks ago by sysrqb

Replying to sysrqb:

I suspect these screen sizes can fingerprint specific devices (but I haven't tested many other phones or tablets).

Err, sorry, "specific device models" is what I meant.

comment:4 Changed 4 weeks ago by arthuredelstein

Cc: arthuredelstein added

comment:5 Changed 4 weeks ago by towiw

Android allows us to change display size in settings. We can also set specific size in developer settings. Maybe it can be mitigated if all users are advised to set a specific display size.

comment:6 Changed 4 weeks ago by towiw

Testing different display sizes in https://browserleaks.com/css shows that only min-height, device-height, and min-device-height are changed. All the rest remain unchanged. So changing display size in Android settings is not really effective.

comment:7 Changed 4 weeks ago by towiw2

Actually it may work. I don't have two phones to test it. Can anyone test it on two different phones and see if setting the same display size is effective?

Only phones running on 7.0 nougat and above have the ability to change display size. At least 7.0+ users can have the same fingerprint.

comment:8 Changed 2 weeks ago by gk

Keywords: tbb-fingerprinting-resolution added
Parent ID: #25703

comment:9 Changed 2 weeks ago by gk

Keywords: TorBrowserTeam201809 added; TorBrowserTeam201808 removed

Moving our tickets to September 2018

Note: See TracTickets for help on using tickets.