As long as #3455 and Tor 0.2.3 isn't ready, I recommend to add on a warning about Identity correlation through circuit sharing. Reference with problem description. [1] [2] [3] [4] [5]

I don't think many people are aware of the issue.

When you google you'll see, that people recommend, in order to torify various applications, to socksify using port 9050. Stream isolation, multiple SocksPorts and identity correlation are discussed nowhere.

And if those people mix different goals (let's say, hide location from chat server, registered with real name; and anonymous posting) or use multiple applications at once, they don't only theoretically risk their anonymity.






I think the most useful document here would be an explanation/howto/cookbook for the bundler and advanced user about using stream isolation in 0.2.3.x. It could also explain the issues with not having them at all (as 0.2.2.x).

We need a paragraph of simple, bite-sized text to explain the risk here.

I think time solved this by now :/

