{"id":191020,"date":"2017-05-04T14:54:02","date_gmt":"2017-05-04T18:54:02","guid":{"rendered":"http:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser-profiles-itself-security-intelligence-blog\/"},"modified":"2017-05-04T14:54:02","modified_gmt":"2017-05-04T18:54:02","slug":"tor-browser-profiles-itself-security-intelligence-blog","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/tor-browser-profiles-itself-security-intelligence-blog\/","title":{"rendered":"Tor Browser Profiles Itself &#8211; Security Intelligence (blog)"},"content":{"rendered":"<p><p>    Dr. Neal Krawetz reported on his blog, The Hacker Factor, that he identified    problems in the Tor browser that may be working against the    anonymity networks stated goals. These issues cause the    browser to disclose information that could potentially allow    threat actors to profile Tor users.  <\/p>\n<p>    Krawetz looked beyond the user string information provided by    the browser in routine communications. While this string    information is the same in all Tor browsers to enhance privacy, he looked at other    parameters that the browser shared with a site, including    screen size, window size and scrollbar thickness. These factors    can vary depending on the OS, but its possible to ascertain    user patterns by observing them.  <\/p>\n<p>    For example, a normal browser setting has a window size that is    less than the size of the screen; but Tor sets them equal to    each other as part of its security stratagem. If a browser    communicant notes that the two parameters have equal value, it    are more likely to infer that it is dealing with a Tor setup.    Krawetz also noted that the macOS Tor browser miscalculates the    window size because of the dock menu on the screen.  <\/p>\n<p>    Additionally, the scrollbar size value is unique for each    version of Tor. Bleeping Computer reported that there is a    default scrollbar thickness in macOS of 15 pixels, while    scrollbars are 17 pixels thick in Windows 7, 8 and 10. Linux    can vary between 10 and 16 pixels.  <\/p>\n<p>    In 1883, Auguste Kerckhoffs formulated six principles for his military    cryptography theory. One aspect states that a system must not    rely upon secrecy, and it must be able to fall into the enemys    hands without disadvantage.  <\/p>\n<p>    The principle has been widened in use throughout the security    field and remains as relevant as ever. In cybersecurity    parlance, making some part of a system obscure will not, in    turn, make it secure. If just finding something can defeat the    system, you have already lost, and your system is not as secure    as you believed.  <\/p>\n<p>    Krawetz identified patterns that could tell an attacker that    Tor is being used for communication. Kerckhoff would likely    say, So what? Im using Tor and you still cant identify me.  <\/p>\n<p>    While Krawetzs threat model can be productive, Tor was    never truly designed to hide the fact that it was being used.    Rather, it was developed to conceal individuals use patterns.  <\/p>\n<p>    Even with these parameters invoked, each OS variant of the Tor    browser should look like any other. Ultimately, the Tor browser    will still function the way it is supposed to.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read the rest here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/securityintelligence.com\/news\/nowhere-to-hide-the-tor-browser-profiles-itself\/\" title=\"Tor Browser Profiles Itself - Security Intelligence (blog)\">Tor Browser Profiles Itself - Security Intelligence (blog)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Dr.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/tor-browser-profiles-itself-security-intelligence-blog\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94875],"tags":[],"class_list":["post-191020","post","type-post","status-publish","format-standard","hentry","category-tor-browser"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/191020"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=191020"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/191020\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=191020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=191020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=191020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}