Skip to content

Tor Browser leaks banned ports in network.security.ports.banned

In Tor Browser linux releases, the start-tor-browser script suggests modifying the network.security.ports.banned preference when using a system-installed Tor process.

However, the ports banned using this preference are leaked by the browser and custom preferences can be detected. For example, Tails users can be easily identified due to using a custom preference.

Code to detect banned ports can be found here:

https://pseudo-flaw.net/tor/torbutton/detect-banned-ports.html

https://privacycheck.sec.lrz.de/active/fp_je/fp_js_echo.html

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information