Skip to content
GitLab
  • Explore
  • Sign in
  • The Tor Project
  • Applications
  • Tor BrowserTor Browser
  • Issues
  • #41317

Tor Browser leaks banned ports in network.security.ports.banned

In Tor Browser linux releases, the start-tor-browser script suggests modifying the network.security.ports.banned preference when using a system-installed Tor process.

However, the ports banned using this preference are leaked by the browser and custom preferences can be detected. For example, Tails users can be easily identified due to using a custom preference.

Code to detect banned ports can be found here:

https://pseudo-flaw.net/tor/torbutton/detect-banned-ports.html

https://privacycheck.sec.lrz.de/active/fp_je/fp_js_echo.html

Assignee
Assign to
Time tracking