Skip to main content
Sign in
Snippets Groups Projects

Fingerprinting: EFF Cover Your Tracks shows actual OS/CPU architecture as platform

  • View options
  • Closed (duplicated) created by Neel Chauhan
    Closed (duplicated) Fingerprinting: EFF Cover Your Tracks shows actual OS/CPU architecture as platform
    • View options
  • I run Tor Browser on openSUSE Tumbleweed, and when I was checking EFF's Cover Your Tracks, I noticed that despite TBB's user agent saying Windows 10 and no CPU architecture, Cover Your Tracks shows the actual platform used, in this case, Linux x86_64.

    Screenshot_from_2023-02-03_21-23-06

    I decided to whip out my MacBook (not my main laptop), and tried the same EFF site, it says MacIntel:

    Screen_Shot_2023-02-03_at_9.34.54_PM

    For reference, a Windows screenshot (from my work ThinkPad) is:

    Tor_Browser_EFF_Cover_Your_Tracks_Win32

    This means websites can still fingerprint by OS despite a "Windows 10" user agent without any architecture, and also the architecture on Linux/Mac/BSD even though it's not in the user agent.

    EDIT: What I meant to say is that in the JavaScript settings, we should only say Windows (desktop) or Android (mobile), and nothing else, like we do in the user agent. This will make it harder to fingerprint Mac and Linux users.

    Edited by Neel Chauhan

    Attributes

    Assignees

    None

    Labels

    None

    Milestone

    None

    Dates

    Start: None

    Due: None

    Time tracking

    No estimate or time spent
    To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information

    Activity

    • All activity
    • Comments only
    • History only
    • Newest first
    • Oldest first