dillo-browser / dillo

Dillo, a multi-platform graphical web browser
https://dillo-browser.github.io/
GNU General Public License v3.0
544 stars 27 forks source link

Fingerprinting #135

Open rodarima opened 4 months ago

rodarima commented 4 months ago

We may want to have some estimate in the amount of entropy we are leaking to find out what is the current fingerprinting capability of a given adversary when using Dillo. Setting the user agent to Dillo already cuts the whole population to probably less than 1ppm, but that is easily solvable.

Not having support for JavaScript certainly helps, but we may be still leaking some information in HTTP headers or in the way we deal with the sockets.

AFAIK, there is no tool to measure uniqueness that works without JS.

https://www.w3.org/TR/fingerprinting-guidance/ https://2019.www.torproject.org/projects/torbrowser/design/#fingerprinting-linkability

rodarima commented 1 month ago

Related: https://lists.mailman3.com/hyperkitty/list/dillo-dev@mailman3.com/message/6C5K4F6NBRUDSPNPWTXLQXCK3U3SI7DM/