Slashdot Mirror


Tor Users Can Be Tracked Based On Their Mouse Movements (softpedia.com)

An anonymous reader writes: The way you move your mouse is unique, like fingerprints, and can be used by dark forces to track you on supposedly anonymous and secure networks like Tor, according to a Barcelona researcher. Because the Tor Project has failed to address a ten-month-old issue regarding "time measurement via JavaScript," there are a series of user fingerprinting techniques that are quite accurate at identifying users based on their mouse movements, scrolling speed, and how their browser and hardware reacts to certain JavaScript code. If a user visits a "fingerprinting" website via Tor and then via a normal browser, an attacker can have a general idea about their identity and can even pinpoint them to real IPs. The data that is usually logged in fingerprinting schemes is not 100% reliable or accurate for that matter, but it provides a starting point for future investigations.

2 of 109 comments (clear)

  1. Noscript. by sims+2 · · Score: 5, Interesting

    This one of the reasons why they should have never left noscript off by default.

    --
    Minimum threshold fixed. Thanks!
    1. Re:Noscript. by Jack+Griffin · · Score: 5, Insightful

      Makes no difference, we're all fucked. Technology is now reaching a point where humans cannot compete with machines.
      Your cell phone provider already has enough info to know everywhere you are at any point in time, who your friends and family are, who you call and how often. Google knows all your web habits, and what you hobbies are, and you bank knows every cent you spend, where and on what. And this info is freely bought and sold to marketing companies and other bad actors. It only takes one slip to connect a name to this data and your life is captured on record forever. We need to start preparing for a non-private reality, than try to hang onto any semblance of privacy we think we still have. Even as I type this some algorithm somewhere has already tied my writing style to all my other web aliases and is connecting me to my real identity.
      Privacy is dead.