Home / Companies / Fingerprint / Blog / Post Details
Content Deep Dive

We found a stable Firefox identifier linking all your private Tor identities

Blog post from Fingerprint

Post Details
Company
Date Published
Author
Dai Nguyen
Word Count
1,538
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recently discovered privacy vulnerability in all Firefox-based browsers, including Tor Browser, allows websites to derive a stable identifier from the order of entries returned by the IndexedDB API, which can be used for tracking user activity across different websites and sessions. This identifier persists even after private browsing sessions are closed in Firefox, and remains stable through the "New Identity" feature in Tor Browser, undermining user expectations of privacy and unlinkability. The issue arises from the internal storage ordering of database names, which becomes a deterministic fingerprint for the browser process. Mozilla and the Tor Project were informed of the issue, leading to a swift fix in Firefox 150 and ESR 140.10.0, which involves returning database names in a canonical order to prevent the exposure of entropy and ensure users' privacy. This vulnerability highlights the importance of carefully considering implementation details that might inadvertently create privacy risks, as even seemingly harmless APIs can become vectors for tracking if they reveal stable process-level state.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.