Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Mike Perry
Thus spake Robert Ransom (rransom.8...@gmail.com): > On Thu, 23 Jun 2011 11:19:45 -0700 > Mike Perry wrote: > > > So perhaps Torbutton controlled per-tab proxy username+password is the > > best option? Oh man am I dreading doing that... (The demons laugh > > again.) > > If you do this, you will

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Robert Ransom
On Thu, 23 Jun 2011 11:19:45 -0700 Mike Perry wrote: > So perhaps Torbutton controlled per-tab proxy username+password is the > best option? Oh man am I dreading doing that... (The demons laugh > again.) If you do this, you will need to give the user some indication of each tab's ‘compartment’,

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Mike Perry
Thus spake Robert Ransom (rransom.8...@gmail.com): > On Thu, 23 Jun 2011 10:10:35 -0700 > Mike Perry wrote: > > > Thus spake Georg Koppen (g.kop...@jondos.de): > > > > > > If you maintain two long sessions within the same Tor Browser Bundle > > > > instance, you're screwed -- not because the ex

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Mike Perry
Thus spake Mike Perry (mikepe...@fscked.org): > Thus spake Robert Ransom (rransom.8...@gmail.com): > > > On Thu, 23 Jun 2011 10:10:35 -0700 > > Mike Perry wrote: > > > > > Thus spake Georg Koppen (g.kop...@jondos.de): > > > > > > > > If you maintain two long sessions within the same Tor Browse

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Robert Ransom
On Thu, 23 Jun 2011 10:10:35 -0700 Mike Perry wrote: > Thus spake Georg Koppen (g.kop...@jondos.de): > > > > If you maintain two long sessions within the same Tor Browser Bundle > > > instance, you're screwed -- not because the exit nodes might be > > > watching you, but because the web sites' l

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Mike Perry
Thus spake Georg Koppen (g.kop...@jondos.de): > > If you maintain two long sessions within the same Tor Browser Bundle > > instance, you're screwed -- not because the exit nodes might be > > watching you, but because the web sites' logs can be correlated, and > > the *sequence* of exit nodes that

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Mike Perry
Thus spake Georg Koppen (g.kop...@jondos.de): > >> And why having again add-ons that can probably be toggled on/off and > >> are thus more error-prone than just having an, say, Tor anon mode? > >> Or is this already included in the Tor anon mode but only separated > >> in the blog post for explana

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Georg Koppen
> Additionally, we expect that fingerprinting resistance will be an > ongoing battle: as new browser features are added, new fingerprinting > defenses will be needed. Furthermore, we'll likely be inclined to > deploy unproven but better-than-nothing fingerprinting defenses (so > long as they don't

Re: [tor-dev] Improving Private Browsing Mode/Tor Browser

2011-06-23 Thread Georg Koppen
> If you maintain two long sessions within the same Tor Browser Bundle > instance, you're screwed -- not because the exit nodes might be > watching you, but because the web sites' logs can be correlated, and > the *sequence* of exit nodes that your Tor client chose is very likely > to be unique. A