Anyone have any good information on using ublock origin with tor browser? Does it compromise my anonymity?

  • Lunacy@lemmy.ml
    link
    fedilink
    arrow-up
    16
    arrow-down
    2
    ·
    3 years ago

    It’s highly discouraged to add further add ons on Tor since you will be more easily fongerprintable.

    The only thing you should change on Tor are security settings, nothing else.

      • Lunacy@lemmy.ml
        link
        fedilink
        arrow-up
        7
        arrow-down
        9
        ·
        edit-2
        3 years ago

        Hi! It doesn’t make sense at all. Blocking ads & trackers is not a good approach to achieve privacy. It’s quite weak actually for many reasons…

        First of all, because enumeration badness doesn’t work; it’s not possible to create a list of every possible “malicious domain”. And even if it was possible, websites could develop their own first party tracking and then share the information to third parties like Google or Facebook.

        Second of all, because apps and websites can detect what domains are blocked, thus they -or malicious actors- will able to uniquely identify users more easily.

        Third of all, because extensions add more attack surface since they use privileged script in order to work.

        That’s why Tor doesn’t use any ad-blocker.

        For more information about enumeration badness and browser tracking you can see here and here

          • snek_boi@lemmy.ml
            link
            fedilink
            arrow-up
            3
            ·
            3 years ago

            I can totally see how Madaidan can cause fear, uncertainty, and doubt. When I read, for example, his criticisms of Linux, I felt not only that, but also disappointment. You for sure have good reasons to dislike Madaidan and either GraphenOS or the Lemmy GrapheneOS community. But I don’t know them. Could you explain a bit why Madidan and GrapheneOS (or it’s Lemmy community) are problematic? Your answer would help me see what you see :)

            • TheAnonymouseJoker@lemmy.ml
              link
              fedilink
              arrow-up
              7
              arrow-down
              6
              ·
              edit-2
              3 years ago

              https://lemmy.ml/post/73800/comment/66774

              Read above comment chain comments too

              Edit: the grifter is making claims about

              And please, don’t listen to TheAnonymouseJoker. He is known as a troll in basically every privacy community

              Here, “every privacy community” refers to NoGoolag and SpiteChat Telegram/Mtarix rooms, both places where madaidan is an admin and his entire pack of extremely racist people shitpost all day. It may also refer to r/privacytoolsio, where blacklight and madaidan seem to be close, toxic friends that call each other for brigading anyone who criticises them. blacklight, r/PTIO mod, once even attacked me after I was banned by trai_dep, the monster in the privacy community.

            • TheAnonymouseJoker@lemmy.ml
              link
              fedilink
              arrow-up
              6
              arrow-down
              9
              ·
              3 years ago

              Surely not gonna take the words of !grapheneos@lemmy.ml moderator, are you, readers? This person moderates the GrapheneOS community here.

              I would like to tell you that you even begged for moderating TheHatedOne and GrapheneOS communities here. Reveals a lot about you more than me.

              • akc3n@lemmy.ml
                link
                fedilink
                arrow-up
                7
                arrow-down
                6
                ·
                edit-2
                3 years ago

                Requesting is not begging, hence the purpose of c/community_requests

                You seem like an angry person replying out of hate. I’m sorry for whatever it is that happened to you to be this way. It doesn’t give you a right to attack, harass and bully people.

                • TheAnonymouseJoker@lemmy.ml
                  link
                  fedilink
                  arrow-up
                  4
                  arrow-down
                  3
                  ·
                  3 years ago

                  Quite the leap there, with the abuser claims. Be careful with the projection and the sarcasm, it might burn you a little on the inside.

                  You are just revealing about yourself as you continue to reply to me.

  • MarcellusDrum@lemmy.ml
    link
    fedilink
    arrow-up
    11
    ·
    3 years ago

    It makes you a bit distinguishable from the people who don’t use an Ad-Blocker. It won’t be enough to identify you, but it does add to your digital fingerprint.

  • nikifa@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    3 years ago

    silly comments. Tails is using ublock orgin for Tor browser they ship with.

    “Don’t use Tails it ruins your OP sec” lol.

    • Lunacy@lemmy.ml
      link
      fedilink
      arrow-up
      6
      arrow-down
      5
      ·
      edit-2
      3 years ago

      A difference is that Tails includes the uBlock Origin extension, which removes advertisements. If an attacker can determine that you are not downloading the advertisements that are included in a webpage, that could reveal that you are a Tails user.

      https://tails.boum.org/doc/anonymous_internet/Tor_Browser/index.en.html

      edit:

      Site-specific or filter-based addons such as AdBlock Plus, Request Policy, Ghostery, Priv3, and Sharemenot are to be avoided. We believe that these addons do not add any real privacy to a proper implementation of the above privacy requirements, and that development efforts should be focused on general solutions that prevent tracking by all third parties, rather than a list of specific URLs or hosts.

      Implementing filter-based blocking directly into the browser, such as done with Firefox’ Tracking Protection, does not alleviate the concerns mentioned in the previous paragraph. There is still just a list containing specific URLs and hosts which, in this case, are assembled by Disconnect and adapted by Mozilla.

      Trying to resort to filter methods based on machine learning does not solve the problem either: they don’t provide a general solution to the tracking problem as they are working probabilistically. Even with a precision rate at 99% and a false positive rate at 0.1% trackers would be missed and sites would be wrongly blocked.

      Filter-based solutions in general can also introduce strange breakage and cause usability nightmares. For instance, there is a trend to observe that websites start detecting filer extensions and block access to content on them. Coping with this fallout easily leads to just whitelisting the affected domains, hoping that this helps, defeating the purpose of the filter in the first place. Filters will also fail to do their job if an adversary simply registers a new domain or creates a new URL path. Worse still, the unique filter sets that each user creates or installs will provide a wealth of fingerprinting targets.

      https://2019.www.torproject.org/projects/torbrowser/design/#philosophy

      This is literally documentation taken from the Tor Project.

      • Brattea@lemmy.ml
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        3 years ago

        Here’s the thing tho, u block might be good for your threat model. Depends what it is. any way if you are surfing clear web you got more serious opsec concerns.

        • Lunacy@lemmy.ml
          link
          fedilink
          arrow-up
          4
          ·
          edit-2
          3 years ago

          Hi.

          I think i didn’t explain myself because this is happened before.

          The point of the comments I wrote are not aimed to say “don’t use ad-blockers” or “don’t use Linux” and so on. What I’m trying to do is “fight” the misinformation spread by certain people about these topic.

          Now, while people should act according their own threat model, they should also be aware about the possible pro and cons about every software they eventually are going to use.

          I’m not an expert, but in my understanding privacy is not something you can easily achieve. Browser need to carefully develop actual features designed to protect users’s privacy, like Tor browser does.

          Installing a bunch of add ons aimed to “blocks ads & trackers” or *spoof user agent" will make you stand out more from the crowd.

          Then if you’re comfortable with that it’s up to you. Again, there is a big difference between be aware about something and then act accordingly and be in denial mode and accuse people to spread misinformation beside the reliable sources linked.

          I personally use ublock on my desktop browser because I don’t like to see a page filled with ads & tracker and I don’t care about stand out from the crowd.

          Please, let me now whether I made that clear or not.

          edit: I’m asking you because I tend to make typos since English is not my first language.

    • TheAnonymouseJoker@lemmy.ml
      link
      fedilink
      arrow-up
      5
      arrow-down
      4
      ·
      3 years ago

      99% people have zero idea when they give advice using buzzwords. These people are either spreading misinformation, or are grifters (few of them).

      If uBlock Origin is creating more attack surface, being a highly vetted, open source addon for REDUCING attack surface, that should tell you about advice you should be taking from such idiots.

      I am one of the main people who has brought back focus on threat modelling and opsec, and I am glad that it is also differentiating the grift from the good advice, and not just guiding everyone towards a less tinfoil, more saner path to privacy.

  • leanleft@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    i would say use it.
    but if you want to blend in perfectly then you should be doing what most people do.