+ Reply to Thread
Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 41

Thread: Test your anonymity

  1. #16
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581
    Quote Originally Posted by Instab View Post
    that's about the definition of "security". you got a good point but letting the "don't stand out is good" policy behind for a moment not sending any referer data at all is still the best.
    Here I disagree. Because it's more a question of anonymity than security. If you walk in the street with a spiderman mask, you can't be immediately recognized, but you are easily traceable until your home (exceppt if you are really spiderman). If on the contrary you have almost the same face as 1000 average joe, you will be very hard to be distinguished and traced until your home.

    extras like refcontrol are nice but in this case i'd rather turn referers off completely instead of trusting some plugin. imagine you upgrade the browser and the addon is not compatible and you don't know about that and go from here to what.cd
    Ok, you've got a point. But in doing that you set a red flag. What if in browsing inside what.cd, you never send any referer ? What.CD's admins, who certainly are reading SBI with great attention, will think: "this guy probably has read Instab on f... SBI -> forvever ban all his IP range".
    Reply With QuoteReply With Quote
    Thanks

  2. #17
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,410
    Activity Longevity
    7/20 19/20
    Today Posts
    0/5 ssss39410
    Quote Originally Posted by Renk View Post
    Ok, you've got a point. But in doing that you set a red flag. What if in browsing inside what.cd, you never send any referer ? What.CD's admins, who certainly are reading SBI with great attention, will think: "this guy probably has read Instab on f... SBI -> forvever ban all his IP range".
    That'd be the epitome of unprofessionalism. Many people browse with referers turned off, but that doesn't mean they've read Instab's post. Or even know about SB-I.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  3. #18
    Here's how to disable referrer in Firefox in case some of us don't know...

    How to disable referrer info in Firefox | eHow.com


    Open Firefox and type the following in the address bar: about:config

    When asked if you'd like to continue, select "Yes".

    To find this setting type the following in the filter bar: network.http.sendRefererHeader

    Double-click this setting to change its value to "0".

    Restart Firefox to allow the change to take affect.

    That's it!
    Reply With QuoteReply With Quote
    Thanks

  4. Who Said Thanks:

    Renk (22.02.11)

  5. #19
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581
    My results, in doing my best:



    How to make my fonts unreadable ? How to get recommanded values for browser window size (600x450 pixels, 1150x600 etc with 32 bits color depth) ???



    Quote Originally Posted by anon View Post
    That'd be the epitome of unprofessionalism. Many people browse with referers turned off, but that doesn't mean they've read Instab's post. Or even know about SB-I.
    Hmmmm... Right in some sense I mean, but it's a question of probability. Given a tracker T, let me name S the number of tracker's member reading an advice on SBI, and A the number of tracker's members adopting a behaviour corresponding to this advice (readers of SBI or not). If a tracker's admin observe that some member adopt this behaviour, he is interessed by the probability that this member is a reader of SBI, ie he wants to evaluate P(S/A) .

    Suppose that 10% of trackers members are SBI readers, to, and that 1% of tracker's members aradoptig the behaviour. THe probability P(A/S) is surely greater, says 5%.

    Then after having reopened my old baysians courses: P(S/A) = 5%*10%/1% = 50%.......
    Last edited by Renk; 22.02.11 at 12:35.
    Reply With QuoteReply With Quote
    Thanks

  6. #20
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    5/20 17/20
    Today Posts
    0/5 sssss6661
    Quote Originally Posted by Renk View Post
    Hmmmm... Right in some sense I mean, but it's a qüstion of probability. Given a tracker T, let me name S the number of tracker's member reading an advice on SBI, and A the number of tracker's members adopting a behaviour corresponding to this advice (readers of SBI or not). If a tracker's admin observe that some member adopt this behaviour, he is interessed by the probability that this member is a reader of SBI, ie he wants to evaluate P(S/A) .

    Suppose that 10% of trackers members are SBI readers, to, and that 1% of tracker's members aradoptig the behaviour. THe probability P(A/S) is surely greater, says 5%.

    Then after having reopened my old baysians courses: P(S/A) = 5%*10%/1% = 50%.......
    turning referers off is a common security advice and not related to SB-I in any way
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  7. #21
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581
    Quote Originally Posted by Renk View Post
    My results, in doing my best:

    (...)

    How to make my fonts unreadable ? How to get recommanded values for browser window size (600x450 pixels, 1150x600 etc with 32 bits color depth) ???
    I did the test with several vpn.
    Surprisingly (for me) the browser window results (number of pixels) depends on the vpn server I use. Is it normal ? Any explanation ?

    ************

    About the referer debate, here is the point of view of the jondo team:

    Referer-Management

    The Referer is one of those HTTP features that allow to distinguish different users while surfing the web and therefore, to reduce their anonymity. But that can be avoided activating our Referer management:


    With it, the Referer is not simply deleted as some webservices are not available without it. Rather, the Referer will or will not be set depending on the context of a particular request. E.g. it will be set as long as a user is surfing within the same domain and will not be set if a bookmark is used to request a particular web page. This context dependent behavior ensures that no web pages will break while at the same time the Referer cannot be used to gather information to identify users.
    https://anonymous-proxy-servers.net/...ondofox2a.html
    Last edited by Renk; 23.02.11 at 00:58.
    Reply With QuoteReply With Quote
    Thanks

  8. #22
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,410
    Activity Longevity
    7/20 19/20
    Today Posts
    0/5 ssss39410
    These are the results I get using a hardened Firefox:



    Authentication could be fixed by using RequestPolicy or CsFire, but cross-request prevention addons are extremely cumbersome. It's a shame that the only selective caching addon I found for Firefox (JohnnyCache) is a blacklist, and doesn't work on the newer versions, even after editing the XPI, since otherwise that could fix the ETag. I've tried setting network.http.keep-alive=false in about:config to disable persistent connections, but it always gave red.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  9. #23
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,410
    Activity Longevity
    7/20 19/20
    Today Posts
    0/5 ssss39410
    I installed JondoFox today to test how well it scored. Everything was green, obviously. I noticed functionality was provided by an addon, so I copied its files, edited some things a bit, and reassembled it into an XPI file. It's attached.

    Known problems and fixes:
    • the addon overrides some Firefox settings every time it is started. However, you can go to about:config, type extensions.jondofox. and change those to what you want.
      ^ One of those settings is "clear history on exit". After installing, turn that off, or else all your cache and cookies will be deleted.
      ^ My hacked addon forces extensions.jondofox.use_document_fonts to be 1, as the default value of 0 severely alters the appearance of most sites.
    • a JondoFox logo is added to error pages. My hack uses the original netError.xhtml file, but the logo will probably come back with updates.
    • the menu to choose between no proxy/custom/Jondo/Tor reappears at the bottom every time you start Firefox, and cannot be moved. Couldn't find a fix for this, but you can close the addon bar.
    • in order for the User-Agent override to work, you must use the custom proxy option, and leave all fields blank.


    I did away with RefControl and UAControl (in fact, JondoFox automatically uninstalls the former) since this fulfills my needs. It also includes working SafeCache. Test results here...



    "HTTP session" can only be fixed using JonDo or Tor, and "Browser window" has no known fix right now.
    Attached Files Attached Files
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  10. Who Said Thanks:

    Instab (13.05.12) , SBfreak (15.04.12) , cheatos (15.04.12)

  11. #24

    Join Date
    30.06.09
    Posts
    23
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 sssssss23
    Last edited by MGustav; 15.04.12 at 16:09.
    Reply With QuoteReply With Quote
    Thanks

  12. Who Said Thanks:

    Instab (13.05.12) , SBfreak (15.04.12)

  13. #25

    Join Date
    11.09.08
    Posts
    179
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss179
    Quote Originally Posted by anon View Post
    I installed JondoFox today to test how well it scored. Everything was green, obviously. I noticed functionality was provided by an addon, so I copied its files, edited some things a bit, and reassembled it into an XPI file. It's attached.

    Known problems and fixes:
    • the addon overrides some Firefox settings every time it is started. However, you can go to about:config, type extensions.jondofox. and change those to what you want.
      ^ One of those settings is "clear history on exit". After installing, turn that off, or else all your cache and cookies will be deleted.
      ^ My hacked addon forces extensions.jondofox.use_document_fonts to be 1, as the default value of 0 severely alters the appearance of most sites.
    • a JondoFox logo is added to error pages. My hack uses the original netError.xhtml file, but the logo will probably come back with updates.
    • the menu to choose between no proxy/custom/Jondo/Tor reappears at the bottom every time you start Firefox, and cannot be moved. Couldn't find a fix for this, but you can close the addon bar.
    • in order for the User-Agent override to work, you must use the custom proxy option, and leave all fields blank.


    I did away with RefControl and UAControl (in fact, JondoFox automatically uninstalls the former) since this fulfills my needs. It also includes working SafeCache. Test results here...

    image

    "HTTP session" can only be fixed using JonDo or Tor, and "Browser window" has no known fix right now.
    Errr... that ↑ addon seems to be corrupt according to my yet Up to date Firefox !!???

    MIre likely incompatible than corrupt iam sure off ..

    Thanks for the efforts though.


    cheers
    Last edited by kabster; 13.05.12 at 20:45.
    Reply With QuoteReply With Quote
    Thanks

  14. #26
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    5/20 17/20
    Today Posts
    0/5 sssss6661
    Quote Originally Posted by kabster View Post
    Errr... that ↑ addon seems to be corrupt according to my yet Up to date Firefox !!???
    so it dös for me i'm afraid
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  15. #27
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,410
    Activity Longevity
    7/20 19/20
    Today Posts
    0/5 ssss39410
    I think it will work if you close Firefox, place it manually under the "extensions" folder in your profile, then restart.

    Note a new version of JondoFox has been released since I wrote that post. You can autoupdate as with any other addon but that will overwrite my hacks, obviously.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  16. #28

    Join Date
    02.02.11
    Location
    Moldova
    P2P Client
    uTorrent, mRatio
    Posts
    26
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 sssssss26
    Someone, tell me why so much atention to anonymity?
    Reply With QuoteReply With Quote
    Thanks

  17. #29
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,410
    Activity Longevity
    7/20 19/20
    Today Posts
    0/5 ssss39410
    Quote Originally Posted by SpartakusMd View Post
    Someone, tell me why so much atention to anonymity?
    For me, it all boils down to: I want my Internet to be a wonderful place to explore, not a data collection source for someone else to keep a record on my preferences.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  18. #30

    Join Date
    02.02.11
    Location
    Moldova
    P2P Client
    uTorrent, mRatio
    Posts
    26
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 sssssss26
    I thought so. I will think about my anonymity :)
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread
Page 2 of 3 FirstFirst 123 LastLast

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •