When the anonymity ends for darknets
In this track we will be discussing methods and tools can be used by someone, who wants to get information about the user and is ready not only to banal traffic analysis on the output nodes, and use the features of font rendering, vulnerability onion-resources and some disadvantages configuration. Demonstration of information leakage channels about the darknet-resident; increasing anonymity in Tor. Unique method of drawing a psychological portrait of the darknet-user, which has not been previously published.
21. Fingerprint
Device fingerprinting
• Tracking you after you delete your cookies.
• Tracking you after you change your IP address.
• Various measurements such as the User-Agent
string, screen size, time zone, fonts, browser
plugins and….rendering!
24. Meanwhile, in Tor Browser:
getImageData()
var canvas = document.getElementById("canvas");
if (canvas.getContext)
{
var canvas = document.getElementById("canvas");
if (canvas.getContext) { var ctx = canvas.getContext("2d");
ctx.fillStyle = "rgb(0,127,0)";
ctx.fillRect(10,10,20,20);
var Pixel = ctx.getImageData(29,10,2,1);
25. Fifty shades of font rendering
hinting/antialiasing
Calibri
Times New Roman
Arial
Georgia
28. • The <span> tag is used to group inline-elements in a
document.
• The <span> tag provides no visual change by itself.
• The <span> tag provides a way to add a hook to a part of a
text or a part of a document.
<span>fingerprint</span>
for (var j = 0; j < STYLES.length; j++)
{
var style = STYLES[j];var div = DIVS[style];var span = SPANS[style];
// This is where the measurment occurs.
span.textContent = c;var w = span.offsetWidth;var h = div.offsetHeight;
// Add to checksum.
checksum = addsum(checksum, w);checksum = addsum(checksum, h);
}
39. Alternatives
• Math routines with floating point?
• Measuring time of calculations?
• Mouse/pointing events?
• Battery Status API?
• Unique keystrokes traits?
• Other gaps…
Все могло пойти по другому, даже если чувак этот и следил за своей анонимностью. Все равно его можно поймать
https://en.wikipedia.org/wiki/Freedom_HostingХостинг размещал ресурсы с деской порно. Как только закрыли хостинг – пропала куча ресурсов и Маркуса объявили в розыск Предполагается, что анонимность клиентов Freedom Hosting была нарушена из-за взлома веб-сервера, а не сети TOR. В код страниц веб-сайтов был помещен фрагмент на языке JavaScript, собиравший и отсылавший информацию о пользователе на сторонний адрес.