Re: Tor Browser font fingerprinting defense

2020-04-13 Thread Caspar Schutijser
On Mon, Apr 13, 2020 at 12:01:16PM +0100, Stuart Henderson wrote: > On 2020/04/12 20:36, Caspar Schutijser wrote: > > On Fri, Apr 10, 2020 at 09:24:31PM +0200, Caspar Schutijser wrote: > > > Below is a WIP diff that makes font fingerprinting defense work in > > > our port of Tor Browser. > > > >

Re: Tor Browser font fingerprinting defense

2020-04-13 Thread Stuart Henderson
On 2020/04/12 20:36, Caspar Schutijser wrote: > On Fri, Apr 10, 2020 at 09:24:31PM +0200, Caspar Schutijser wrote: > > Below is a WIP diff that makes font fingerprinting defense work in > > our port of Tor Browser. > > Thanks for your feedback from both of you. I incorporated sthen@'s > feedback

Re: Tor Browser font fingerprinting defense

2020-04-12 Thread Caspar Schutijser
On Fri, Apr 10, 2020 at 09:24:31PM +0200, Caspar Schutijser wrote: > Below is a WIP diff that makes font fingerprinting defense work in > our port of Tor Browser. Thanks for your feedback from both of you. I incorporated sthen@'s feedback in the diff below (and besides that there's some fixes and

Re: Tor Browser font fingerprinting defense

2020-04-10 Thread Stuart Henderson
On 2020/04/10 21:24, Caspar Schutijser wrote: > Ports-wise, it looks a bit silly. And also, since this extra distfile > does not end up in WRKSRC, it is not straightforward to patch > fonts.conf, which we need to do (for now I use sed -i in the > post-install target). > > ports@, do you have any

Re: Tor Browser font fingerprinting defense

2020-04-10 Thread Theo de Raadt
Caspar Schutijser wrote: > p.s. This makes me wonder whether there are other features that don't > work on OpenBSD.. I'm planning to look into that at some point. In the > meantime, should we warn users about this? Warn the software comes without a warranty? Or any actual claim that it

Tor Browser font fingerprinting defense

2020-04-10 Thread Caspar Schutijser
Hi, On Sat, Mar 14, 2020 at 11:45:13AM -, Bronze Alibi wrote: > (tested on current with the provided package and nothing else installed) > > It looks like the Font > fingerprinting defenses from upstream don't work in the OpenBSD