I just want to retract this one thing: I previously thought that JavaScript was being disabled in private browsing mode, but it isn't. It's just that some kind of bug in LibreJS causes the icon to not show up in private browsing mode, and it currently tends to block most scripts, so it gives that impression. With scripts enabled, the fingerprint isn't entirely unique, but not even remotely generic.

I think IceCat should do what I previously thought it did: disable scripts in private browsing mode. Otherwise, this has a potential to create a false sense of security.

Reply via email to