FingerprintJS Same Fingerprint on Whonix, Mullvad - VPN and Mullvad - Tor

This is strange. New installed Whonix gives same fingerprint on FingerprintJS Demo to a different Template / DVM, with a different OS with standard Mullvad Browser going through a VPN and also the same fingerprint as another different OS with Mullvad-Browser through Tor. All 3 the same fingerprint.

I restarted (the whole laptop) and got the same fingerprint as before. I tried a new identity in Whonix, and still got the same fingerprint.
However Shard browser was giving different ones.

How can this be?

Changing security slide to safer. Gives a different fingerprint (it wont work on safest).

But closing that disposable, starting a new one and setting slider to safer, gives the same fingerprint (the second one) as before. (so no matter how many restarts there are 2 recurring fingerprints.)

But using the standard ‘Work’ VM through sys-whonix gives a different fingerprint.

Whonix was installed with the qubes-os installer just recently and has not been altered so this should be reproducible. (but also how can it be the same on all 3 different Browsers with different OS’s?) Unless its something else?

  • DispVM01 Firefox connected to whonix
  • DispVM02 Firefox connected to vpn01 (stays to run another browser inside)
  • DispVM02 Wayfern connected to vpn01

All have different visitor identifier

DispVM03 Firefox connected to vpn01 - same visitor identifier as DispVM02 Firefox.
DispVM04 Firefox connected to vpn02 - same visitor identifier as DispVM02 and DispVM03 Firefox
They use same template.

Thanks, for me its Whonix-workstation-18-dvm →sys-whonix (dispxxxx) → Same Identifier (even after reboot, new identity etc..)

Mullvad-browser-dvm (different OS)→ VPN → Same Identifier

Mullvad-browser-dvm2 → TorVM (not sys-whonix) Same Identifier.

(all 3 the same identifier) How could 3 different disp browsers based on different templates with different networking give the same identifier?

Whonix-worksation-18-dvm with setting safer → Identifier 2

New Identity or reboot with Whonix setting safer → Identifier 2 (same)

Work → sys-whonix → Different Identifier

Shard → VPN → Different Identifier

I’m guessing purely on the qube names, as you havent provided enough
information.

MullvadBrowser is based on Tor Browser, so you are running 3 instances
of TorBrowser with Javascript enabled. It’s not surprising that they
have the same fingerprint, is it? That’s the point .

If you were to run vanilla firefox in Mullvad-browser-dvm I am sure you
would see a different identifier. Instructive to identify what the
differences are, and what similarities are disclosed.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

2 Likes

Thanks @unman

I had thought of that until I read whonix’s documentation:

http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Browser_Tests#Fingerprint.com

The Fingerprint.com Demo (formerly FingerprintJS) (on GitHub) is a particularly important test, since “12% of the largest 500 websites use Fingerprint.com”. Through use of browser fingerprinting, fingerprint.com attempts to assign a unique identifier to the user that is similar to an IP address. Fingerprint.com refers to that unique identifier as visitorID.

Using Tor Browser’s new identity function results in a different browser fingerprint. Fingerprint.com will detect a different visitorID. The same applies after restarting Tor Browser.

Fortunately, fingerprint.com is unable to assign the same visitorID to different instances of Tor Browser running in different Whonix-Workstation™. In other words, when using multiple Whonix-Workstation™, fingerprint.com fails to correlate them to the same pseudonym. This benefits users who wish to avoid tracking.

Ah I see now, there is a difference between fingerprint.com and fingerprintjs…

I think there is.

Open Tor Browser in a Whonix disposable, and generate a fingerprint.
Use new identity, and then check again.
If the fingerprints are different, compare them and report back the
difference.
Run Mullvad Browser in a disposable, and generate a fingerprint.
Compare that against the first two.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

Yes, fingerprintjs gives the same in all 3 (Tor-browser whonix, Mullvad Debian and Mullvad on Devuan) New Identity gives the same Id (changes nothing). Fingerprint.com however gives different ID’s for all of them. I even installed foxyproxy on one of the mullvad browser dvms and set a random proxy and still got the same fingerprint (as the other 3). If you are correct @unman then everyone using Mullvad or Tor-browser should have the same fingerprint. So I fired up another laptop (Artix, same kind of laptop and screen res etc) and started tor-browser and got a completely different fingerprint (which persists no matter a reboot or ‘new-identity’). Yes fingerprint.com gives different Visitor ID’s but this seems to be something else.

Seems Joanna may have had similar results on this thread?: 9dc122

Test 2: This one is more concerning. I tested Tor browser (only change I made was setting it to safest) on both an intel based mac and on fedora and the fingerprints were different and constant to each device (as in the remained the same upon browser restart). They are able to differentiate firefox on mac vs firefox on others platforms so that was how they fingerprinted me. This is extremely concerning, I wonder if other macs with different hardware would provide the same fingerprint or not. Based on the parameters they use probably not.

How is it correlating all 3 browsers then?
@unman can you recommend a good canvas spoofer I could install in one of the mullvads) so I may try to see if that makes any difference to my tests? I remind you that it is the same fingerprint showing up despite reboots or as it seems now, even adding different FF extentions.

This should be concerning if a Fingerprint was unique to every users machine despite peoples extensions, proxies, VPN’s Tor or Tor-Browser! If everyone everywhere had the same fingerprint I could understand, but this does not seem to be the case.

Also I have tried giving them different themes etc. Same result. Same ID. If the Javascript is changed to Safer it gives a different result but that one also persists.

If anyone is trying to repeat this test it may help that the Visitor identifier across all of them Mullvad-debian-vpn Mullvad-devuan-torVM and Whonix-Sys-whonix) with Javascript set to standard for me begins with 749b95…..

Similarites - Mullvad browser, Tor Browser (same base), all qubes dvms, all with noscript all with standard javascript setting.

Differences: Themes, Tor browser set to Dark, Mullvad has FoxyProxy installed, all 3 are based on different templates and OS’s (Whonix, Debian and Devuan) all 3 have different networking. Whonix-sys-whonix, Debian-VPN and and Devuan-TorVM. I tried all of them through sys-net, or putting sys-whonix through a vpn, different firewalls (mirage and sys-firewall) Same result. Same ID.

Another test. → re-installing fresh the tor -browser on Whonix template. Gives same ID.

related: Good News - Testing Tor Browser DispVMs Against New fingerprint.js Browser Fingerprinting where you wrote: For another reference point:
A standard Debian Firefox with NoScript and CanvasDefender -
As @Sven says, NoScript blocks completely.
Allowing Scripts, using the same Canvas, through Tor, tends to give (on limited testing) the
same fingerprint between qubes.
Allowing Scripts, using a different Canvas, through Tor, tends not to give (on limited testing) the
same fingerprint between qubes.

So then, is the solution to add a canvas hasher to all 3? Which then would violate the statements of whonix and tor to not add extensions as it may make you unique? I am confused! :zany_face: