The User-Agent and Accept headers gave me a unique fingerprint on 
https://panopticlick.eff org/. 

They should be set to the same as the Tor Browser. There's no point in 
identifying the client as a mobile user if you seek anonymity; and the 
User-Agent is the one most basic way to track browsers besides IP addresses. 

The Accept headers are plain and simple leaked from the device. 

Could easily pass as a honest mistake if this issue had not already been 
reported 2 years ago about Orweb. 
-- 
tor-talk mailing list - [email protected]
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

Reply via email to