We found a stable Firefox identifier linking all your private Tor identities

A critical privacy vulnerability in Firefox and Tor Browser allows websites to create stable, persistent identifiers linking user activity across origins by exploiting the non-random ordering of IndexedDB database results, defeating the core privacy protections users expect from private browsing modes. This process-level fingerprinting technique persists even through Tor Browser's "New Identity" feature and private session resets, representing a fundamental breach of isolation guarantees that impacts user trust in privacy-focused tools. Mozilla has patched the issue in Firefox 150, but IT organizations must ensure rapid deployment across all Firefox-based deployments and verify compliance, particularly for enterprises supporting privacy-sensitive users or regulated use cases.

Hacker News3 min read
Read full article
We found a stable Firefox identifier linking all your private Tor identities
A critical privacy vulnerability in Firefox and Tor Browser allows websites to create stable, persistent identifiers linking user activity across origins by exploiting the non-random ordering of IndexedDB database results, defeating the core privacy protections users expect from private browsing modes. This process-level fingerprinting technique persists even through Tor Browser's "New Identity" feature and private session resets, representing a fundamental breach of isolation guarantees that impacts user trust in privacy-focused tools. Mozilla has patched the issue in Firefox 150, but IT organizations must ensure rapid deployment across all Firefox-based deployments and verify compliance, particularly for enterprises supporting privacy-sensitive users or regulated use cases.