[guardian-dev] Possible Orbot/orweb deanonymization - verizon supercookie

PaulD dietricp at efn.org
Mon Jan 26 13:58:32 EST 2015

I have reason to believe that it is possible to deanonymize an orbot
user using the verizon supercookie. Possibly other "supercookies" as well.

Provided that:
 (a) the phone is communicating on mobile data, not wifi
 (b) user visits an http page (not https)
 (c) no other anonymity tools such as vpns stand in the way.

Unclear whether root permissions matter. My phone is NOT rooted.

My sample size is really small. just my phone. With that said, it seems
that it is possible to deanonymize a pretty big chunk of tor users,
without serious effort.

The bottom line is that I visited the "do you have the verizon
Supercookie" website with orweb, and it appears that I do.

