Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
vi
HomeCategoriesArcadeBookmarks
Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
Privacy|Terms

© 2026 Coding4Food. Written by devs, for devs.

All news
TechnologyIT Drama

Tor Privacy Busted: How Firefox IndexedDB Leaked Your Anonymous Identities

April 23, 20263 min read

A massive vulnerability in Firefox's IndexedDB just shattered Tor's privacy promises. Dive into the Hacker News drama, the tech breakdown, and dev takeaways.

Share this post:
fingerprint, security, privacy policy, protect, computer, password, pc, trojan, protection, data theft, hacker, data, trojan password, fingerprint, fingerprint, fingerprint, fingerprint, fingerprint, security, privacy policy, privacy policy, privacy policy, privacy policy, privacy policy, password, data theft, hacker
Nguồn gốc: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leakNguồn gốc: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak
Nguồn gốc: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leakNguồn gốc: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/tor-privacy-busted-firefox-indexeddb-leak
tor browserfirefoxindexeddbhacker newslỗ hổng bảo mậtbrowser fingerprinting
Share this post:

Bình luận

Related posts

cybersecurity, palm print, data security, firewall, hacker, malware, ransomware, hacking, cybersecurity, cybersecurity, cybersecurity, cybersecurity, cybersecurity, ransomware, ransomware, ransomware, ransomware
TechnologyDev Life

1-Click and Your GitHub Token is Gone: The Latest VSCode Nightmare

One misplaced click and your GitHub token saved in VSCode could be yeeted to an attacker. Let's break down the massive security drama trending on Hacker News.

Jun 33 min read
Read more →
lumber, lumberjack, axe, beard, forest, job, profession, tree, wood, woodcutter, man, person, strong, nature, male
GamingTechnology

The ASMR Firewood Splitting Simulator is the Ultimate Dev Procrastination Tool

Discover the incredibly satisfying Firewood Splitting Simulator that's taking over Hacker News. Put down your IDE and start chopping virtual wood.

Jun 152 min read
Read more →
ai generated, cloud computing, mining, gpu, server, blockchain, artificial intelligence, machine learning, data center, gpu, gpu, data center, data center, data center, data center, data center
TechnologyAI & Automation

Claude Fable 5 Dropped: Legit Next-Gen Tech or Just Another Benchmark Flex?

Anthropic quietly dropped the System Card for Claude Fable 5, scoring over 2100 points on Hacker News. Is this the AGI moment or just pure marketing?

Jun 103 min read
Read more →
laptop, hands, gadgets, iphone, apple, lens, macbook, mobile phone, smartphone, typing, blogging, flat lay, workspace, laptop, laptop, typing, typing, typing, typing, typing, blogging, blogging, blogging
TechnologyDev Life

Social Media is Dead, Long Live the Feed: How Algorithms Killed Our Friendships

Remember when social media was actually about friends and not just brain-melting algorithmic fads? Here is how the 'social' part got brutally murdered.

Jun 93 min read
Read more →
code, coding, computer, data, developing, development, ethernet, html, programmer, programming, screen, software, technology, work, code, code, coding, coding, coding, coding, coding, computer, computer, computer, computer, data, programming, programming, programming, software, software, technology, technology, technology, technology
Dev LifeIT Drama

"LLMs Are Eating My Career" - A Dev's Existential Crisis on Hacker News

A trending Hacker News post reveals mid-career panic as devs feel LLMs are taking over. Are AI tools ending software engineering or just evolving it?

Jun 73 min read
Read more →
computer, technology, future, robot, light, futuristic, woman, room, hacker, security, code, cyber, coding, matrix, hacking, programming, digital, network, ai generated, coding, coding, hacking, hacking, hacking, programming, programming, programming, programming, programming
AI & AutomationTechnology

The GenAI 'Oh Sh*t' Moments: From Parlor Tricks to Sweating Bullets

Remember when we laughed at AI drawing 7 fingers? Read the Hacker News thread where senior devs reveal the exact moment AI made them question their careers.

Jun 73 min read
Read more →

What's up, fellow code monkeys? Just when you thought you could browse the dark web in peace or stash some cryptocurrency without the feds snooping, Tor gets slapped with a massive privacy reality check. A recent post exploded on Hacker News (hitting a massive 829 score), revealing that Tor's holy grail of anonymity has a gigantic leak. Grab your coffee, let's dissect this dumpster fire.

How the Cookie... I mean, IndexedDB Crumbles

The drama started when Fingerprint.com—a company that literally sells browser fingerprinting solutions—dropped a tactical nuke on the privacy community. They discovered a stable identifier vulnerability utilizing the IndexedDB API in Firefox.

Here is the kicker: Tor Browser is essentially Firefox wearing a trench coat. When you click "New Identity" or request a new Tor circuit, you expect to be reborn as a completely new, untraceable user. But nope! Because Firefox failed to properly isolate and clear the IndexedDB state across different private sessions, this stable ID persists.

It links all your pristine, supposedly isolated anonymous identities into one neat little profile. It's like putting on an invisibility cloak but forgetting to take off your GPS-enabled smart shoes.

Hacker News Goes Full Panic Mode

The HN comment section turned into an absolute warzone:

  • The Blamers: Pointing fingers directly at Mozilla. Devs are furious that modern browsers keep cramming bloated Web APIs (like IndexedDB, WebGL) into the core. More features mean a massive attack surface, effectively killing true privacy.
  • The Purists: The grey-beard sysadmins chimed in with a collective "I told you so." Their logic? If you browse Tor with JavaScript enabled, you're asking to be tracked. Disabling JS via NoScript prevents this exploit, but it also breaks 99% of the modern web. Choose your poison.
  • The Skeptics: Laughing at the sheer irony of a fingerprinting company reporting a fingerprinting bug. "Task failed successfully?" Still, most agreed that a disclosed bug is better than a zero-day sold to the highest bidder.

The Coding4Food Takeaway: State Isolation is Hard

There is no silver bullet for online privacy. Trusting a single tool to protect you is like trusting a PM who says "there will be no scope creep." Pure fiction.

For the dev folks in the room: If you're messing with client-side storage (LocalStorage, IndexedDB), pay damn good attention to isolation and lifecycle management. State leaking isn't just a backend database problem; it happens right in the browser. Leaking a user's state across sessions is a massive YIKES.

If you were doing anything highly sensitive on Tor recently... well, good luck out there. If you just need to scrape data anonymously without the Tor drama, maybe just invest in a proper Proxy to unlock limitless web data collection instead.


Source: Fingerprint.com Blog