• JetpackJackson@feddit.org
    link
    fedilink
    arrow-up
    10
    ·
    3 days ago

    But if you’ve logged in to an account before on the regular web, then you can still be tracked because theres that connection between clearnet you and Tor you right? Or am I making stuff up

    • mnemonicmonkeys@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 days ago

      For that particular site.

      But the big thing about using Tor for normal things is that doing so helps to obfuscate traffic that governments want to track by surrounding it with “legitimate” traffic

    • Cethin@lemmy.zip
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 days ago

      Yes, you’re correct. If you want to be hidden you need to only log into accounts that you’ve only accessed through TOR. IIRC, TOR actually tells you this when you open it for the first time, or at least it used to. It also tells you things like to not resize the window, because window size is a fingerprint that can be used to identify you. You shouldn’t full-screen or resize it. There’s a lot of ways to identify people that they don’t even think about.

    • Vincent@feddit.nl
      link
      fedilink
      arrow-up
      9
      ·
      3 days ago

      Sort of, as in, the site you’re logging into will know that you’re the same person. Obviously if it’s something like Lemmy, if you post public comments then everybody else will see that it’s the same person posting them. It used to be the case that your exit node could also see quite a bit of what you were viewing, which can indeed often be linked to things you did outside of Tor, unless the website you’re connecting to was using HTTPS. Nowadays, practically every website does that, so you should be good.

      That said, I am not a security person, so if you’re a journalist protecting their sources or otherwise have a serious threat model, seek expert advice.

        • Vincent@feddit.nl
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          Presumably, if you log in to a site, you want it to know who you are, so I think that’s fine. (Where “who you are” means “that whatever you do while logged in is being done by the same person as who did other things when logged in outside of Tor”.) So no, I don’t think you need to limit it to stuff you don’t have logins for. I’d only make sure to not login/visit a site if Tor browser actively tells you that it’s insecure (which it does when a site doesn’t use HTTPS), which is pretty obvious.