Accuracy of Sam Bent video criticizing TOR (and PrivacyGuides) on HTTP Header OS spoofing removal?

They do still spoof your user agent like they always have, they just don’t let you choose which operating system you’re appearing to be.

It does not make sense to allow users to choose this, because any change like this would make you appear significantly more unique. Yes, you can certainly argue that standardizing on Windows for all Safest mode users might make sense, @TorProject did not answer my question asking about that, so I do not know what their specific reason for not doing that is.

What I do know is that the actual increase in entropy here is so insignificant that it does not make a difference for the end user either way, which is why I’m not going to hound Tor Project for an answer or drama-post about them “gaslighting” their users, even though I am indeed curious. Your operating system is simply not an identifying trait, there’s only like 4 of them.

It is a significantly higher danger to include a function that promises some privacy benefit while being unable to deliver it in all contexts, than it is to not have that function in the first place. It creates a false sense of privacy/security that will land people in serious danger, which is why whether it is “easy to fingerprint” is not relevant.

At the end of the day, the Tor Project clearly believes they are unable to completely hide what OS you are using, and as a result they made the (IMHO) correct decision to not pretend like they sometimes can. I am confident that if they did believe they could spoof any OS to look like Windows then they would do so.


YouTubers like Sam Bent are of course financially incentivized to drum up drama (because calling out Tor Project gets clicks) and position themselves as the One True Source of educational information about privacy by promoting uncertainty about other educational sources like Privacy Guides.

Since we lack those incentives, we prefer to focus on the real mountains of privacy problems out there rather than closely inspect every proverbial molehill of a problem that shows up in projects like Tor.

12 Likes