# Sam Bent: Tor Browser’s Latest Update Could Get You Fingerprinted

**URL:** https://discuss.privacyguides.net/t/sam-bent-tor-browser-s-latest-update-could-get-you-fingerprinted/26973
**Category:** Questions
**Created:** 2025-04-23T18:03:09Z
**Posts:** 44

## Post 1 by @bitsondatadev — 2025-04-23T18:03:09Z

> **[Tor Browser’s Latest Update Could Get You Fingerprinted...](https://www.youtube.com/watch?v=Ml99dXffRXk)**
>
> In this video, I explain a major shift in the Tor Browser’s privacy architecture and why it’s a serious problem for anyone who values anonymity. With the rel...

Spoiler: The change is [the removal of OS Spoofing](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43189) in HTTP header.

Tor 14.5 Release Notes: [New Release: Tor Browser 14.5 | The Tor Project](https://blog.torproject.org/new-release-tor-browser-145/)  
Related Issues: [1](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43170), [2](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43653)

I’ve generally been a fan of Sam Bent’s takes, though not all (e.g. I use VPN and Tor when in using identities with higher threat models but he isn’t a fan for reasons I won’t get into but disagree with).

That said, I’d like to do a vibe check on this one with the community and specifically anyone who might know a plausible explanation for why the Tor project made this move.

Update: Perhaps this [linked Issue](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42439) is part of addressing a compatibility bug but requires the removal of defaults. Looks like [you still can set it to the previous functionality](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42467) if compatibility wasn’t a problem. Sam argues this goes against the conventional design approach of (don’t touch the settings).

I’m only guessing here from titles since the Tor project doesn’t do much explaining on these issues/PRs.

---

## Post 2 by @fdb_hiroshima — 2025-04-23T18:15:32Z

I see why he is getting worried, but he’s missing what the change actually is. Before, js and http headers were reporting different user agents, now they are reporting the same, with the OS taken from a list of [4 possible values](https://gitlab.torproject.org/tpo/applications/tor-browser/-/blob/tor-browser-128.10.0esr-14.5-1/toolkit/components/resistfingerprinting/nsRFPService.h?ref_type=heads#L33) (the part he’s missing). So all the QubeOS, OpenBSD and exotic distro getting trivially fingerprinting, that’s not actually right. All Windows are W10, all Android are Android 10, all MacOS are OS X 10.15, and everything else (including BSD) is a Linux running X11.

---

## Post 3 by @anonymous261 — 2025-04-23T18:19:23Z

Does that mean if one forced Tor Browser to use Wayland on Linux for the sake of security, they wouldn’t stand out?

---

## Post 4 by @fdb_hiroshima — 2025-04-23T18:20:52Z

before, that would show as Windows 10 in the headers, and Linux with X11 in javascript (assuming js is enabled), now that would be Linux with X11 for both.

---

## Post 5 by @jonah — 2025-04-23T19:25:00Z

YouTubers not understanding browser fingerprinting (among many, many other things) is a scourge in the privacy space. Thorin is perhaps **the** expert when it comes to browser fingerprinting, and Bent doesn’t even know his name in this video.

Around 6:34 Bent’s claim that Tor developers wanting to encourage consistency is “in no way […] some kind of security argument” is beyond ridiculous, when consistency is the **entire** point of the Tor Browser. Giving “experienced users” (8:42) the option to decide what they want to do in this situation would place them in significant danger because their spoofing would ensure their browser is no longer aligned with anyone else’s.

The operating system is essentially **always** detectable in Tor Browser. Even with JS disabled, you can detect it through CSS, it’s impossible to solve unless you completely break websites in the process. If this guy had his way then there would be “experienced users” on Linux spoofing their user agent to look like Windows, meaning that malicious website operators could narrow down on them as the only people in the Tor ecosystem on Linux (because again, it’s detectable!) with a Windows user agent.

Anyways, I will +1 @fdb_hiroshima’s response above. This change does not meaningfully impact fingerprinting in Tor Browser, don’t let random internet creators tell you otherwise.

---

## Post 6 by @bitsondatadev — 2025-04-23T19:27:47Z

This is why I donate to community forums. Challenging this type of info can be difficult with lack of time and huge learning curve it would take for me to grasp the intricacies of finger printing to refute one way or the other. At some level we need forums like these to crop up around many different areas of expertise to provide fact-checking consensus on potential populist hype preaching.

Pluralism \> Populism \>= Elitism \> Totalitarianism

---

## Post 8 by @TorProject — 2025-04-23T19:58:58Z

Regarding the well-meaning, but inaccurate claims in the video, we’re offering this clarification on how user agent protection works in Tor Browser. To support informed discussion, here’s what actually changed, and what hasn’t changed.

We are still protecting user agents: Tor Browser has always limited user agents to general categories: Windows, macOS, Linux, or Android in JavaScript, and Windows or Android in HTTP Headers. That means we spoof the OS version and architecture, which was always the approach in JavaScript–now it’s consistent in HTTP headers too.

Any OS info shown in the user agent does not expose any new information that wasn’t already present with JavaScript. With JavaScript disabled, entropy is already greatly reduced (self-information: e.g. the thousands of JavaScript derived metrics) and even without this change, passive methods have always existed to determine the platform. In fact, asymmetric user agent spoofing triggered anti-fraud and bot-detection scripts breaking websites without added privacy benefits.

Proposals for this change were introduced in September 2024 with

the Tor Browser 14.0a4 release, calling on the Tor community to provide feedback. We received very little feedback and implemented the change.

Tor Browser still offers one of the strongest privacy and anonymity protections for web browsing.

---

## Post 11 by @jonah — 2025-04-23T20:25:52Z

> [@TorProject](#):
>
> In fact, asymmetric user agent spoofing triggered anti-fraud and bot-detection scripts breaking websites without added privacy benefits.

So do you think the risk of this happening (which this change now prevents) is greater than the risk posed by HTTP user agent strings being stored by most standard webserver access logs?

I would agree it probably is, for the record, but I didn’t find conversations where that discussion was actually resolved, and I can see why people who browse in Safest mode could be concerned.

---

## Post 12 by @bitsondatadev — 2025-04-23T22:02:19Z

Damn, I feel honored the team took some time to reach out on this!

First post by Tor project in the community!

Y’all are the best! :sparkling_heart:

---

## Post 17 by @ihateKYC — 2025-04-25T00:12:13Z

I love the idea of TOR but it is way too targeted to use comfortably.

---

## Post 19 by @bitsondatadev — 2025-04-25T01:25:55Z

Depending on who you are concerned about. I live in the US and use it with little issue with my ISP seeing I use Tor. I VPN to my house when I’m in public so same thing. The US only has two ISPs and they both report to our gov.

I think it’s usage is becoming more common based on hearsay but no metrics.

That said, if you don’t want your ISP or public networks to know you’re Torin it up, then use Mullvad VPN.

---

## Post 20 by @jonah — 2025-04-25T02:37:13Z

> [@bitsondatadev](#):
>
> The US only has two ISPs

:thinking: how so?

---

## Post 21 by @anon39279085 — 2025-04-25T07:04:37Z

I swear I know in the US we have 3 ISPs no?  
maybe a little bit more than that if I dont know anything outside of AT&T, Verizon and T-Mobile.

---

## Post 22 by @Eebzter — 2025-04-25T07:15:29Z

There is far more than that. There are major ones everyone knows like At&t, Hughs, Xfinity, Verizon, T-Mobile, spectrum and Cricket.

According to a quick web search it shows closer to 3000 (far more than i even thought)

[The United States Internet Service Provider Directory - InMyArea.com](https://www.inmyarea.com/provider#:~:text=Nearly%203%2C000%20internet%20service%20providers,provide%20multiple%20internet%20connection%20types.)

---

## Post 23 by @nahme — 2025-04-25T13:20:22Z

> [@TorProject](#):
>
> **passive methods have always existed to determine the platform**. In fact, asymmetric user agent spoofing triggered anti-fraud and bot-detection scripts breaking websites without added privacy benefits.

This should be obvious knowledge to anyone who looked into the specifics of for example how Arkenfox worked in the past. As such, of course this change does not make anything worse, the opposite rather.

---

## Post 24 by @jonah — 2025-04-25T14:01:47Z

Oh, mobile carriers, yeah that is true (well, there’s 5 because US Cellular and Boost have their own towers, and 6 if you count Starlink).

When I hear ISPs I think of traditional residential ISPs. There are a lot more individual fiber operators in the US (at least [9](https://en.wikipedia.org/wiki/Tier_1_network#List_of_Tier_1_networks) that are nationwide, and thousands+ on a local level).

---

## Post 25 by @bitsondatadev — 2025-04-28T12:43:01Z

I meant to say this tongue in cheek sorry y’all.

The US has _like_ two feasible or commonly used ISPs depending on where you live (at least in my experience) you have the option of DSL speeds or Xfinity for instance in the suburbs of Chicago.

Its better as you get closer or in cities.

My point regardless was to say all the info bubbles up to the same spy shack and rarely do they stop you from using Tor and I want to normalize its use.

---

## Post 26 by @Marvin — 2025-05-04T20:11:25Z

Hello all,  
I saw a post pertaining to this topic back in November 2024, but unfortunately, I didn’t see any helpful solutions.  
Sam Bent just posted a video about this situation on his Youtube channel. In the comments on the video, he got into a big argument with a Tor Project developer.  
Sam’s suggestion is to use Tails or Whonix, rather than the Tor Browser, and to use the “safest” setting. But it still appears that the user is using Linux and not Windows (as was the result before this change), which makes fingerprinting easier.  
Sam also suggested the possibility of rolling back the Tor Browser to version 14.0, and re-enabling spoofing. (That would be tough for newbies like me).  
Does anyone have some ideas for this situation? Thanks in advance.

---

## Post 27 by @anon80779245 — 2025-05-04T20:13:42Z

No, don’t rollback. I don’t like the new change (they should have spoofed js and htps headers instead) but for security-sensitive apps you don’t want to be on an outdated version.

---

## Post 28 by @Marvin — 2025-05-04T20:24:03Z

Thanks very much, Encounter. I moved the control to the “safest” setting, then tested it with the EFF’s “cover my tracks” site. It said that because java script had been disabled, many other attack surfaces were unusable. So that was at least a good thing.

---

## Post 29 by @Marvin — 2025-05-04T20:40:30Z

Maybe the better option is to use 3 chained VPNs from different providers? (One on a VPN router, the second on the host operating system, and the third on the guest operating system).

---

## Post 30 by @nahme — 2025-05-05T00:00:51Z

While the EFF website is good for some basic education, don’t mistake it for a comprehensive tool that compares to the actual capabilities of tracking companies.

And chaining VPNs as an alternative to Tor? I guess depending on your threat model it could be an alternative for someone, but talking about a general case then no, these two things just aren’t alike. (Any decent OS will allow you to chain any number of VPN connections without the workarounds you mentioned btw.)

Last thing I want to say on the actual topic of this thread: If you ever find yourself in a similar argument with literally Tor developers, take a step back and consider that there might be some things that you don’t yet have a full picture understanding of… nuff said.

---

## Post 31 by @ihateKYC — 2025-05-05T02:00:52Z

I’d rather remotely connect to a rented server so i don’t have to worry about vm escape vulnerabilities.

---

## Post 32 by @JohnDose — 2025-05-05T09:19:40Z

> (Any decent OS will allow you to chain any number of VPN connections without the workarounds you mentioned btw.)

May I ask how to chain VPNs on, for example, Windows? The only way I know is to use a virtual machine.

---

## Post 33 by @Marvin — 2025-05-05T14:08:48Z

Thanks, Jonah. Sam Bent gave a good reply to the TorProject on his recent video.

---

## Post 34 by @Marvin — 2025-05-05T14:11:45Z

Sorry, but I only know about Linux. GL-iNet makes VPN routers. That would be the first VPN. Then the host OS would be yoour second VPN. Then launch the virtual machine, and that would be the third VPN.

---

## Post 35 by @Marvin — 2025-05-05T14:12:23Z

Thanks for the explanation, Nahme.

---

## Post 36 by @asanyan — 2025-05-06T01:50:29Z

Any chance that this feature could be re-enabled for safest, as it does worsen privacy with javascript disabled?

---

## Post 37 by @nahme — 2025-05-08T16:49:57Z

“any decent OS” is what I said so no idea about Windows. In Linux what I would do is just use multiple network namespaces and chain them, can run Wireguard in each of them.

---

## Post 38 by @TheDoc — 2025-05-08T20:04:40Z

> [@Marvin](#):
>
> Sam also suggested the possibility of rolling back the Tor Browser to version 14.0, and re-enabling spoofing.

I watched both of his recent videos on Tor and Sam Bent gets plenty of technical info wrong and makes plenty of terrible suggestions. I didn’t remember him suggesting to roll back the Tor Browser but if he actually did, that should be the nail in the coffin for his reputation regarding anything related to cybersecurity. Definitely don’t take his advice or commentary on it seriously. It’s best he stick to covering DNM news.

---

## Post 39 by @privacy4all — 2025-07-20T07:22:15Z

> [@jonah](#):
>
> Even with JS disabled, you can detect it through CSS,

I’ve searched. I don’t think it’s possible to detect the operating system using pure CSS only. Please show how that’s possible.

---

## Post 40 by @Niek-de-Wilde — 2025-07-20T09:22:14Z

[https://archive.is/DEyT7](https://archive.is/DEyT7)

First google result. There are quite a few things one a can do with CSS.

---

## Post 41 by @privacy4all — 2025-07-20T09:37:09Z

There’s also [GitHub - OliverBrotchie/CSS-Fingerprint: Pure CSS device fingerprinting.](https://github.com/OliverBrotchie/CSS-Fingerprint?tab=readme-ov-file#os-and-browser-detection) which is similar operating system detection based on fonts.

But this not applicable to Tor Browser because Tor Browser normalizes fonts. It ships its own limited list of fonts. It doesn’t use operating system fonts.

In conclusion, CSS based OS detection against Tor Browser won’t work.

---

## Post 42 by @Niek-de-Wilde — 2025-07-20T09:38:34Z

“This one specfic method does not work, therefor I can write off and entire class of bugs.” Oh how I wish it was that simple.

P.s., do not move goal posts, you were talking about whether its possible at all, not just for tor browser.

---

## Post 43 by @fria — 2025-07-20T10:24:02Z

> Overall, out of the 1176 combinations in our evaluation, we can distinguish 1152 of them (i.e., 97.95%). The combination of our novel techniques can generally distinguish all operating systems included in our evaluation, including the Tor browser with NoScript, both configured to the highest security level.

> **[2025-s238-paper.pdf](https://www.ndss-symposium.org/wp-content/uploads/2025-s238-paper.pdf)**
>
> 723.33 KB

Interesting paper I found. Seems CSS fingerprinting is very much a thing and it can differentiate between operating systems and not just through installed fonts. I reckon the only reason it’s not more developed by now is that most people (including Tor browser users) have JavaScript enabled and that’s a goldmine of fingerprinting.

---

## Post 44 by @privacy4all — 2025-07-20T13:09:48Z

> [@Niek-de-Wilde](#):
>
> P.s., do not move goal posts, you were talking about whether its possible at all, not just for tor browser.

This discussion isn’t happening without context. The context was operating system spoofing removal for Tor Browser.

> [@Niek-de-Wilde](#):
>
> “This one specfic method does not work, therefor I can write off and entire class of bugs.” Oh how I wish it was that simple.

I wasn’t aware there’s a class of attacks.

> [@fria](#):
>
> Interesting paper I found.

Thank you.

So there’s fonts which Tor Browser mitigates and the paper helped to fix related bug in Tor Browser.

And there’s CSS calc to detect the operating system. Here’s their proof of concept that I haven’t tried.

> <https://github.com/cispa/cascading-spy-sheets/blob/ecad63da6802c7714dfefbf6290b1fade2fbd833/pocs/browser/poc_firefox.html>

I’d hope these bugs could be fixed instead of giving up on OS spoofing entirely.

---

## Post 45 by @jonah — 2025-07-23T05:56:57Z

18 posts were merged into an existing topic: [Accuracy of Sam Bent video criticizing TOR (and PrivacyGuides) on HTTP Header OS spoofing removal?](/t/accuracy-of-sam-bent-video-criticizing-tor-and-privacyguides-on-http-header-os-spoofing-removal/29136/32)
