<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mikeperry</id>
	<title>MozillaWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mikeperry"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/Special:Contributions/Mikeperry"/>
	<updated>2026-09-11T21:14:22Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=318030</id>
		<title>Talk:Privacy/Roadmap 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=318030"/>
		<updated>2011-06-13T01:15:39Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Deploy Safe and Rational Defaults */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Improve Private &amp;amp; Semi-anonymous Browsing ===&lt;br /&gt;
&lt;br /&gt;
I think per-tab private mode is likely to be confusing. I think the more intuitive way to provide this linkability improvement is by isolating the browser state for a given top-level urlbar domain (ie the double-keying Cookie idea but applied to cache, DOM Storage, client certs, etc).&lt;br /&gt;
&lt;br /&gt;
OTOH, the ability to have a per-window private mode, or perhaps even just a single concurrent private mode consisting of many windows may make sense. For example, I think Chrome&#039;s Incognito Mode windows are very intuitive for this reason. I think it also does make sense to have all private browsing windows share the same virtual profile.&lt;br /&gt;
&lt;br /&gt;
On the third hand, the downside of concurrent use is that it makes the &amp;quot;I&#039;ll just go to the wifi cafe or tether my cell phone&amp;quot; use case more difficult. That user will end up linking themselves via all the activity in their previous tabs/windows.&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;br /&gt;
&lt;br /&gt;
=== Deploy Safe and Rational Defaults ===&lt;br /&gt;
&lt;br /&gt;
While I think that improving the referer situation is useful in some cases, it really doesn&#039;t do anything to stop bad actors. I think giving sites control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII themselves. Right now it simply is not possible for sites to restrict referer for many elements. Providing trickle-down restrictions via CSS or via an attribute of the html or body tag would be ideal.&lt;br /&gt;
&lt;br /&gt;
Perhaps the way to do this for private browsing mode is to create an attribute that says &amp;quot;Yes transmit referer&amp;quot;, and have referer disabled or restricted otherwise.&lt;br /&gt;
&lt;br /&gt;
After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317982</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317982"/>
		<updated>2011-06-12T04:16:20Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Interface and Options */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language. Further, dropping items from the UA string while only in Anonymous Browsing Mode would reveal the fact that the user is using the mode.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to simply pick a user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton.&lt;br /&gt;
&lt;br /&gt;
It should be noted that the Firefox minor revision and other properties can still be determined by inspecting Components.interfaces, so [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070] would need to be fixed for these protections to have any real value.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
Referer and querystring identifiers: {{bug|587523|Protect path of HTTP Referer Header when in a possible future anonymous mode}}&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Because of the issues with localization and finding a common set of default fonts, the best option here is probably to limit the number of local fonts a tab can load. Precedence can be given to remote font files so they do not count against this limit. Research should be performed to find the typical number of fonts loaded by the top 1000 sites and set the limit high enough not to break any of them.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset. Another possibility would be to simply bin the milliseconds to low resolution (250ms or so). Studies would need to be done to determine how effective either approach is.&lt;br /&gt;
&lt;br /&gt;
Additionally, interval timers and event timestamps would need reduced resolution, due to computational fingerprinting:&lt;br /&gt;
http://w2spconf.com/2011/papers/jspriv.pdf&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode. This is obviously a long-term strategy.&lt;br /&gt;
&lt;br /&gt;
Similarly, another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
Shorter-term, it may be best to leverage the permissions manager to disable all plugins by default. If an object tag or an access to window.plugins is detected, the chrome could ask the user if they would like to enable that plugin for that top-level domain only. Keeping plugin permissions isolated to the top-level urlbar domain would at least cut down on linkability between domains.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, in general it is best to minimize options that have an effect on browser behavior. Such options become fingerprintable attributes.&lt;br /&gt;
&lt;br /&gt;
However, visual and local preferences are still desirable. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317981</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317981"/>
		<updated>2011-06-12T04:06:44Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Plug-Ins */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language. Further, dropping items from the UA string while only in Anonymous Browsing Mode would reveal the fact that the user is using the mode.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to simply pick a user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton.&lt;br /&gt;
&lt;br /&gt;
It should be noted that the Firefox minor revision and other properties can still be determined by inspecting Components.interfaces, so [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070] would need to be fixed for these protections to have any real value.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
Referer and querystring identifiers: {{bug|587523|Protect path of HTTP Referer Header when in a possible future anonymous mode}}&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Because of the issues with localization and finding a common set of default fonts, the best option here is probably to limit the number of local fonts a tab can load. Precedence can be given to remote font files so they do not count against this limit. Research should be performed to find the typical number of fonts loaded by the top 1000 sites and set the limit high enough not to break any of them.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset. Another possibility would be to simply bin the milliseconds to low resolution (250ms or so). Studies would need to be done to determine how effective either approach is.&lt;br /&gt;
&lt;br /&gt;
Additionally, interval timers and event timestamps would need reduced resolution, due to computational fingerprinting:&lt;br /&gt;
http://w2spconf.com/2011/papers/jspriv.pdf&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode. This is obviously a long-term strategy.&lt;br /&gt;
&lt;br /&gt;
Similarly, another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
Shorter-term, it may be best to leverage the permissions manager to disable all plugins by default. If an object tag or an access to window.plugins is detected, the chrome could ask the user if they would like to enable that plugin for that top-level domain only. Keeping plugin permissions isolated to the top-level urlbar domain would at least cut down on linkability between domains.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317980</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317980"/>
		<updated>2011-06-12T03:54:09Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Clock Delta+Precision */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language. Further, dropping items from the UA string while only in Anonymous Browsing Mode would reveal the fact that the user is using the mode.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to simply pick a user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton.&lt;br /&gt;
&lt;br /&gt;
It should be noted that the Firefox minor revision and other properties can still be determined by inspecting Components.interfaces, so [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070] would need to be fixed for these protections to have any real value.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
Referer and querystring identifiers: {{bug|587523|Protect path of HTTP Referer Header when in a possible future anonymous mode}}&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Because of the issues with localization and finding a common set of default fonts, the best option here is probably to limit the number of local fonts a tab can load. Precedence can be given to remote font files so they do not count against this limit. Research should be performed to find the typical number of fonts loaded by the top 1000 sites and set the limit high enough not to break any of them.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset. Another possibility would be to simply bin the milliseconds to low resolution (250ms or so). Studies would need to be done to determine how effective either approach is.&lt;br /&gt;
&lt;br /&gt;
Additionally, interval timers and event timestamps would need reduced resolution, due to computational fingerprinting:&lt;br /&gt;
http://w2spconf.com/2011/papers/jspriv.pdf&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317979</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=317979"/>
		<updated>2011-06-12T03:47:35Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Fonts and Font Lists */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language. Further, dropping items from the UA string while only in Anonymous Browsing Mode would reveal the fact that the user is using the mode.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to simply pick a user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton.&lt;br /&gt;
&lt;br /&gt;
It should be noted that the Firefox minor revision and other properties can still be determined by inspecting Components.interfaces, so [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070] would need to be fixed for these protections to have any real value.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
Referer and querystring identifiers: {{bug|587523|Protect path of HTTP Referer Header when in a possible future anonymous mode}}&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Because of the issues with localization and finding a common set of default fonts, the best option here is probably to limit the number of local fonts a tab can load. Precedence can be given to remote font files so they do not count against this limit. Research should be performed to find the typical number of fonts loaded by the top 1000 sites and set the limit high enough not to break any of them.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset.&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317978</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317978"/>
		<updated>2011-06-11T23:51:01Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.* (multiple bugs)&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Disable addons that don&#039;t observe &amp;quot;private-browsing&amp;quot; event/opt-in&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317977</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317977"/>
		<updated>2011-06-11T23:32:21Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Disable addons that don&#039;t observe &amp;quot;private-browsing&amp;quot; event/opt-in&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317976</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317976"/>
		<updated>2011-06-11T23:27:57Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Disable addons that don&#039;t observe &amp;quot;private-browsing&amp;quot; event/opt-in&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317975</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317975"/>
		<updated>2011-06-11T23:21:11Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2 &amp;amp; 3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2 &amp;amp; 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317974</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317974"/>
		<updated>2011-06-11T23:18:10Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P4&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317973</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317973"/>
		<updated>2011-06-11T23:12:56Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Provide mechanisms to clear cert store and STS &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317972</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317972"/>
		<updated>2011-06-11T23:07:44Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317971</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317971"/>
		<updated>2011-06-11T23:04:50Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.1&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Virtualized/memory-only permissions manager and site-specific options&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2,3&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose local font loading control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Provide about:config pref to limit number of fonts loaded per tab&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317970</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317970"/>
		<updated>2011-06-11T22:59:32Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Features and bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Limit CSS3 resolution and window.screen info to render window size&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Block content-window script from accessing Components.*&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local disk privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose font control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317969</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317969"/>
		<updated>2011-06-11T22:46:07Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Expose display resolution to about:config spoofing&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 1.2&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose font control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| 2&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1.2,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317968</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317968"/>
		<updated>2011-06-11T22:37:43Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1,3&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Expose display resolution to about:config spoofing&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| Double-key Cache, DOM Storage, client certs, http auth&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Make local privacy optional in Private Browsing Mode&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| P3&lt;br /&gt;
| Expose font control to XPCOM/observers&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317967</id>
		<title>Privacy/Roadmap/Tor</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Privacy/Roadmap/Tor&amp;diff=317967"/>
		<updated>2011-06-11T22:24:32Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Advancing Anonymity =&lt;br /&gt;
&lt;br /&gt;
This document is a high-level vision for enhancing anonymity on the web, especially supporting the efforts of [http://www.torproject.org the Tor project].  Not everyone wants to be completely anonymous, but we should help those who want control their anonymity online.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related:&#039;&#039;&#039;&lt;br /&gt;
* [[Security/Anonymous_Browsing]]&lt;br /&gt;
* [[Thirdparty]]&lt;br /&gt;
&lt;br /&gt;
== Vision ==&lt;br /&gt;
Ultimately, it&#039;s really hard to be anonymous online right now.  On top of that, it&#039;s really hard for projects to harness Firefox as a platform that can be extended into an anonymity-instilling tool.  We want it to be easy for users to be as anonymous as possible in Firefox, and it should be easy for Tor developers to make sure Firefox is easy to configure as a platform for anonymous browsing.&lt;br /&gt;
&lt;br /&gt;
There are three desired outcomes that will make Firefox a better home for Tor:&lt;br /&gt;
# Better API-level switches for add-ons like torbutton to control Firefox&#039;s behavior&lt;br /&gt;
# Improve Private Browsing Mode&lt;br /&gt;
## Reduced Fingerprintability (leaky pipes)&lt;br /&gt;
## Robust suite of experimental/radical privacy features&lt;br /&gt;
# Better local security and privacy (non-network anonymity)&lt;br /&gt;
&lt;br /&gt;
= Features and bugs =&lt;br /&gt;
&lt;br /&gt;
{|class=wikitable&lt;br /&gt;
! Priority&lt;br /&gt;
! Item&lt;br /&gt;
! Status&lt;br /&gt;
! ETA&lt;br /&gt;
! Owner&lt;br /&gt;
! Outcomes&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| {{bug|565965|Double-key cookies}}&lt;br /&gt;
| {{StatusAtRisk|status=stalled}}&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1,3&lt;br /&gt;
|-&lt;br /&gt;
| P1&lt;br /&gt;
| Expose display resolution to about:config spoofing&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| P2&lt;br /&gt;
| [[Opt-in activation for plugins]]&lt;br /&gt;
|&lt;br /&gt;
| TBD&lt;br /&gt;
| &lt;br /&gt;
| 1,2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
&lt;br /&gt;
Links to implementation plan and progress:&lt;br /&gt;
* [[Firefox/Flight Tracking]]&lt;br /&gt;
* [[Firefox/Features]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Roadmaps]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317909</id>
		<title>Talk:Privacy/Roadmap 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317909"/>
		<updated>2011-06-11T00:11:58Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Deploy Safe and Rational Defaults */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Improve Private &amp;amp; Semi-anonymous Browsing ===&lt;br /&gt;
&lt;br /&gt;
I think per-tab private mode is likely to be confusing. I think the more intuitive way to provide this linkability improvement is by isolating the browser state for a given top-level urlbar domain (ie the double-keying Cookie idea but applied to cache, DOM Storage, client certs, etc).&lt;br /&gt;
&lt;br /&gt;
OTOH, the ability to have a per-window private mode, or perhaps even just a single concurrent private mode consisting of many windows may make sense. For example, I think Chrome&#039;s Incognito Mode windows are very intuitive for this reason. I think it also does make sense to have all private browsing windows share the same virtual profile.&lt;br /&gt;
&lt;br /&gt;
On the third hand, the downside of concurrent use is that it makes the &amp;quot;I&#039;ll just go to the wifi cafe or tether my cell phone&amp;quot; use case more difficult. That user will end up linking themselves via all the activity in their previous tabs/windows.&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;br /&gt;
&lt;br /&gt;
=== Deploy Safe and Rational Defaults ===&lt;br /&gt;
&lt;br /&gt;
While I think that improving the referer situation is useful in some cases, it really doesn&#039;t do anything to stop bad actors. I think giving sites control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII themselves. Right now it simply is not possible to restrict referer for many elements. Providing trickle-down restrictions via CSS or via an attribute of the html or body tag would be ideal.&lt;br /&gt;
&lt;br /&gt;
After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated...&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317906</id>
		<title>Talk:Privacy/Roadmap 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317906"/>
		<updated>2011-06-11T00:09:40Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Deploy Safe and Rational Defaults */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Improve Private &amp;amp; Semi-anonymous Browsing ===&lt;br /&gt;
&lt;br /&gt;
I think per-tab private mode is likely to be confusing. I think the more intuitive way to provide this linkability improvement is by isolating the browser state for a given top-level urlbar domain (ie the double-keying Cookie idea but applied to cache, DOM Storage, client certs, etc).&lt;br /&gt;
&lt;br /&gt;
OTOH, the ability to have a per-window private mode, or perhaps even just a single concurrent private mode consisting of many windows may make sense. For example, I think Chrome&#039;s Incognito Mode windows are very intuitive for this reason. I think it also does make sense to have all private browsing windows share the same virtual profile.&lt;br /&gt;
&lt;br /&gt;
On the third hand, the downside of concurrent use is that it makes the &amp;quot;I&#039;ll just go to the wifi cafe or tether my cell phone&amp;quot; use case more difficult. That user will end up linking themselves via all the activity in their previous tabs/windows.&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;br /&gt;
&lt;br /&gt;
=== Deploy Safe and Rational Defaults ===&lt;br /&gt;
&lt;br /&gt;
While I think that improving the referer situation is useful in some cases, it really doesn&#039;t do anything to stop bad actors. I think giving sites control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII themselves. Right now it simply is not possibly to restrict referer for many elements. Providing trickle-down restrictions via CSS or via an attribute of the html or body tag would be ideal.&lt;br /&gt;
&lt;br /&gt;
After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated...&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317904</id>
		<title>Talk:Privacy/Roadmap 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Talk:Privacy/Roadmap_2011&amp;diff=317904"/>
		<updated>2011-06-11T00:07:11Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: Created page with &amp;quot;=== Improve Private &amp;amp; Semi-anonymous Browsing ===  I think per-tab private mode is likely to be confusing. I think the more intuitive way to provide this linkability improvement ...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Improve Private &amp;amp; Semi-anonymous Browsing ===&lt;br /&gt;
&lt;br /&gt;
I think per-tab private mode is likely to be confusing. I think the more intuitive way to provide this linkability improvement is by isolating the browser state for a given top-level urlbar domain (ie the double-keying Cookie idea but applied to cache, DOM Storage, client certs, etc).&lt;br /&gt;
&lt;br /&gt;
OTOH, the ability to have a per-window private mode, or perhaps even just a single concurrent private mode consisting of many windows may make sense. For example, I think Chrome&#039;s Incognito Mode windows are very intuitive for this reason. I think it also does make sense to have all private browsing windows share the same virtual profile.&lt;br /&gt;
&lt;br /&gt;
On the third hand, the downside of concurrent use is that it makes the &amp;quot;I&#039;ll just go to the wifi cafe or tether my cell phone&amp;quot; use case more difficult. That user will end up linking themselves via all the activity in their previous tabs/windows.&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;br /&gt;
&lt;br /&gt;
=== Deploy Safe and Rational Defaults ===&lt;br /&gt;
&lt;br /&gt;
While I think that improving the referer situation is useful in some cases, it really doesn&#039;t do anything to stop bad actors. I think giving sites the ability to better control over when referer info is sent to third parties should be a higher priority than just restricting it client side, so sites can control the leakage of their PII better themselves. Right now it simply is not possibly to restrict referer for many elements. Also, providing trickle-down restrictions via CSS or via an attribute of the html or body tag would be ideal.&lt;br /&gt;
&lt;br /&gt;
After all, if bad actors really want to pass data to their third parties, they have plenty of options available for this even if referer is restricted/eliminated...&lt;br /&gt;
&lt;br /&gt;
- [[mikeperry]]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234300</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234300"/>
		<updated>2010-06-28T18:14:28Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* User Agent */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language. Further, dropping items from the UA string while only in Anonymous Browsing Mode would reveal the fact that the user is using the mode.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to simply pick a user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton.&lt;br /&gt;
&lt;br /&gt;
It should be noted that the Firefox minor revision and other properties can still be determined by inspecting Components.interfaces, so [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070] would need to be fixed for these protections to have any real value.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Long term, the best option would be to standardize on a small, common set of fonts for the mode that are typically available on all platforms, or simply set browser.display.use_document_fonts to 0.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset.&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234295</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234295"/>
		<updated>2010-06-28T18:03:51Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Clock Delta+Precision */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Long term, the best option would be to standardize on a small, common set of fonts for the mode that are typically available on all platforms, or simply set browser.display.use_document_fonts to 0.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
The Date object currently provides millisecond accuracy. This accuracy can be&lt;br /&gt;
used as an identifier based on clock skew, or can be used to accurately measure&lt;br /&gt;
user behaviours for use in fingerprinting.&lt;br /&gt;
&lt;br /&gt;
At least two companies claim to use this accuracy to fingerprint users when&lt;br /&gt;
other methods fail:&lt;br /&gt;
http://arstechnica.com/tech-policy/news/2010/02/firm-uses-typing-cadence-to-finger-unauthorized-users.ars&lt;br /&gt;
&lt;br /&gt;
One possibility might be to quantize Date values to the second, and then add random, monotonically increasing amounts of milliseconds to subsequent calls during anonymous browsing mode, along with a random per-page or per-origin offset.&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234293</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234293"/>
		<updated>2010-06-28T17:57:45Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Fonts and Font Lists */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Installed font presence provides a large amount of identifying information. Currently, the major culprit of leaking this information is plugins, as they provide an unsorted complete enumeration of all system fonts.&lt;br /&gt;
&lt;br /&gt;
There are ways to [http://flippingtypical.com/ query fonts for existence] in JavaScript and CSS, but this issue is not really worth dealing with until the plugin problem is solved, or it is decided that non-compliant plugins should be disabled.&lt;br /&gt;
&lt;br /&gt;
Long term, the best option would be to standardize on a small, common set of fonts for the mode that are typically available on all platforms, or simply set browser.display.use_document_fonts to 0.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234284</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234284"/>
		<updated>2010-06-28T17:42:36Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Behavior */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
Ideally, these requirements would be satisfied in such a way as to make it difficult or impossible to determine if Anonymous Browsing is enabled, but this may come at a cost of some resistance to fingerprinting.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234282</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234282"/>
		<updated>2010-06-28T17:39:14Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Screen Resolution and Properties */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
Some combination of these could help to make it hard to determine if the user is actually in Anonymous browsing mode. For example, providing a valid, but resized render window, lying about the size of the actual window to some standard platform size, and lying about the desktop size to return the most popular resolution just larger than the current window size.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234192</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234192"/>
		<updated>2010-06-28T12:58:03Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Relevant Bugzilla Entries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=440892 Bug 440892]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234183</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234183"/>
		<updated>2010-06-28T12:04:51Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Relevant Bugzilla Entries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=575230 Bug 575230]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234177</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234177"/>
		<updated>2010-06-28T11:30:47Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* User Agent */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
User agent can be handled two different ways. One way would be to simply reduce the amount of entropy provided by the standard user agent headers. There is a [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint bug for this], but some high-entropy items may end up being too useful to drop, such as the operating system and Accept-Language.&lt;br /&gt;
&lt;br /&gt;
The other way to handle this would be to assume that there is no way to prevent a remote website from determining if a user is in anonymous browsing mode by testing for any of the other protections in this document. If this is the case, then anonymous mode could simply pick its own uniform user agent string that is determined to be one of the more common Firefox user agent strings currently in use. This is the approach taken by Torbutton. However, providing an anonymous browsing mode that makes it difficult to determine if anonymous browsing is enabled has numerous obvious advantages, so this may not be an option.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234175</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234175"/>
		<updated>2010-06-28T11:15:45Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Relevant Bugzilla Entries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234174</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234174"/>
		<updated>2010-06-28T11:13:36Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Relevant Bugzilla Entries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234050</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234050"/>
		<updated>2010-06-26T23:42:24Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Interface and Options */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
One way to provide this mode would be to expose it as an option for private browsing mode. If the actual web usability impact can be kept low, there should be no reason why this couldn&#039;t be enabled by default for Private Browsing Mode sessions.&lt;br /&gt;
&lt;br /&gt;
However, if the impact is potentially higher, the browser could provide two independent modes, one for an &amp;quot;Off the record&amp;quot; mode, where nothing is recorded on disk, and another for a &amp;quot;Tracking Resistance&amp;quot; mode, that enables the features here.&lt;br /&gt;
&lt;br /&gt;
According to [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers], Private Browsing Mode may be suffering from &amp;quot;Mode Error&amp;quot;, where users enable the mode, but forget to ever disable it because of poor UI indication. A better UI might provide clear graphical indication that private browsing mode is enabled for a particular window.&lt;br /&gt;
&lt;br /&gt;
As far as options, it may be desirable to provide a Private Browsing Mode dialog with a few preferences. Some users may prefer that there be *no* UI indication that private browsing mode is enabled. Others may prefer that their non-private tabs and windows not be closed, so that they can use the two modes concurrently. Some users may not want Private Browsing Mode to write any data to disk, while others may only care about web tracking.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234048</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234048"/>
		<updated>2010-06-26T23:26:52Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Metadata */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html An analysis of private browsing modes in modern browsers]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234047</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=234047"/>
		<updated>2010-06-26T23:24:51Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Behavior */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
==Livemark updates==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233956</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233956"/>
		<updated>2010-06-26T14:01:07Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Use Cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233952</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233952"/>
		<updated>2010-06-26T13:49:48Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Plug-Ins */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
Another option might be to leverage the out of process execution of plugins to restrict their ability to access the local system while the mode is enabled.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233950</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233950"/>
		<updated>2010-06-26T13:27:46Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Cookies */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies and DOM Storage==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233949</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233949"/>
		<updated>2010-06-26T13:20:47Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Plug-Ins */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
Plugins are abysmal for privacy in several respects. First, because of the wide variety of browser plugins, the presence or absence of plugins from navigator.plugins actually provides a large amount of information.&lt;br /&gt;
&lt;br /&gt;
Second, plugins themselves will happily provide websites with a large amount of identifying information about a user, including their list of installed fonts, their CPU model and speed, their local interface IP addresses, username, hostname, and so on. In addition, plugins can also have their own data and cookie stores, that they allow websites to manipulate.&lt;br /&gt;
&lt;br /&gt;
The best course of action may be to develop an independent policy for what plugins are allowed to do in anonymous and private browsing modes with respect to the above information. Any plugins that do not advertise their adherence to this policy should be disabled during the mode.&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233947</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233947"/>
		<updated>2010-06-26T13:11:09Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Screen Resolution and Properties */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
Desktop resolution provides about 5 bits of identifying information, and window and decoration sizes provide yet more. This information is available both through window.screen and [https://developer.mozilla.org/En/CSS/Media_queries CSS media queries].&lt;br /&gt;
&lt;br /&gt;
There are a couple of options for anonymous browsing mode to handle this data. One would be to lie, and to present websites with a common desktop resolution, and round the reported browser resolution to some multiple of pixels.&lt;br /&gt;
&lt;br /&gt;
A another option would be to tell websites that the desktop resolution is the render window, and resize the render window to either a popular common resolution, or to a multiple of 50px. The downside of this approach is that it has shortcomings when the window is maximized, because window decoration and scrollbar sizes will prevent rounding to an actual multiple of 50px.&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233940</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233940"/>
		<updated>2010-06-26T10:53:05Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Relevant Bugzilla Entries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=429070 Bug 429070]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=http-fingerprint Bug 572650 (Meta)]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=418986 Bug 418986]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=290456 Bug 290456]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=448743 Bug 448743]&lt;br /&gt;
* [https://bugzilla.mozilla.org/show_bug.cgi?id=435159 Bug 435159]&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233938</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233938"/>
		<updated>2010-06-26T10:34:13Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Interface and Options=&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233937</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233937"/>
		<updated>2010-06-26T10:28:37Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* SSL */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
&lt;br /&gt;
The SSL Layer currently exposes a few different pieces of identifying information that would need to be altered while the user is in anonymous browsing mode. Stored client certificates must be disabled during the mode. All current SSL session identifiers must be cleared upon entering the mode.&lt;br /&gt;
&lt;br /&gt;
Stored server and CA certificates may also need to be optionally disabled, though this should be left to user preference.&lt;br /&gt;
&lt;br /&gt;
Finally, the SSL handshake also contains a timestamp from the client. A small random, per-domain offset could be added to it, but since it is already truncated to the second, this may not be terribly important.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233934</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233934"/>
		<updated>2010-06-26T10:11:37Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Behavior */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
This section describes the major browser behaviours the mode will need to alter in order to address the adversary model. Many of these come from the [[Fingerprinting]] page, but some are just general privacy mechanisms.&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Cookies==&lt;br /&gt;
&lt;br /&gt;
==Location Information==&lt;br /&gt;
&lt;br /&gt;
==External Protocol Handlers==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Clock Delta+Precision==&lt;br /&gt;
&lt;br /&gt;
==Screen Resolution and Properties==&lt;br /&gt;
&lt;br /&gt;
==HTTP Headers/Activity==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==SSL==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
==Form Fill==&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233932</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233932"/>
		<updated>2010-06-26T09:35:17Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Adversary Model */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting]] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233931</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233931"/>
		<updated>2010-06-26T09:33:19Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Adversary Model */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing using unique identifiers, in obtaining location information, and in [[Fingerprinting|fingerprinting] the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty|Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233929</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233929"/>
		<updated>2010-06-26T09:29:23Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Adversary Model */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Private Browsing Mode, in particular, is primarily concerned with preventing the storage of browsing data. &lt;br /&gt;
&lt;br /&gt;
This document will focus on network-based tracking mechanisms. In particular, the adversary is interested in correlation of regular mode browsing to anonymous mode browsing, in obtaining location information, and in fingerprinting the user&#039;s browser characteristics.&lt;br /&gt;
&lt;br /&gt;
The adversary may have many motivations for doing this, but to keep scope simple, it may be best to assume that their primary motivation is to correlate user web activity for purposes of tracking users against their will for purposes of serving ads. A large class of adversaries (the ad networks) are interested in deploying semi-intrusive mechanisms to do so, in light of increasing number of users choosing to clear their cookies regularly, and in light of potential future [[Thirdparty Third Party Cookie]] protection mechanisms implemented by the major browsers.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233926</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233926"/>
		<updated>2010-06-26T09:11:19Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Adversary Model */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
The adversary is interested in tracking the user by any means necessary. However, mechanisms that are already being addressed by other projects will not be discussed in this document. Examples of this include protections given by Private Browsing Mode, and general planned privacy protections, such as the [https://developer.mozilla.org/en/CSS/Privacy_and_the_:visited_selector CSS Visited Selector] spoofing.&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233921</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233921"/>
		<updated>2010-06-26T08:27:05Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=Adversary Model=&lt;br /&gt;
&lt;br /&gt;
=Requirements=&lt;br /&gt;
&lt;br /&gt;
=Behavior=&lt;br /&gt;
&lt;br /&gt;
==User Agent==&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;br /&gt;
&lt;br /&gt;
=Relevant Bugzilla Entries=&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233920</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233920"/>
		<updated>2010-06-26T08:14:21Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* The Privacy Power User */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features. However, it looks as if the proposed [[Labs/Weave|Weave]] Identity project called [[Labs/Weave/Identity/Account_Manager|Account Manager]] could be extended to support this use case.&lt;br /&gt;
&lt;br /&gt;
=User Agent Considerations=&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233693</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233693"/>
		<updated>2010-06-25T10:53:51Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* The Paranoid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They clear their cookies regularly, and may disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features.&lt;br /&gt;
&lt;br /&gt;
=User Agent Considerations=&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233692</id>
		<title>Security/Anonymous Browsing</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Anonymous_Browsing&amp;diff=233692"/>
		<updated>2010-06-25T10:51:07Z</updated>

		<summary type="html">&lt;p&gt;Mikeperry: /* Use Cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;This page will serve as a design requirements and discussion for an Anonymous Browsing Mode.  Whether or not it is implemented, the requirements and goals for such a mode will be documented here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Anonymous Browsing Mode=&lt;br /&gt;
&lt;br /&gt;
Unlike Private Browsing, which mainly attempts to protect a user from a local attacker, Anonymous Browsing will serve to minimize the amount of identifying data that is available to a remote (web or network) attacker (for example, consider the EFF [http://panopticlick.eff.org/ panopticlick project]).  The main motivations behind such a mode are to prevent user tracking and fingerprinting, but there are many use cases.&lt;br /&gt;
&lt;br /&gt;
== Scope of this Document ==&lt;br /&gt;
&lt;br /&gt;
This working document will serve as an explanation of &#039;&#039;&#039;why&#039;&#039;&#039; users will want Anonymous Browsing, &#039;&#039;&#039;how&#039;&#039;&#039; such a mode would behave and &#039;&#039;&#039;what&#039;&#039;&#039; will need to be different in this mode from regular browsing sessions for such a mode to be useful.&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&#039;&#039;Driver&#039;&#039;: || [[User:Sidstamm|Sid Stamm]]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Status&#039;&#039;: || Brainstorming&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;Started&#039;&#039;: || 24-June-2010&lt;br /&gt;
|}&lt;br /&gt;
Relevant Links:&lt;br /&gt;
* [https://www.torproject.org/torbutton/design/ Torbutton Design Document] and [https://www.torproject.org/torbutton/design/#adversary Adversary Model]&lt;br /&gt;
* [[Fingerprinting]]&lt;br /&gt;
&lt;br /&gt;
=Use Cases=&lt;br /&gt;
&lt;br /&gt;
Users of anonymous browsing mode would be concerned about tracking from Internet sites under various circumstances, and may or may not be concerned about local records on their computer&#039;s disk.&lt;br /&gt;
&lt;br /&gt;
Public awareness of the privacy issues surrounding using the web is rising, as evidenced by the need for advertising networks to resort to flash cookies and fingerprinting due to the frequency with which normal users clear their cookies. The popularity of privacy-enhancing addons and the private browsing modes of the major browsers also suggest that a mode that helps to mitigate ubiquitous web tracking may be a key differentiator against competing browsers.&lt;br /&gt;
&lt;br /&gt;
The target users of this mode may have a number of different browsing behaviours and needs. It is best to represent these behaviours as &amp;quot;stories&amp;quot;, to better understand the needs of different types of users, and to properly design feature and option choices to accommodate them.&lt;br /&gt;
&lt;br /&gt;
== The Medical Patient/Abuse Victim ==&lt;br /&gt;
&lt;br /&gt;
The medical patient has some kind of condition that they would prefer that ad networks not be aware of: possibly one that puts them at risk for raised medical, life, or auto insurance premiums, or carries other social stigma. Such a user may decide to use the mode after receiving mysterious targeted ads for their condition while visiting unrelated sites.&lt;br /&gt;
&lt;br /&gt;
They are possibly a member of a number of online support groups that they log in to and post to under a pseudonym (such as alcoholics anonymous, narcanon, etc) using the mode.&lt;br /&gt;
&lt;br /&gt;
They are likely an occasional user, and would remain logged in to social media services, their email account, and other websites continuously during normal browsing, but would prefer a clean slate for web usage relating to their condition.&lt;br /&gt;
&lt;br /&gt;
They may or may not be concerned about records of anonymous web activity on their own computer. They likely use the mode from home, but may opt to use a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Pseudonymous Blogger ==&lt;br /&gt;
&lt;br /&gt;
The pseudonymous blogger maintains a politically or technically controversial blog that may expose them to subpoena risk to uncover their identity. There have been several cases of Apple in particular demanding the identity of bloggers posting about unreleased or otherwise secret product releases or features. Bloggers in China and other countries also face risk of attempts to identify them.&lt;br /&gt;
 &lt;br /&gt;
This user likely uses public wifi, a prepaid data device, a VPN, or a proxy to access the Internet, as opposed to their normal Internet connection.&lt;br /&gt;
&lt;br /&gt;
If operating in the United States, this user is likely not concerned about logs on their local disk.&lt;br /&gt;
&lt;br /&gt;
This user may wish to preserve their &amp;quot;Anonymous mode&amp;quot; cookies beyond a single session, but does not want them mixing with their normal cookies. They may have a seperate Facebook, twitter, and other social media accounts for their blogging persona, in addition to their regular persona.&lt;br /&gt;
&lt;br /&gt;
== The Anonymous Commenter ==&lt;br /&gt;
&lt;br /&gt;
The anonymous commenter is a user who is posting relevant information to a blog post or news article. Those that truly require anonymity need it because they have inside or privileged information relevant to a story. &lt;br /&gt;
&lt;br /&gt;
Most likely, they spend the majority of their Internet usage logged into a number of services online that record various things about them, and may log them into arbitrary services automatically due to federated login systems such as OpenID, and have been exposed to a number of ad networks intent on tracking them.&lt;br /&gt;
&lt;br /&gt;
They use Anonymous Mode to ensure that the blog or news site (which may have numerous advertising partnerships) would have a very hard time correlating their comment to their normal browsing.&lt;br /&gt;
&lt;br /&gt;
They likely do not care about their activity being recorded to their computer&#039;s disk. They most likely use the mode from home, but may use public wifi or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Whistleblower/Anonymous Tipster ==&lt;br /&gt;
Similar to the Anonymous Commenter, the whistleblower uses the web normally for the majority of the time. However, at some point they discover wrongdoing at their workplace or otherwise need to anonymously contact the press.&lt;br /&gt;
&lt;br /&gt;
The whistleblower will only use the mode once or rarely, though they may create an email account to establish communication with the press. &lt;br /&gt;
&lt;br /&gt;
They will likely use public wifi, a prepaid data device, and/or a proxy.&lt;br /&gt;
&lt;br /&gt;
== The Paranoid ==&lt;br /&gt;
Just because you&#039;re paranoid doesn&#039;t mean they aren&#039;t out to get you.&lt;br /&gt;
&lt;br /&gt;
The paranoid wants to avoid most of their activity being recorded by ad networks and services. They are suspicious of Facebook, social media sites, and tend not to be logged in to any services continuously. They are the types that currently disable javascript and/or run NoScript, BetterPrivacy, RequestPolicy, Adblock Plus, TACO, CookieCuller, and other addons to improve their privacy online. These are some of the most popular Firefox addons on addons.mozilla.org. &lt;br /&gt;
&lt;br /&gt;
They likely use the mode continuously from home.&lt;br /&gt;
&lt;br /&gt;
== The Privacy Power User ==&lt;br /&gt;
&lt;br /&gt;
The power user would prefer to maintain multiple independent identities logged in to various social media services. They would prefer to be able to configure their browser to quickly switch between these identities, which may represent different personae, or may simply represent individual services or websites that they do not want to be logged in to concurrently.&lt;br /&gt;
&lt;br /&gt;
They likely author independent blogs, have multiple email accounts, post on multiple mailinglists/web forums, contribute to a number of open source projects, and/or operate multiple twitter feeds, all under different pseudonyms.&lt;br /&gt;
&lt;br /&gt;
They likely use a prepaid data device or proxy of some sort. They are not concerned about their activity being stored on their computer: in fact they would prefer it, to ease their ability to remain logged in to services and retain history and bookmarks without suffering the privacy consequences.&lt;br /&gt;
&lt;br /&gt;
They would likely also prefer the ability to configure their browser to only retain cookies for certain sites, and to periodically clear all other browser state. They would be satisfied if these features were available only through addons, as opposed to core browser features.&lt;br /&gt;
&lt;br /&gt;
=User Agent Considerations=&lt;br /&gt;
&lt;br /&gt;
==Caches and History==&lt;br /&gt;
&lt;br /&gt;
==Fonts and Font Lists==&lt;br /&gt;
Locale issues, standard font lists, etc.&lt;br /&gt;
&lt;br /&gt;
==Advertised Capabilities==&lt;br /&gt;
User-Agent string, Accept headers, etc.&lt;br /&gt;
&lt;br /&gt;
==Plug-Ins==&lt;br /&gt;
&lt;br /&gt;
==Extensions/Add-Ons==&lt;br /&gt;
&lt;br /&gt;
==Security==&lt;br /&gt;
SSL certs, etc.&lt;br /&gt;
&lt;br /&gt;
=Impact=&lt;br /&gt;
How much will this impact web experience for the users?  Sure we can break things in the name of anonymity if users opt for such a mode, but how much is tolerable?&lt;/div&gt;</summary>
		<author><name>Mikeperry</name></author>
	</entry>
</feed>