All times are UTC + 1 hour




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: More usefull FF addons ?
PostPosted: Fri Sep 16, 2011 11:46 

Joined: Mon Apr 18, 2011 13:27
Posts: 31
I havesome questions about addons seeming very usefull ti me. But I don't know if I can without any problem add them to the jodofox profile:


1) Secure Sanitizer: When closing the session, it doesn't delete but wipe (DoD 3 passes) history, cookies, etc.
https://addons.mozilla.org/en-US/firefo ... sanitizer/

Does Jondofox progfile do the same thing (ie wiping datas on exit, not only deleting them) .



2) Anonymizer Nevercookies, an addon devoted to fight against the plague of ever/zombies/super cookies. It requires private browsing enabled to work (what Jondo Team doesn't generally recommand), but tests done on samy's site was conclusive.

Strangely when using it (with private mode enabled) a random-named FF profile is added to my list of FF profile, and remained in it when I restart FF.

https://www.pcworld.com/downloads/file/ ... ption.html

http://arstechnica.com/web/news/2010/09 ... reness.ars

http://samy.pl/evercookie/


Have you planed something agains "evercookies" ?


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Fri Sep 16, 2011 12:39 
User avatar

Joined: Mon Dec 29, 2008 15:58
Posts: 1877
JonDoFox is blocking most features used by Samys "Evercookies".

Code:
pngData mechanism: undefined
etagData mechanism:
cacheData mechanism:
userData mechanism: undefined
cookieData mechanism: undefined
localData mechanism: undefined
globalData mechanism: undefined
sessionData mechanism: undefined
historyData mechanism: undefined
lsoData mechanism: undefined
slData mechanism: undefined

Only one new feature is working, if Javascript was enabled. We are working on this issue:
Code:
windowData mechanism: XXX

The HTTP Auth feature is under development for Samys "Evercookie" but already secured by JonDoFox.


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Fri Sep 16, 2011 12:55 
User avatar

Joined: Thu May 24, 2007 14:52
Posts: 1196
cane wrote:
Only one new feature is working, if Javascript was enabled. We are working on this issue:
Code:
windowData mechanism: XXX


In fact, JonDoFox protects against this. YOu see this by leaving the site and coming back. Samy's test is not able to recognize this, but our IP check does.


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Sat Sep 17, 2011 8:40 

Joined: Mon Apr 18, 2011 13:27
Posts: 31
Thanks for your fast and detailed answer about nevercookies.



But, what about about my first question concerning the addon secure sanitizer ? I prefer when my private session data are wiped than only deleted (and so recoverablle by some tools).

But at the same time, I wan't damage my JonDoFox profile.

So, is it cautious and secure to use secure sanitizer with JD profile ? If not, does JD profile wipe selected session datas at the end of the session, and if not, have you some plan for that ? Is it on tour "to do" list ?


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Sat Sep 17, 2011 11:00 
User avatar

Joined: Mon Dec 29, 2008 15:58
Posts: 1877
Quote:
But, what about about my first question concerning the addon secure sanitizer ?
I can't say somethink about "secure sanitizer" at the moment. We will have a look. But may be, it will take some time.


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Sat Sep 17, 2011 14:37 

Joined: Thu Dec 30, 2010 0:22
Posts: 70
Urkal wrote:
I havesome questions about addons seeming very usefull ti me. But I don't know if I can without any problem add them to the jodofox profile:


1) Secure Sanitizer: When closing the session, it doesn't delete but wipe (DoD 3 passes) history, cookies, etc.
https://addons.mozilla.org/en-US/firefo ... sanitizer/

Does Jondofox progfile do the same thing (ie wiping datas on exit, not only deleting them) .



Sorry-but this is overkill! :)
you only need to write over old info once(zeros or something else)and_nobody_is abel to recover anything.
That you have to write more then once is an old myth but not true!
Check it by urself with any forensic tool-u'll never get something back.


Top
 Profile  
 
 Post subject: Re: More usefull FF addons ?
PostPosted: Mon Sep 19, 2011 10:10 
User avatar

Joined: Thu Dec 04, 2008 18:02
Posts: 1066
Urkal wrote:
But, what about about my first question concerning the addon secure sanitizer ? I prefer when my private session data are wiped than only deleted (and so recoverablle by some tools).But at the same time, I wan't damage my JonDoFox profile. So, is it cautious and secure to use secure sanitizer with JD profile ? If not, does JD profile wipe selected session datas at the end of the session, and if not, have you some plan for that ? Is it on tour "to do" list ?
I looked at the code and yes, there is no problem using this add-on with JonDoFox. BUT: I would not do it as it is actually not very useful. First, it seems not to be developed anymore and may only be used in FF up to 3.6. Second, as the former post already said: overwriting a file 3 times is not necessary. Third, I would say if you do not encrypt your home partition and someone gets your computer you probably have more trouble than not properly deleted cache files but if you are encrypting your home partition then there should be only a minimal risk (if risk at all) that these cache files pose. Thus, in order to reduce complexity I would suggest to not use this add-on.

We currently clear the cache at session end and do not plan to implement such kind of wiping the cache file(s).


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC + 1 hour


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
cron
Free Trial for Premium Services
Free Trial for Premium Services
Get your free test code for JonDonym Premium services!
JonDonym News
JonDoBrowser 0.7 – Status Report
Tue, 04 June 2013
Planned Maintenance
Fri, 03 June 2013
Speaker's Corner
PRISM Brothers
Wed, 12 June 2013
EUhackathon 2013
Fri, 07 June 2013
For your web site - free!
Get your free IP check image for your web site or forum here!
Latest software releases
JonDo 0.18.001
Tue, 29 May 2012
JonDoFox 2.6.14
Wed, 15 May 2013
JonDoBrowser 0.7 Beta
Tue, 21 May 2013
Live-CD/DVD 0.9.43
Thu, 23 May 2013