FINDING · EVALUATION
Automatic Onion-Location redirect was disabled in Tor Browser 13.0.12 as a direct result of this research, because automatic redirect forces the distinguishable clearnet-then-onion circuit pattern on every visit without user awareness. Manual O-L remains in Tor Browser but is still fingerprintable with the same near-perfect accuracy since the exit→onion circuit sequence is identical whether the redirect is automatic or manually triggered.
From 2025-syverson-onion-location-measurements-fingerprinting — Onion-Location Measurements and Fingerprinting · §2.2, footnote 1; §6 · 2025 · PoPETs 2025
Implications
- Removing automatic redirect reduces inadvertent fingerprinting exposure but does not eliminate OLF; tool designers should not treat user opt-in as a sufficient mitigation against guard-level traffic analysis.
- Any browser feature that automatically opens a second tunnel (exit → onion) carrying overlapping content creates a correlated two-circuit fingerprint; audit new onion-discovery UX for this pattern before shipping.
Tags
Extracted by claude-sonnet-4-6 — review before relying.